MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL.
The following packages have been upgraded to a later upstream version: mariadb (10.3.35), galera (25.3.35).
Security Fix(es):
mariadb: MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used (CVE-2021-46669)
mysql: Server: FTS unspecified vulnerability (CPU Apr 2022) (CVE-2022-21427)
mariadb: lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer (CVE-2022-24048)
mariadb: lack of validating the existence of an object prior to performing operations on the object (CVE-2022-24050)
mariadb: lack of proper validation of a user-supplied string before using it as a format specifier (CVE-2022-24051)
mariadb: CONNECT storage engine heap-based buffer overflow (CVE-2022-24052)
mariadb: assertion failure in Item_args::walk_arg (CVE-2022-27376)
mariadb: use-after-poison when complex conversion is involved in blob (CVE-2022-27377)
mariadb: server crash in create_tmp_table::finalize (CVE-2022-27378)
mariadb: server crash in component arg_comparator::compare_real_fixed (CVE-2022-27379)
mariadb: server crash at my_decimal::operator= (CVE-2022-27380)
mariadb: server crash at Field::set_default via specially crafted SQL statements (CVE-2022-27381)
mariadb: use-after-poison in my_strcasecmp_8bit() of ctype-simple.c (CVE-2022-27383)
mariadb: crash via component Item_subselect::init_expr_cache_tracker (CVE-2022-27384)
mariadb: server crashes in query_arena::set_query_arena upon SELECT from view (CVE-2022-27386)
mariadb: assertion failures in decimal_bin_size (CVE-2022-27387)
mariadb: assertion failure in compare_order_elements (CVE-2022-27445)
mariadb: use-after-poison in Binary_string::free_buffer (CVE-2022-27447)
mariadb: crash in multi-update and implicit grouping (CVE-2022-27448)
mariadb:...
0:1.0.5-18.module+el8.4.0+427+adf357070:25.3.35-1.module+el8.6.0+1005+cdf19c223:10.3.35-1.module+el8.6.0+1005+cdf19c22Exploitability
AV:LAC:LPR:LUI:NScope
S:UImpact
C:HI:HA:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H