Integer overflow in MariaDB - CVE-2021-46667

 

Integer overflow in MariaDB - CVE-2021-46667

Published: May 31, 2022


Vulnerability identifier: #VU63850
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-46667
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to integer overflow in the sql_lex.cc. A local user can pass specially crafted data to the application, trigger integer overflow and perform a denial of service attack.


Affected software

MariaDB
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Judy
Judy-devel
asio-devel
mariadb-errmsg
mariadb-embedded-devel
mariadb-embedded
mariadb-devel
mariadb-common
mariadb-backup
mariadb
mariadb-server
mariadb-test
mariadb-server-utils
mariadb-server-galera
mariadb-gssapi-server
mariadb-oqgraph-engine
rh-mariadb103-mariadb (Red Hat package)
mariadb-cracklib
mariadb-debugsource
mariadb-debuginfo
mariadb-errmessage
mariadb-pam
rh-mariadb105-mariadb (Red Hat package)
mariadb105
galera
rh-mariadb103-galera (Red Hat package)
rh-mariadb105-galera (Red Hat package)
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
openEuler
Fedora

How to mitigate CVE-2021-46667

Install updates from vendor's website.

MariaDB - addressed in versions 10.2.41, 10.3.32, 10.4.22, 10.5.13, 10.6.5
Judy - update to 1.0.5-18
Judy-devel - update to 1.0.5-18
asio-devel - update to 1.10.8-7
mariadb-errmsg - addressed in versions 10.3.32-2, 10.5.13-1
mariadb-embedded-devel - addressed in versions 10.3.32-2, 10.5.13-1
mariadb-embedded - addressed in versions 10.3.32-2, 10.5.13-1
mariadb-devel - addressed in versions 10.3.32-2, 10.5.13-1
mariadb-common - addressed in versions 10.3.32-2, 10.5.13-1
mariadb-backup - addressed in versions 10.3.32-2, 10.5.13-1
mariadb - addressed in versions 10.3.32-2, 10.5.13-1
mariadb-server - addressed in versions 10.3.32-2, 10.5.13-1
mariadb-test - addressed in versions 10.3.32-2, 10.5.13-1
mariadb-server-utils - addressed in versions 10.3.32-2, 10.5.13-1
mariadb-server-galera - addressed in versions 10.3.32-2, 10.5.13-1
mariadb-gssapi-server - addressed in versions 10.3.32-2, 10.5.13-1
mariadb-oqgraph-engine - addressed in versions 10.3.32-2, 10.5.13-1
rh-mariadb103-mariadb (Red Hat package) - update to 10.3.32-2.el7
mariadb-devel - update to 10.3.34-1
mariadb-embedded - update to 10.3.34-1
mariadb - update to 10.3.34-1
mariadb-embedded-devel - update to 10.3.34-1
mariadb-oqgraph-engine - update to 10.3.34-1
mariadb-cracklib - update to 10.3.34-1
mariadb-backup - update to 10.3.34-1
mariadb-debugsource - update to 10.3.34-1
mariadb-common - update to 10.3.34-1
mariadb-server - update to 10.3.34-1
mariadb-debuginfo - update to 10.3.34-1
mariadb-server-galera - update to 10.3.34-1
mariadb-gssapi-server - update to 10.3.34-1
mariadb-errmessage - update to 10.3.34-1
mariadb-test - update to 10.3.34-1
mariadb - addressed in versions 10.3-3520220716094844.f27b74a8, 10.4-3520220717092835.f27b74a8, 10.5.15-1.fc34, 10.5.15-1.fc35, 10.5.15-1.fc36, 10.5-3420220428160949.058368ca, 10.5-3520220428160949.f27b74a8, 10.5-3620220428160949.5e5ad4a0, 10.6-3420220430165639.058368ca, 10.6-3520220430165639.f27b74a8, 10.6-3620220430165639.5e5ad4a0, 10.7-3420220501001308.058368ca, 10.7-3520220501001308.f27b74a8, 10.7-3620220501001308.5e5ad4a0
mariadb-pam - update to 10.5.13-1
rh-mariadb105-mariadb (Red Hat package) - update to 10.5.13-1.el7
mariadb105 - update to 10.5.16-1
galera - addressed in versions 25.3.34-4, 26.4.9-4
rh-mariadb103-galera (Red Hat package) - update to 25.3.34-4.el7
rh-mariadb105-galera (Red Hat package) - update to 26.4.9-3.el7
galera - addressed in versions 26.4.11-1.fc35, 26.4.11-1.fc36

External References

Related Security Bulletins