Resource exhaustion in MariaDB - CVE-2023-5157

 

Resource exhaustion in MariaDB - CVE-2023-5157

Published: October 13, 2023


Vulnerability identifier: #VU81995
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5157
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can launch a simple port scan on ports 3306/tcp and 4567/tcp and perform a denial of service (DoS) attack.


Affected software

MariaDB
Gentoo Linux
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Judy-devel
Judy
asio-devel
mariadb-server-galera
mariadb-server
mariadb-embedded
mariadb-gssapi-server
mariadb-common
mariadb-embedded-devel
mariadb-test
mariadb-devel
mariadb-backup
mariadb-debugsource
mariadb-oqgraph-engine
mariadb-debuginfo
mariadb-cracklib
mariadb-errmessage
mariadb
rh-mariadb105-mariadb (Red Hat package)
mariadb (Red Hat package)
mariadb-server-utils
mariadb-pam
mariadb-errmsg
galera
rh-mariadb105-galera (Red Hat package)
galera (Red Hat package)

How to mitigate CVE-2023-5157

Install updates from vendor's website.

MariaDB - addressed in versions 10.4.26, 10.5.17, 10.6.9, 10.7.5, 10.8.4
Judy-devel - update to 1.0.5-18
Judy - update to 1.0.5-18
asio-devel - update to 1.10.8-7
mariadb-server-galera - update to 10.3.39-1
mariadb-server - update to 10.3.39-1
mariadb-embedded - update to 10.3.39-1
mariadb-gssapi-server - update to 10.3.39-1
mariadb-common - update to 10.3.39-1
mariadb-embedded-devel - update to 10.3.39-1
mariadb-test - update to 10.3.39-1
mariadb-devel - update to 10.3.39-1
mariadb-backup - update to 10.3.39-1
mariadb-debugsource - update to 10.3.39-1
mariadb-oqgraph-engine - update to 10.3.39-1
mariadb-debuginfo - update to 10.3.39-1
mariadb-cracklib - update to 10.3.39-1
mariadb-errmessage - update to 10.3.39-1
mariadb - update to 10.3.39-1
rh-mariadb105-mariadb (Red Hat package) - update to 10.5.22-1.el7
mariadb (Red Hat package) - addressed in versions 10.5.22-1.el9_0, 10.5.22-1.el9_2
mariadb-embedded-devel - update to 10.5.22-1.0.1
mariadb-test - update to 10.5.22-1.0.1
mariadb-server-utils - update to 10.5.22-1.0.1
mariadb-server-galera - update to 10.5.22-1.0.1
mariadb-server - update to 10.5.22-1.0.1
mariadb-pam - update to 10.5.22-1.0.1
mariadb-oqgraph-engine - update to 10.5.22-1.0.1
mariadb-gssapi-server - update to 10.5.22-1.0.1
mariadb-errmsg - update to 10.5.22-1.0.1
mariadb-embedded - update to 10.5.22-1.0.1
mariadb-devel - update to 10.5.22-1.0.1
mariadb-common - update to 10.5.22-1.0.1
mariadb-backup - update to 10.5.22-1.0.1
mariadb - update to 10.5.22-1.0.1
galera - update to 26.4.14-1
rh-mariadb105-galera (Red Hat package) - update to 26.4.14-1.el7
galera (Red Hat package) - addressed in versions 26.4.14-1.el9_0, 26.4.14-1.el9_2

External References

Related Security Bulletins