PT-2021-24337 · Mariadb+7 · Mariadb+8
Zuming Jiang
·
Published
2021-06-23
·
Updated
2025-06-10
·
CVE-2021-46657
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
MariaDB versions prior to 10.6.2
Description:
The issue allows an application crash via certain subquery uses of ORDER BY. This is related to the get sort by table function in MariaDB.
Recommendations:
For MariaDB versions prior to 10.6.2, update to version 10.6.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of subqueries with ORDER BY to minimize the risk of application crashes.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Mariadb
Mariadb Server
Red Hat
Rocky Linux
Suse