PT-2022-3334 · Mariadb+10 · Mariadb+11

Jingzhou Fu

·

Published

2021-08-19

·

Updated

2025-06-10

·

CVE-2022-32091

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MariaDB version 10.7
Description The issue is related to an out-of-bounds operation in the interceptor memset function, located at /libsanitizer/sanitizer common/sanitizer common interceptors.inc, which can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information. This is also described as a use-after-poison condition in the same function.
Recommendations For MariaDB version 10.7, as a temporary workaround, consider disabling the interceptor memset function until a patch is available. However, since specific guidance on resolving the issue for this version is not provided, it is essential to monitor for official patches or updates from MariaDB. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:5259
ALSA-2023:5683
ALSA-2023:5684
ALT-PU-2022-2436
ALT-PU-2022-2446
ALT-PU-2023-1583
ALT-PU-2023-6462
AZL-10607
BDU:2022-04082
BIT-MARIADB-2022-32091
BIT-MARIADB-MIN-2022-32091
BIT-MYSQL-CLIENT-2022-32091
CESA-2023_5259
CESA-2023_5683
CVE-2022-32091
DLA-3114-1
DLA-3114-2
MGASA-2022-0314
OESA-2023-1830
OPENSUSE-SU-2022_3159-1
OPENSUSE-SU-2022_3391-1
OPENSUSE-SU-2024:12360-1
RHSA-2023:5259
RHSA-2023:5683
RHSA-2023:5684
RHSA-2023:6821
RHSA-2023:6822
RHSA-2023:6883
RHSA-2023:7633
RHSA-2023_5259
RHSA-2023_5683
RHSA-2023_5684
RLSA-2023:5683
ROSA-SA-2023-2255
SUSE-RU-2023:3956-1
SUSE-RU-2023:4991-1
SUSE-SU-2022:3159-1
SUSE-SU-2022:3225-1
SUSE-SU-2022:3391-1
USN-5739-1
USN-5739-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Mariadb
Mariadb Server
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu