CVE-2022-27376

HIGH7.5EPSS 0.32%
Published: 4/12/2022Modified: 4/28/2026
Also known as:ALPINE-CVE-2022-27376DEBIAN-CVE-2022-27376

Description

MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.

Affected packages (5)

  • Alpine/mariadbfrom 0, < 10.4.25-r0
  • Bitnami/mariadb>= 10.3.0, < 10.3.35, >= 10.4.0, < 10.4.25, >= 10.5.0, < 10.5.16, >= 10.6.0, < 10.6.8, >= 10.7.0, < 10.7.4
  • Bitnami/mariadb-min>= 10.3.0, < 10.3.35, >= 10.4.0, < 10.4.25, >= 10.5.0, < 10.5.16, >= 10.6.0, < 10.6.8, >= 10.7.0, < 10.7.4
  • Bitnami/mysql-client>= 10.3.0, < 10.3.35, >= 10.4.0, < 10.4.25, >= 10.5.0, < 10.5.16, >= 10.6.0, < 10.6.8, >= 10.7.0, < 10.7.4
  • Debian/mariadb-10.5from 0, < 1:10.5.18-0+deb11u1

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (6)