ALASMARIADB10.5-2023-002

Related Vulnerabilities: CVE-2022-32081   CVE-2022-32082   CVE-2022-32084  

MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc. (CVE-2022-32081) MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc. (CVE-2022-32082) MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select. (CVE-2022-32084)

ALASMARIADB10.5-2023-002


Amazon Linux 2 Security Advisory: ALASMARIADB10.5-2023-002
Advisory Release Date: 2023-08-21 21:00 Pacific
Advisory Updated Date: 2023-09-25 22:10 Pacific
Severity: Medium

Issue Overview:

MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc. (CVE-2022-32081)

MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc. (CVE-2022-32082)

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select. (CVE-2022-32084)


Affected Packages:

mariadb


Issue Correction:
Run yum update mariadb to update your system.

New Packages:
aarch64:
    mariadb-10.5.10-2.amzn2.0.2.aarch64
    mariadb-libs-10.5.10-2.amzn2.0.2.aarch64
    mariadb-config-10.5.10-2.amzn2.0.2.aarch64
    mariadb-common-10.5.10-2.amzn2.0.2.aarch64
    mariadb-errmsg-10.5.10-2.amzn2.0.2.aarch64
    mariadb-server-galera-10.5.10-2.amzn2.0.2.aarch64
    mariadb-server-10.5.10-2.amzn2.0.2.aarch64
    mariadb-oqgraph-engine-10.5.10-2.amzn2.0.2.aarch64
    mariadb-connect-engine-10.5.10-2.amzn2.0.2.aarch64
    mariadb-backup-10.5.10-2.amzn2.0.2.aarch64
    mariadb-cracklib-password-check-10.5.10-2.amzn2.0.2.aarch64
    mariadb-gssapi-server-10.5.10-2.amzn2.0.2.aarch64
    mariadb-pam-10.5.10-2.amzn2.0.2.aarch64
    mariadb-sphinx-engine-10.5.10-2.amzn2.0.2.aarch64
    mariadb-s3-engine-10.5.10-2.amzn2.0.2.aarch64
    mariadb-server-utils-10.5.10-2.amzn2.0.2.aarch64
    mariadb-devel-10.5.10-2.amzn2.0.2.aarch64
    mariadb-embedded-10.5.10-2.amzn2.0.2.aarch64
    mariadb-embedded-devel-10.5.10-2.amzn2.0.2.aarch64
    mariadb-test-10.5.10-2.amzn2.0.2.aarch64
    mariadb-debuginfo-10.5.10-2.amzn2.0.2.aarch64

src:
    mariadb-10.5.10-2.amzn2.0.2.src

x86_64:
    mariadb-10.5.10-2.amzn2.0.2.x86_64
    mariadb-libs-10.5.10-2.amzn2.0.2.x86_64
    mariadb-config-10.5.10-2.amzn2.0.2.x86_64
    mariadb-common-10.5.10-2.amzn2.0.2.x86_64
    mariadb-errmsg-10.5.10-2.amzn2.0.2.x86_64
    mariadb-server-galera-10.5.10-2.amzn2.0.2.x86_64
    mariadb-server-10.5.10-2.amzn2.0.2.x86_64
    mariadb-oqgraph-engine-10.5.10-2.amzn2.0.2.x86_64
    mariadb-connect-engine-10.5.10-2.amzn2.0.2.x86_64
    mariadb-backup-10.5.10-2.amzn2.0.2.x86_64
    mariadb-rocksdb-engine-10.5.10-2.amzn2.0.2.x86_64
    mariadb-cracklib-password-check-10.5.10-2.amzn2.0.2.x86_64
    mariadb-gssapi-server-10.5.10-2.amzn2.0.2.x86_64
    mariadb-pam-10.5.10-2.amzn2.0.2.x86_64
    mariadb-sphinx-engine-10.5.10-2.amzn2.0.2.x86_64
    mariadb-s3-engine-10.5.10-2.amzn2.0.2.x86_64
    mariadb-server-utils-10.5.10-2.amzn2.0.2.x86_64
    mariadb-devel-10.5.10-2.amzn2.0.2.x86_64
    mariadb-embedded-10.5.10-2.amzn2.0.2.x86_64
    mariadb-embedded-devel-10.5.10-2.amzn2.0.2.x86_64
    mariadb-test-10.5.10-2.amzn2.0.2.x86_64
    mariadb-debuginfo-10.5.10-2.amzn2.0.2.x86_64