Related Vulnerabilities: CVE-2022-31624  

MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a denial of service due to the deadlock.

Description

The MITRE CVE dictionary describes this issue as:

MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a denial of service due to the deadlock.

Additional Information

  • Bugzilla 2092362: CVE-2022-31624 mariadb: DoS due to improper locking due to unreleased lock in plugin/server_audit/server_audit.c
  • CWE-404: Improper Resource Shutdown or Release
  • FAQ: Frequently asked questions about CVE-2022-31624