Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Fedora 35: 2022-03350936ee Critical: Galera Database Update

fedora
Calendar Grey May 7, 2022
Dist Fedora Esm H88
Fedora 35's latest update enhances Galera, fixing bugs and boosting MariaDB performance, improving clustering and replication for increased stability and user satisfaction
**MariaDB 10.5.15** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10515-release-notes

Summary

Galera is a fast synchronous multi-master wsrep provider (replication engine)

for transactional databases and similar applications. For more information

about wsrep API see https://launchpad.net/wsrep For a description of Galera

replication engine see .

**MariaDB 10.5.15** Release notes:

https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10515-release-notes

* Sun Feb 20 2022 Michal Schorm - 26.4.11-1

- Rebase to 26.4.11

* Thu Jan 20 2022 Fedora Release Engineering - 26.4.9-4

- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild

* Fri Nov 19 2021 Lukas Javorsky - 26.4.9-3

- Explicitly require the 'procps-ng' package

- Otherwise it will not require it in the lightweight systems (e.g. containers)

- and Galera won't work properly

* Tue Sep 14 2021 Sahana Prasad - 26.4.9-2

- Rebuilt with OpenSSL 3.0.0

[ 1 ] Bug #1947388 - DROP TABLE doesn't raise error while dropping non-existing table in MariaDB 10.5.9 when OQGraph SE is loaded to the server

https://bugzilla.redhat.com/show_bug.cgi?id=1947388

[ 2 ] Bug #2019805 - Galera doesn't work without 'procps-ng' package

https://bugzilla.redhat.com/show_bug.cgi?id=2019805

[ 3 ] Bug #2036329 - mysql cli no longer accepts French accented characters

https://bugzilla.redhat.com/show_bug.cgi?id=2036329

[ 4 ] Bug #2055710 - CVE-2021-46659 mariadb: Crash executing query with VIEW, aggregate and subquery [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055710

[ 5 ] Bug #2055743 - CVE-2021-46661 mariadb: MariaDB allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE) [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055743

[ 6 ] Bug #2055749 - CVE-2021-46663 mariadb: MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055749

[ 7 ] Bug #2055755 - CVE-2021-46664 mariadb: MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055755

[ 8 ] Bug #2055761 - CVE-2021-46665 mariadb: MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055761

[ 9 ] Bug #2055768 - CVE-2021-46668 mariadb: MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055768

[ 10 ] Bug #2055835 - CVE-2021-46667 mariadb: Integer overflow in sql_lex.cc integer leading to crash [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055835

[ 11 ] Bug #2059134 - FTBFS: galera does not build in Fedora Rawhide

https://bugzilla.redhat.com/show_bug.cgi?id=2059134

[ 12 ] Bug #2068213 - CVE-2022-24052 mariadb: CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability [fedora-34]

https://bugzilla.redhat.com/show_bug.cgi?id=2068213

[ 13 ] Bug #2068223 - CVE-2022-24052 mariadb: CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability [fedora-35]

https://bugzilla.redhat.com/show_bug.cgi?id=2068223

[ 14 ] Bug #2078293 - CVE-2022-24051 mariadb: lack of proper validation of a user-supplied string before using it as a format specifier [fedora-34]

https://bugzilla.redhat.com/show_bug.cgi?id=2078293

[ 15 ] Bug #2078299 - CVE-2022-24051 mariadb: lack of proper validation of a user-supplied string before using it as a format specifier [fedora-35]

https://bugzilla.redhat.com/show_bug.cgi?id=2078299

[ 16 ] Bug #2078313 - CVE-2022-24048 mariadb: lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer [fedora-34]

https://bugzilla.redhat.com/show_bug.cgi?id=2078313

[ 17 ] Bug #2078316 - CVE-2022-24048 mariadb: lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer [fedora-35]

https://bugzilla.redhat.com/show_bug.cgi?id=2078316

[ 18 ] Bug #2078322 - CVE-2022-24050 mariadb: lack of validating the existence of an object prior to performing operations on the object [fedora-34]

https://bugzilla.redhat.com/show_bug.cgi?id=2078322

[ 19 ] Bug #2078328 - CVE-2022-24050 mariadb: lack of validating the existence of an object prior to performing operations on the object [fedora-35]

https://bugzilla.redhat.com/show_bug.cgi?id=2078328

su -c 'dnf upgrade --advisory FEDORA-2022-03350936ee' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 35
Version: 26.4.11
Release: 1.fc35
Summary: Synchronous multi-master wsrep provider (replication engine)

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here