Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 36: 2022-263f7cc483 Critical: MariaDB 10.5.15 SQL Update

fedora
Calendar Grey May 7, 2022
Dist Fedora Esm H88
The release of MariaDB 10.5.15 for Fedora 36 brings essential enhancements and patches aimed at boosting security and overall system stability.
**MariaDB 10.5.15** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10515-release-notes

Summary

MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded

SQL database server. It is a client/server implementation consisting of

a server daemon (mariadbd) and many different client programs and libraries.

The base package contains the standard MariaDB/MySQL client programs and

utilities.

**MariaDB 10.5.15** Release notes:

https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10515-release-notes

* Sun Feb 20 2022 Michal Schorm - 3:10.5.15-1

- Rebase to 10.5.15

* Mon Feb 7 2022 Honza Horak - 3:10.5.13-3

- Fix md5 in FIPS mode with OpenSSL 3.0.0

Resolves: #2050541

* Thu Jan 20 2022 Fedora Release Engineering - 3:10.5.13-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild

[ 1 ] Bug #1947388 - DROP TABLE doesn't raise error while dropping non-existing table in MariaDB 10.5.9 when OQGraph SE is loaded to the server

https://bugzilla.redhat.com/show_bug.cgi?id=1947388

[ 2 ] Bug #2019805 - Galera doesn't work without 'procps-ng' package

https://bugzilla.redhat.com/show_bug.cgi?id=2019805

[ 3 ] Bug #2036329 - mysql cli no longer accepts French accented characters

https://bugzilla.redhat.com/show_bug.cgi?id=2036329

[ 4 ] Bug #2055710 - CVE-2021-46659 mariadb: Crash executing query with VIEW, aggregate and subquery [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055710

[ 5 ] Bug #2055743 - CVE-2021-46661 mariadb: MariaDB allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE) [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055743

[ 6 ] Bug #2055749 - CVE-2021-46663 mariadb: MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055749

[ 7 ] Bug #2055755 - CVE-2021-46664 mariadb: MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055755

[ 8 ] Bug #2055761 - CVE-2021-46665 mariadb: MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055761

[ 9 ] Bug #2055768 - CVE-2021-46668 mariadb: MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055768

[ 10 ] Bug #2055835 - CVE-2021-46667 mariadb: Integer overflow in sql_lex.cc integer leading to crash [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2055835

[ 11 ] Bug #2059134 - FTBFS: galera does not build in Fedora Rawhide

https://bugzilla.redhat.com/show_bug.cgi?id=2059134

[ 12 ] Bug #2068213 - CVE-2022-24052 mariadb: CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability [fedora-34]

https://bugzilla.redhat.com/show_bug.cgi?id=2068213

[ 13 ] Bug #2068223 - CVE-2022-24052 mariadb: CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability [fedora-35]

https://bugzilla.redhat.com/show_bug.cgi?id=2068223

[ 14 ] Bug #2078293 - CVE-2022-24051 mariadb: lack of proper validation of a user-supplied string before using it as a format specifier [fedora-34]

https://bugzilla.redhat.com/show_bug.cgi?id=2078293

[ 15 ] Bug #2078299 - CVE-2022-24051 mariadb: lack of proper validation of a user-supplied string before using it as a format specifier [fedora-35]

https://bugzilla.redhat.com/show_bug.cgi?id=2078299

[ 16 ] Bug #2078313 - CVE-2022-24048 mariadb: lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer [fedora-34]

https://bugzilla.redhat.com/show_bug.cgi?id=2078313

[ 17 ] Bug #2078316 - CVE-2022-24048 mariadb: lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer [fedora-35]

https://bugzilla.redhat.com/show_bug.cgi?id=2078316

[ 18 ] Bug #2078322 - CVE-2022-24050 mariadb: lack of validating the existence of an object prior to performing operations on the object [fedora-34]

https://bugzilla.redhat.com/show_bug.cgi?id=2078322

[ 19 ] Bug #2078328 - CVE-2022-24050 mariadb: lack of validating the existence of an object prior to performing operations on the object [fedora-35]

https://bugzilla.redhat.com/show_bug.cgi?id=2078328

su -c 'dnf upgrade --advisory FEDORA-2022-263f7cc483' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 36
Version: 10.5.15
Release: 1.fc36
Summary: A very fast and robust SQL database server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here