Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia: 2022-0314 Moderate: Mariadb Memory Corruption and Assertion Fault

mageia
Calendar Grey August 29, 2022
Dist Mageia Esm H88
On August 29, 2022, new mariadb updates addressed memory corruption issues and assertion failure vulnerabilities within Mageia.
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches

Summary

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. (CVE-2018-25032) A use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc. (CVE-2022-32081) An assertion failure at table->get_ref_count() == 0 in dict0dict.cc. (CVE-2022-32082) Segmentation fault via the component sub_select. (CVE-2022-32084) Segmentation fault via the component st_select_lex_unit::exclude_level. (CVE-2022-32089)

References

- https://bugs.mageia.org/show_bug.cgi?id=30754

- https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10517-release-notes

- https://www.cve.org/CVERecord?id=CVE-2018-25032

- https://www.cve.org/CVERecord?id=CVE-2022-32081

- https://www.cve.org/CVERecord?id=CVE-2022-32082

- https://www.cve.org/CVERecord?id=CVE-2022-32084

- https://www.cve.org/CVERecord?id=CVE-2022-32089

- https://www.cve.org/CVERecord?id=CVE-2022-32091

Resolution

SRPMS

- 8/core/mariadb-10.5.17-1.mga8

Publication date: 29 Aug 2022
URL: https://advisories.mageia.org/MGASA-2022-0314.html
Type: security
CVE: CVE-2018-25032, CVE-2022-32081, CVE-2022-32082, CVE-2022-32084, CVE-2022-32089, CVE-2022-32091

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here