← Back

CVE-2022-38791

nvd nist
Published: Aug 27, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.

Affected (10)

1 product
Mariadb
1 product
Fedora
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Mariadb
From 10.3.0 to 10.3.36
From 10.4.0 to 10.4.26
From 10.5.0 to 10.5.17
From 10.6.0 to 10.6.9
From 10.7.0 to 10.7.5
From 10.8.0 to 10.8.4
Version 10.9.1
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 35
Version 36
Version 37

Timeline

No history available yet.