
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-27445 affects MariaDB Server versions up to 10.9, specifically involving a segmentation fault in the component sql/sql_window.cc. The vulnerability was discovered in early 2022 and received a CVSS v3.1 base score of 7.5 (High) (NVD).
The vulnerability manifests as a segmentation fault in the MariaDB Server's window functions component, specifically in the sql/sql_window.cc file. The issue occurs during the comparison of order elements in window functions, leading to an assertion failure in the compare_order_elements function (MariaDB Issue). The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating network accessibility with no required privileges or user interaction (NetApp Advisory).
When successfully exploited, this vulnerability can lead to a Denial of Service (DoS) condition through a segmentation fault in the database server. The high availability impact (A:H) in the CVSS score indicates that the vulnerability can cause a complete denial of access to the targeted system (NetApp Advisory).
The vulnerability has been fixed in MariaDB versions 10.2.44, 10.3.35, 10.4.25, 10.5.16, 10.6.8, 10.7.4, and 10.8.3. Users are advised to upgrade to these or later versions to mitigate the vulnerability (Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."