CVE-2022-27383

HIGH7.5EPSS 0.24%
Published: 4/12/2022Modified: 4/28/2026
Also known as:ALPINE-CVE-2022-27383DEBIAN-CVE-2022-27383

Description

MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.

Affected packages (5)

  • Alpine/mariadbfrom 0, < 10.4.25-r0
  • Bitnami/mariadb>= 10.2.0, < 10.2.44, >= 10.3.0, < 10.3.35, >= 10.4.0, < 10.4.25, >= 10.5.0, < 10.5.16, >= 10.6.0, < 10.6.8, >= 10.7.0, < 10.7.4, >= 10.8.0, < 10.8.3
  • Bitnami/mariadb-min>= 10.2.0, < 10.2.44, >= 10.3.0, < 10.3.35, >= 10.4.0, < 10.4.25, >= 10.5.0, < 10.5.16, >= 10.6.0, < 10.6.8, >= 10.7.0, < 10.7.4, >= 10.8.0, < 10.8.3
  • Bitnami/mysql-client>= 10.2.0, < 10.2.44, >= 10.3.0, < 10.3.35, >= 10.4.0, < 10.4.25, >= 10.5.0, < 10.5.16, >= 10.6.0, < 10.6.8, >= 10.7.0, < 10.7.4, >= 10.8.0, < 10.8.3
  • Debian/mariadb-10.5from 0, < 1:10.5.18-0+deb11u1

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (6)