Update Info

SUSE-SLE-Module-Packagehub-Subpackages-15-SP3-2022-3391


Security update for mariadb


Type: security
Severity: important
Issued: 2022-09-26
Description:
This update for mariadb fixes the following issues:

Update to 10.5.17:

- CVE-2022-32082: Fixed assertion failure at table->get_ref_count() == 0 in dict0dict.cc (bsc#1201162).
- CVE-2022-32089: Fixed segmentation fault via the component st_select_lex_unit::exclude_level (bsc#1201169).
- CVE-2022-32081: Fixed use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc (bsc#1201161).
- CVE-2022-32091: Fixed use-after-poison in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc (bsc#1201170).
- CVE-2022-32084: Fixed segmentation fault via the component sub_select (bsc#1201164).
- CVE-2022-38791: Fixed deadlock in compress_write in extra/mariabackup/ds_compress.cc (bsc#1202863).

- CVE-2022-32088: Fixed segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort (bsc#1201168).
- CVE-2022-32087: Fixed segmentation fault via the component Item_args::walk_args (bsc#1201167).
- CVE-2022-32086: Fixed segmentation fault via the component Item_field::fix_outer_field (bsc#1201166).
- CVE-2022-32085: Fixed segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor (bsc#1201165).
- CVE-2022-32083: Fixed segmentation fault via the component Item_subselect::init_expr_cache_tracker (bsc#1201163).

Bugfixes:

- Fixed mysql-systemd-helper being unaware of custom group (bsc#1200105).


              

References


Packages


  • mariadb-10.5.17-150300.3.21.1