Bug 1201163 - (CVE-2022-32083) VUL-0: CVE-2022-32083: mariadb: segmentation fault via the component Item_subselect:init_expr_cache_tracker
(CVE-2022-32083)
VUL-0: CVE-2022-32083: mariadb: segmentation fault via the component Item_sub...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Danilo Spinella
Security Team bot
https://smash.suse.de/issue/336161/
CVSSv3.1:SUSE:CVE-2022-32083:4.4:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-07-04 12:04 UTC by Alexander Bergmann
Modified: 2023-03-12 18:32 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2022-07-04 12:04:28 UTC
CVE-2022-32083

MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the
component Item_subselect::init_expr_cache_tracker.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-32083
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32083
https://jira.mariadb.org/browse/MDEV-26047
Comment 1 Kristyna Streitova 2022-08-10 15:35:48 UTC
Fix Version/s: 
10.2.44, 10.3.35, 10.4.25, 10.5.16, 10.6.8, 10.7.4, 10.8.3

We've already updated MariaDB to these versions in respective codestreams but this CVE hasn't been mentioned in changes because we updated it in May but the CVE number was assigned in July. We can mention it in the changelog during the next update.
Comment 5 Swamp Workflow Management 2022-09-07 16:33:43 UTC
SUSE-SU-2022:3159-1: An update that solves 10 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1200105,1201161,1201162,1201163,1201164,1201165,1201166,1201167,1201168,1201169,1201170
CVE References: CVE-2022-32081,CVE-2022-32082,CVE-2022-32083,CVE-2022-32084,CVE-2022-32085,CVE-2022-32086,CVE-2022-32087,CVE-2022-32088,CVE-2022-32089,CVE-2022-32091
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    mariadb-10.6.9-150400.3.12.1
SUSE Linux Enterprise Module for Server Applications 15-SP4 (src):    mariadb-10.6.9-150400.3.12.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2022-09-09 10:20:37 UTC
SUSE-SU-2022:3225-1: An update that solves 10 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1197459,1200105,1201161,1201163,1201164,1201165,1201166,1201167,1201168,1201169,1201170
CVE References: CVE-2018-25032,CVE-2022-32081,CVE-2022-32083,CVE-2022-32084,CVE-2022-32085,CVE-2022-32086,CVE-2022-32087,CVE-2022-32088,CVE-2022-32089,CVE-2022-32091
JIRA References: 
Sources used:
SUSE Manager Server 4.1 (src):    mariadb-10.4.26-150200.3.31.1
SUSE Manager Retail Branch Server 4.1 (src):    mariadb-10.4.26-150200.3.31.1
SUSE Manager Proxy 4.1 (src):    mariadb-10.4.26-150200.3.31.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    mariadb-10.4.26-150200.3.31.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    mariadb-10.4.26-150200.3.31.1
SUSE Linux Enterprise Server 15-SP2-BCL (src):    mariadb-10.4.26-150200.3.31.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    mariadb-10.4.26-150200.3.31.1
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    mariadb-10.4.26-150200.3.31.1
SUSE Enterprise Storage 7 (src):    mariadb-10.4.26-150200.3.31.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2022-09-26 16:24:50 UTC
SUSE-SU-2022:3391-1: An update that solves 11 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1200105,1201161,1201162,1201163,1201164,1201165,1201166,1201167,1201168,1201169,1201170,1202863
CVE References: CVE-2022-32081,CVE-2022-32082,CVE-2022-32083,CVE-2022-32084,CVE-2022-32085,CVE-2022-32086,CVE-2022-32087,CVE-2022-32088,CVE-2022-32089,CVE-2022-32091,CVE-2022-38791
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    mariadb-10.5.17-150300.3.21.1
SUSE Linux Enterprise Module for Server Applications 15-SP3 (src):    mariadb-10.5.17-150300.3.21.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src):    mariadb-10.5.17-150300.3.21.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Marcus Meissner 2023-03-12 18:32:19 UTC
done