Bug 1195325 - (CVE-2021-46657) VUL-1: CVE-2021-46657: mariadb-100,mariadb: get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.
(CVE-2021-46657)
VUL-1: CVE-2021-46657: mariadb-100,mariadb: get_sort_by_table in MariaDB befo...
Status: IN_PROGRESS
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/322164/
CVSSv3.1:SUSE:CVE-2021-46657:3.7:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-01-31 09:57 UTC by Thomas Leroy
Modified: 2022-07-27 16:19 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2022-01-31 09:57:53 UTC
CVE-2021-46657

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via
certain subquery uses of ORDER BY.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-46657
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46657
http://www.cvedetails.com/cve/CVE-2021-46657/
https://jira.mariadb.org/browse/MDEV-25629
Comment 1 Thomas Leroy 2022-01-31 10:00:55 UTC
The fix [0] was introduced in the following versions:
- 10.2.39
- 10.3.30
- 10.4.20
- 10.5.11
- 10.6.2
- 10.7.1

[0] https://github.com/MariaDB/server/commit/e570f740cdabb1774683203ee848d522c6588dbc
Comment 2 Danilo Spinella 2022-01-31 10:43:39 UTC
I think the only thing left for this CVE is just adding the reference number in the changes file, since all SLE codestream have a fixed version already. Can you please confirm?
Comment 3 Thomas Leroy 2022-01-31 10:48:48 UTC
(In reply to Danilo Spinella from comment #2)
> I think the only thing left for this CVE is just adding the reference number
> in the changes file, since all SLE codestream have a fixed version already.
> Can you please confirm?

I think the following codestreams are indeed already fixed:
- SUSE:SLE-12-SP4:Update/mariadb
- SUSE:SLE-15:Update/mariadb	
- SUSE:SLE-15-SP2:Update/mariadb	
- SUSE:SLE-15-SP3:Update/mariadb	
- SUSE:SLE-15-SP4:Update/mariadb

However I think SUSE:SLE-12-SP3:Update:Products:Cloud8:Update is affected. And I am not sure about SUSE:SLE-12-SP1:Update/mariadb and SUSE:SLE-12-SP4:Update/mariadb-100, I am trying to figure out if v10.0.x are affected.

I gave a CVSS of 3.7, let's see the score that NIST will give, but it's very unlikely that the score will be higher than 7.0. 
SUSE:SLE-12-SP3:Update:Products:Cloud8:Update is affected, but due to the CVSS this will be wontfix for this codestream. Am I correct @Danilo?
Comment 4 Thomas Leroy 2022-01-31 13:03:01 UTC
I think that 10.0.x is also affected. Therefore SUSE:SLE-12-SP1:Update/mariadb and SUSE:SLE-12-SP4:Update/mariadb-100 should be affected
Comment 5 Danilo Spinella 2022-01-31 14:17:29 UTC
(In reply to Thomas Leroy from comment #3)
> SUSE:SLE-12-SP3:Update:Products:Cloud8:Update is affected, but due to the
> CVSS this will be wontfix for this codestream. Am I correct @Danilo?

You're right, but the codestream that won't be fixed is SUSE:SLE-12-SP4:Update/mariadb-100. SUSE:SLE-12-SP3:Update:Products:Cloud8:Update is maintained by the Cloud team, so I don't know if mariadb has been updated there.
Comment 6 Thomas Leroy 2022-01-31 14:22:20 UTC
(In reply to Danilo Spinella from comment #5)
> You're right, but the codestream that won't be fixed is
> SUSE:SLE-12-SP4:Update/mariadb-100.
> SUSE:SLE-12-SP3:Update:Products:Cloud8:Update is maintained by the Cloud
> team, so I don't know if mariadb has been updated there.

Alright! As far as I can see, SUSE:SLE-12-SP3:Update:Products:Cloud8:Update contain version 10.2.31, which is vulnerable (fixed in 10.2.39)
Comment 12 Gianluca Gabrielli 2022-02-25 08:41:21 UTC
@cloud-team: please submit a patch for SUSE:SLE-12-SP3:Update:Products:Cloud8:Update/mariadb
Comment 13 Christian Almeida de Oliveira 2022-02-25 10:27:25 UTC
Hi @gianluca, for SOC 8 (Cloud 8) only CVE's with CVSS higher than 7 are considered.
Comment 14 Swamp Workflow Management 2022-03-04 14:24:42 UTC
SUSE-SU-2022:0725-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1195325,1195334,1195339,1196016
CVE References: CVE-2021-46657,CVE-2021-46658,CVE-2021-46659,CVE-2021-46661,CVE-2021-46663,CVE-2021-46664,CVE-2021-46665,CVE-2021-46668,CVE-2022-24048,CVE-2022-24050,CVE-2022-24051,CVE-2022-24052
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    mariadb-10.2.43-3.51.1
SUSE Linux Enterprise Server for SAP 15 (src):    mariadb-10.2.43-3.51.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    mariadb-10.2.43-3.51.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    mariadb-10.2.43-3.51.1
SUSE Linux Enterprise Server 15-LTSS (src):    mariadb-10.2.43-3.51.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    mariadb-10.2.43-3.51.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    mariadb-10.2.43-3.51.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    mariadb-10.2.43-3.51.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    mariadb-10.2.43-3.51.1
SUSE Enterprise Storage 6 (src):    mariadb-10.2.43-3.51.1
SUSE CaaS Platform 4.0 (src):    mariadb-10.2.43-3.51.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 15 Swamp Workflow Management 2022-03-04 14:38:41 UTC
SUSE-SU-2022:0726-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1195325,1195334,1195339,1196016
CVE References: CVE-2021-46657,CVE-2021-46658,CVE-2021-46659,CVE-2021-46661,CVE-2021-46663,CVE-2021-46664,CVE-2021-46665,CVE-2021-46668,CVE-2022-24048,CVE-2022-24050,CVE-2022-24051,CVE-2022-24052
JIRA References: 
Sources used:
SUSE Manager Server 4.1 (src):    mariadb-10.4.24-3.25.1
SUSE Manager Retail Branch Server 4.1 (src):    mariadb-10.4.24-3.25.1
SUSE Manager Proxy 4.1 (src):    mariadb-10.4.24-3.25.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    mariadb-10.4.24-3.25.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    mariadb-10.4.24-3.25.1
SUSE Linux Enterprise Server 15-SP2-BCL (src):    mariadb-10.4.24-3.25.1
SUSE Linux Enterprise Realtime Extension 15-SP2 (src):    mariadb-10.4.24-3.25.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    mariadb-10.4.24-3.25.1
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    mariadb-10.4.24-3.25.1
SUSE Enterprise Storage 7 (src):    mariadb-10.4.24-3.25.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Swamp Workflow Management 2022-03-04 14:39:33 UTC
openSUSE-SU-2022:0726-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1195325,1195334,1195339,1196016
CVE References: CVE-2021-46657,CVE-2021-46658,CVE-2021-46659,CVE-2021-46661,CVE-2021-46663,CVE-2021-46664,CVE-2021-46665,CVE-2021-46668,CVE-2022-24048,CVE-2022-24050,CVE-2022-24051,CVE-2022-24052
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    mariadb-10.4.24-3.25.1
Comment 17 Swamp Workflow Management 2022-03-04 14:40:26 UTC
openSUSE-SU-2022:0725-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1195325,1195334,1195339,1196016
CVE References: CVE-2021-46657,CVE-2021-46658,CVE-2021-46659,CVE-2021-46661,CVE-2021-46663,CVE-2021-46664,CVE-2021-46665,CVE-2021-46668,CVE-2022-24048,CVE-2022-24050,CVE-2022-24051,CVE-2022-24052
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    mariadb-10.2.43-3.51.1
Comment 18 Swamp Workflow Management 2022-03-04 17:21:55 UTC
SUSE-SU-2022:0731-1: An update that fixes 12 vulnerabilities, contains one feature is now available.

Category: security (important)
Bug References: 1195325,1195334,1195339,1196016
CVE References: CVE-2021-46657,CVE-2021-46658,CVE-2021-46659,CVE-2021-46661,CVE-2021-46663,CVE-2021-46664,CVE-2021-46665,CVE-2021-46668,CVE-2022-24048,CVE-2022-24050,CVE-2022-24051,CVE-2022-24052
JIRA References: SLE-22245
Sources used:
SUSE Linux Enterprise Module for Server Applications 15-SP3 (src):    mariadb-10.5.15-150300.3.15.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 19 Swamp Workflow Management 2022-03-04 17:24:59 UTC
openSUSE-SU-2022:0731-1: An update that fixes 12 vulnerabilities, contains one feature is now available.

Category: security (important)
Bug References: 1195325,1195334,1195339,1196016
CVE References: CVE-2021-46657,CVE-2021-46658,CVE-2021-46659,CVE-2021-46661,CVE-2021-46663,CVE-2021-46664,CVE-2021-46665,CVE-2021-46668,CVE-2022-24048,CVE-2022-24050,CVE-2022-24051,CVE-2022-24052
JIRA References: SLE-22245
Sources used:
openSUSE Leap 15.3 (src):    mariadb-10.5.15-150300.3.15.1
Comment 20 Swamp Workflow Management 2022-03-09 17:20:01 UTC
SUSE-SU-2022:0782-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1195325,1195334,1195339,1196016
CVE References: CVE-2021-46657,CVE-2021-46658,CVE-2021-46659,CVE-2021-46661,CVE-2021-46663,CVE-2021-46664,CVE-2021-46665,CVE-2021-46668,CVE-2022-24048,CVE-2022-24050,CVE-2022-24051,CVE-2022-24052
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    mariadb-10.2.43-3.47.1
SUSE OpenStack Cloud 9 (src):    mariadb-10.2.43-3.47.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    mariadb-10.2.43-3.47.1
SUSE Linux Enterprise Server 12-SP5 (src):    mariadb-10.2.43-3.47.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    mariadb-10.2.43-3.47.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 23 Swamp Workflow Management 2022-04-29 13:19:50 UTC
SUSE-SU-2022:0731-2: An update that fixes 12 vulnerabilities, contains one feature is now available.

Category: security (important)
Bug References: 1195325,1195334,1195339,1196016
CVE References: CVE-2021-46657,CVE-2021-46658,CVE-2021-46659,CVE-2021-46661,CVE-2021-46663,CVE-2021-46664,CVE-2021-46665,CVE-2021-46668,CVE-2022-24048,CVE-2022-24050,CVE-2022-24051,CVE-2022-24052
JIRA References: SLE-22245
Sources used:
openSUSE Leap 15.4 (src):    mariadb-10.5.15-150300.3.15.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 25 Swamp Workflow Management 2022-07-27 16:19:01 UTC
SUSE-SU-2022:2561-1: An update that fixes 36 vulnerabilities, contains one feature is now available.

Category: security (important)
Bug References: 1195076,1195325,1195334,1195339,1196016,1198603,1198604,1198605,1198606,1198607,1198609,1198610,1198611,1198612,1198613,1198628,1198629,1198630,1198631,1198632,1198633,1198634,1198635,1198636,1198637,1198638,1198639,1198640,1199928
CVE References: CVE-2021-46657,CVE-2021-46658,CVE-2021-46659,CVE-2021-46661,CVE-2021-46663,CVE-2021-46664,CVE-2021-46665,CVE-2021-46668,CVE-2021-46669,CVE-2022-24048,CVE-2022-24050,CVE-2022-24051,CVE-2022-24052,CVE-2022-27376,CVE-2022-27377,CVE-2022-27378,CVE-2022-27379,CVE-2022-27380,CVE-2022-27381,CVE-2022-27382,CVE-2022-27383,CVE-2022-27384,CVE-2022-27386,CVE-2022-27387,CVE-2022-27444,CVE-2022-27445,CVE-2022-27446,CVE-2022-27447,CVE-2022-27448,CVE-2022-27449,CVE-2022-27451,CVE-2022-27452,CVE-2022-27455,CVE-2022-27456,CVE-2022-27457,CVE-2022-27458
JIRA References: SLE-22245
Sources used:
openSUSE Leap 15.4 (src):    mariadb-10.6.8-150400.3.7.1
SUSE Linux Enterprise Module for Server Applications 15-SP4 (src):    mariadb-10.6.8-150400.3.7.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.