BIT-mariadb-min-2022-31623

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/mariadb-min/BIT-mariadb-min-2022-31623.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-mariadb-min-2022-31623
Aliases
Published
2025-06-10T11:51:18.181Z
Modified
2025-06-10T12:57:07.494598Z
Summary
[none]
Details

MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/dscompress.cc, when an error occurs (i.e., going to the err label) while executing the method createworkerthreads, the held lock thd->ctrlmutex is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug and not a vulnerability with adverse effects.

Database specific
{
    "cpes": [
        "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / mariadb-min

Package

Name
mariadb-min
Purl
pkg:bitnami/mariadb-min

Severity

  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.2.42
Introduced
10.3.0
Fixed
10.3.33
Introduced
10.4.0
Fixed
10.4.23
Introduced
10.5.0
Fixed
10.5.14
Introduced
10.6.0
Fixed
10.6.6
Introduced
10.7.0
Fixed
10.7.2

Database specific

source

"https://github.com/bitnami/vulndb/tree/main/data/mariadb-min/BIT-mariadb-min-2022-31623.json"