MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/serveraudit/serveraudit.c method logstatementex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a denial of service due to the deadlock.
{ "vanir_signatures": [ { "deprecated": false, "source": "https://github.com/mariadb/server/commit/d627d00b13ab2f2c0954ea7b77202470cb102944", "target": { "file": "plugin/server_audit/server_audit.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "90711998564806735195805859599695974488", "250235656453474445952886226940630586901", "138601424526244396688102904980203116856", "260899504695773825099167960290426804286", "195618794319389720373887341924388728956", "235225536445748945692084098199749057201", "31883114073388339147653063826921368361", "197917030096083514348454819156402060362", "289230583495206341900450989516810730650", "91430430361054231056328722674418866585", "77643133024047768721912717814398829819", "320552537875945211561760460640784081150", "105789923430061880194312968275998308603", "98735563345642094680434238620443677187", "292031684763090909993275794773076322308", "92489659976201637249318478726246706024", "27007173774237668602419387574308086290", "274122217988597580338963001472301063072", "300963376605594763791233698212657871132", "26572807623540130495412504265101171947", "66215638979692992416579566907711463705", "303932196489732739924874928020261281051", "113940657857467622423686902261834598417", "331452141832298997014984331662191676077", "208780544668844162214639230045198014431", "51175193043033892703788848976725360034", "295660115854400421342896505650256948479", "35098586381009888889512332354175616121", "283810331822564743159193848861315334503", "326402544696859951904373527823434289044", "92823256719393566777045561395813687873", "293733344546467634335795315081711120116", "275312355389525935055558046435670752820", "243074016587120086829191301778761339000", "84155445143525991563516771469806392016", "271349187173497616455976187008678950698", "93604260207551949815101346941943719267", "90978700924351308299517326809194195046", "38508214844301462891858640833477141052", "106079778222993512903751763731120692597", "290487621905075585846882912372845753214", "31557689926468019009368634742709831835", "90767754057816029463892744414730377001", "28596287046245976445032249206946795832", "109749886240234928794249123406894187768", "284808872374891894869097567934294674017", "279399910199429446361672530887901626278", "83474200343153023088513681884050655343", "276125084189040160593261940922046663677", "4626733841424454083806093044308943681", "6141779977975797060391828250288999884", "237846036462394682827350038206442158043", "137364733800278379521916866831845789459", "1484270925556905909558539122805529576", "331479318533556605097644896467278117922", "117299276375238609187406297257687113891", "307471933080226789218435425833536169797", "334873379364503629241668652362502488215", "158836082376971200932844697620135032127", "92094223751136598475424808555861066367" ] }, "id": "CVE-2022-31624-21bfa473", "signature_version": "v1", "signature_type": "Line" }, { "deprecated": false, "source": "https://github.com/mariadb/server/commit/d627d00b13ab2f2c0954ea7b77202470cb102944", "target": { "function": "log_statement_ex", "file": "plugin/server_audit/server_audit.c" }, "digest": { "function_hash": "68208181369720662953476210177932291928", "length": 3203.0 }, "id": "CVE-2022-31624-429159e8", "signature_version": "v1", "signature_type": "Function" } ] }