MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/serveraudit/serveraudit.c method logstatementex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a denial of service due to the deadlock.
[
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"90711998564806735195805859599695974488",
"250235656453474445952886226940630586901",
"138601424526244396688102904980203116856",
"260899504695773825099167960290426804286",
"195618794319389720373887341924388728956",
"235225536445748945692084098199749057201",
"31883114073388339147653063826921368361",
"197917030096083514348454819156402060362",
"289230583495206341900450989516810730650",
"91430430361054231056328722674418866585",
"77643133024047768721912717814398829819",
"320552537875945211561760460640784081150",
"105789923430061880194312968275998308603",
"98735563345642094680434238620443677187",
"292031684763090909993275794773076322308",
"92489659976201637249318478726246706024",
"27007173774237668602419387574308086290",
"274122217988597580338963001472301063072",
"300963376605594763791233698212657871132",
"26572807623540130495412504265101171947",
"66215638979692992416579566907711463705",
"303932196489732739924874928020261281051",
"113940657857467622423686902261834598417",
"331452141832298997014984331662191676077",
"208780544668844162214639230045198014431",
"51175193043033892703788848976725360034",
"295660115854400421342896505650256948479",
"35098586381009888889512332354175616121",
"283810331822564743159193848861315334503",
"326402544696859951904373527823434289044",
"92823256719393566777045561395813687873",
"293733344546467634335795315081711120116",
"275312355389525935055558046435670752820",
"243074016587120086829191301778761339000",
"84155445143525991563516771469806392016",
"271349187173497616455976187008678950698",
"93604260207551949815101346941943719267",
"90978700924351308299517326809194195046",
"38508214844301462891858640833477141052",
"106079778222993512903751763731120692597",
"290487621905075585846882912372845753214",
"31557689926468019009368634742709831835",
"90767754057816029463892744414730377001",
"28596287046245976445032249206946795832",
"109749886240234928794249123406894187768",
"284808872374891894869097567934294674017",
"279399910199429446361672530887901626278",
"83474200343153023088513681884050655343",
"276125084189040160593261940922046663677",
"4626733841424454083806093044308943681",
"6141779977975797060391828250288999884",
"237846036462394682827350038206442158043",
"137364733800278379521916866831845789459",
"1484270925556905909558539122805529576",
"331479318533556605097644896467278117922",
"117299276375238609187406297257687113891",
"307471933080226789218435425833536169797",
"334873379364503629241668652362502488215",
"158836082376971200932844697620135032127",
"92094223751136598475424808555861066367"
],
"threshold": 0.9
},
"source": "https://github.com/mariadb/server/commit/d627d00b13ab2f2c0954ea7b77202470cb102944",
"deprecated": false,
"id": "CVE-2022-31624-21bfa473",
"signature_version": "v1",
"target": {
"file": "plugin/server_audit/server_audit.c"
}
},
{
"signature_type": "Function",
"digest": {
"length": 3203.0,
"function_hash": "68208181369720662953476210177932291928"
},
"source": "https://github.com/mariadb/server/commit/d627d00b13ab2f2c0954ea7b77202470cb102944",
"deprecated": false,
"id": "CVE-2022-31624-429159e8",
"signature_version": "v1",
"target": {
"function": "log_statement_ex",
"file": "plugin/server_audit/server_audit.c"
}
}
]