CVE-2022-38791
Published on: Not Yet Published
Last Modified on: 12/08/2022 03:44:00 AM UTC
Certain versions of Fedora from Fedoraproject contain the following vulnerability:
In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.
- CVE-2022-38791 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
[SECURITY] Fedora 35 Update: mariadb-10.5.18-1.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
[SECURITY] Fedora 36 Update: galera-26.4.13-1.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
[SECURITY] Fedora 37 Update: mariadb-10.5.18-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
CVE-2022-38791 MariaDB Vulnerability in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
[MDEV-28719] compress_write() fails to release mutex on failure - Jira | jira.mariadb.org text/html |
![]() |
Related QID Numbers
- 181409 Debian Security Update for mariadb-10.5 (CVE-2022-38791)
- 283363 Fedora Security Update for galera (FEDORA-2022-cf88f807f9)
- 283364 Fedora Security Update for galera (FEDORA-2022-333df1c4aa)
- 283406 Fedora Security Update for galera (FEDORA-2022-e0e9a43546)
- 753464 SUSE Enterprise Linux Security Update for mariadb (SUSE-SU-2022:3391-1)
- 903736 Common Base Linux Mariner (CBL-Mariner) Security Update for mariadb (10780)
- 904216 Common Base Linux Mariner (CBL-Mariner) Security Update for mariadb (10780-1)
Exploit/POC from Github
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Fedoraproject | Fedora | 35 | All | All | All |
Operating System | Fedoraproject | Fedora | 36 | All | All | All |
Operating System | Fedoraproject | Fedora | 37 | All | All | All |
Application | Mariadb | Mariadb | All | All | All | All |
Application | Mariadb | Mariadb | 10.9.1 | All | All | All |
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*:
- cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*:
- cpe:2.3:a:mariadb:mariadb:10.9.1:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-38791 : In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data… twitter.com/i/web/status/1… | 2022-08-27 20:04:09 |
![]() |
CVE-2022-38791 In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_m… twitter.com/i/web/status/1… | 2022-08-27 23:26:50 |
![]() |
Emerging Vulnerability Found CVE-2022-38791 - In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_comp… twitter.com/i/web/status/1… | 2022-08-27 23:26:58 |
![]() |
Mariadb - CVE-2022-38791: jira.mariadb.org/browse/MDEV-28… | 2022-08-28 00:02:46 |
![]() |
CVE-2022-38791 In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_m… twitter.com/i/web/status/1… | 2022-08-28 07:09:55 |
![]() |
CVE-2022-38791 dlvr.it/SXMSVz | 2022-08-28 08:25:42 |
![]() |
CVE-2022-38791 | 2022-08-27 21:01:03 |