Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.DIST
  • Bug#1100437: mariadb: CVE-2023-52969 CVE-2023-52970 CVE-2023-52971

    From Salvatore Bonaccorso@21:1/5 to All on Thu Mar 13 23:00:01 2025
    Source: mariadb
    Version: 1:11.4.5-1
    Severity: important
    Tags: security upstream
    X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

    Hi,

    The following vulnerabilities were published for mariadb.

    CVE-2023-52969[0]:
    | MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7
    | through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an
    | empty backtrace log. This may be related to make_aggr_tables_info
    | and optimize_stage2.


    CVE-2023-52970[1]:
    | MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7
    | through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.*
    | crashes in
    | Item_direct_view_ref::derived_field_transformer_for_where.


    CVE-2023-52971[2]:
    | MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes
    | in JOIN::fix_all_splittings_in_plan.

    There are related MDEV issues referenced upstream and from the limited information this seems to affect the latest versions. The MDEV are not
    public accessible, so can you please clarify with upstream on their
    status.

    If you fix the vulnerabilities please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2023-52969
    https://www.cve.org/CVERecord?id=CVE-2023-52969
    https://jira.mariadb.org/browse/MDEV-32083
    [1] https://security-tracker.debian.org/tracker/CVE-2023-52970
    https://www.cve.org/CVERecord?id=CVE-2023-52970
    https://jira.mariadb.org/browse/MDEV-32086
    [2] https://security-tracker.debian.org/tracker/CVE-2023-52971
    https://www.cve.org/CVERecord?id=CVE-2023-52971
    https://jira.mariadb.org/browse/MDEV-32084

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From =?UTF-8?B?T3R0byBLZWvDpGzDpGluZW4=?@21:1/5 to All on Thu Mar 13 23:10:01 2025
    Thanks for the heads-up. None of these are visible on https://mariadb.com/kb/en/security/ yet.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Adam Fancher
      Thu May 22 20:51:38 2025
      from Winsted, Ct via Telnet
    • Jokke
      Thu May 22 20:13:05 2025
      from Be via Telnet
    • Jokke
      Thu May 22 15:51:38 2025
      from Be via Telnet
    • Adam Fancher
      Thu May 22 15:27:52 2025
      from Winsted, Ct via Telnet
    • Skwx
      Thu May 22 15:25:23 2025
      from London, Uk via Telnet
    • Jokke
      Thu May 22 11:19:03 2025
      from Be via Telnet
    • Jokke
      Thu May 22 10:58:11 2025
      from Be via Telnet
    • Jokke
      Thu May 22 10:43:16 2025
      from Be via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 481
    Nodes: 16 (2 / 14)
    Uptime: 14:36:45
    Calls: 9,540
    Calls today: 8
    Files: 13,653
    Messages: 6,139,623
    Posted today: 1

© >>> Magnum BBS <<<, 2025