CVE-2021-35604

Source
https://cve.org/CVERecord?id=CVE-2021-35604
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35604.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-35604
Aliases
Downstream
Related
Published
2021-10-20T11:17:06.087Z
Modified
2026-03-15T22:43:31.225566Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
[none]
Details

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.35 and prior and 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

References

Affected packages

Git / github.com/mariadb/server

Affected ranges

Type
GIT
Repo
https://github.com/mariadb/server
Events
Database specific
{
    "versions": [
        {
            "introduced": "10.2.0"
        },
        {
            "fixed": "10.2.41"
        },
        {
            "introduced": "10.3.0"
        },
        {
            "fixed": "10.3.32"
        },
        {
            "introduced": "10.4.0"
        },
        {
            "fixed": "10.4.22"
        },
        {
            "introduced": "10.5.0"
        },
        {
            "fixed": "10.5.13"
        },
        {
            "introduced": "10.6.0"
        },
        {
            "fixed": "10.6.3"
        }
    ]
}
Type
GIT
Repo
https://github.com/mysql/mysql-server
Events
Database specific
{
    "versions": [
        {
            "introduced": "8.0.0"
        },
        {
            "last_affected": "8.0.26"
        }
    ]
}

Affected versions

mariadb-10.*
mariadb-10.0.25
mariadb-10.0.26
mariadb-10.0.27
mariadb-10.0.28
mariadb-10.0.29
mariadb-10.0.30
mariadb-10.0.31
mariadb-10.0.32
mariadb-10.0.33
mariadb-10.0.34
mariadb-10.0.35
mariadb-10.0.36
mariadb-10.0.37
mariadb-10.0.38
mariadb-10.1.14
mariadb-10.1.15
mariadb-10.1.16
mariadb-10.1.17
mariadb-10.1.18
mariadb-10.1.19
mariadb-10.1.20
mariadb-10.1.21
mariadb-10.1.22
mariadb-10.1.23
mariadb-10.1.24
mariadb-10.1.25
mariadb-10.1.26
mariadb-10.1.27
mariadb-10.1.28
mariadb-10.1.29
mariadb-10.1.30
mariadb-10.1.31
mariadb-10.1.32
mariadb-10.1.33
mariadb-10.1.34
mariadb-10.1.35
mariadb-10.1.36
mariadb-10.1.37
mariadb-10.1.38
mariadb-10.1.39
mariadb-10.1.40
mariadb-10.1.41
mariadb-10.1.42
mariadb-10.1.43
mariadb-10.1.44
mariadb-10.1.45
mariadb-10.1.46
mariadb-10.1.47
mariadb-10.2.0
mariadb-10.2.1
mariadb-10.2.10
mariadb-10.2.11
mariadb-10.2.12
mariadb-10.2.13
mariadb-10.2.14
mariadb-10.2.15
mariadb-10.2.16
mariadb-10.2.17
mariadb-10.2.18
mariadb-10.2.19
mariadb-10.2.2
mariadb-10.2.20
mariadb-10.2.21
mariadb-10.2.22
mariadb-10.2.23
mariadb-10.2.24
mariadb-10.2.25
mariadb-10.2.26
mariadb-10.2.27
mariadb-10.2.28
mariadb-10.2.29
mariadb-10.2.3
mariadb-10.2.30
mariadb-10.2.31
mariadb-10.2.32
mariadb-10.2.33
mariadb-10.2.34
mariadb-10.2.35
mariadb-10.2.36
mariadb-10.2.37
mariadb-10.2.38
mariadb-10.2.39
mariadb-10.2.4
mariadb-10.2.40
mariadb-10.2.5
mariadb-10.2.6
mariadb-10.2.7
mariadb-10.2.8
mariadb-10.2.9
mariadb-5.*
mariadb-5.5.49
mariadb-5.5.50
mariadb-5.5.51
mariadb-5.5.52
mariadb-5.5.53
mariadb-5.5.54
mariadb-5.5.55
mariadb-5.5.56
mariadb-5.5.57
mariadb-5.5.58
mariadb-5.5.59
mariadb-5.5.60
mariadb-5.5.61
mariadb-5.5.62
mariadb-5.5.63
mariadb-5.5.64
mariadb-5.5.65
mariadb-5.5.66
mariadb-5.5.67
mariadb-5.5.68
mariadb-galera-10.*
mariadb-galera-10.0.25
mariadb-galera-10.0.26
mariadb-galera-10.0.27
mariadb-galera-10.0.28
mariadb-galera-10.0.29
mariadb-galera-10.0.30
mariadb-galera-10.0.31
mariadb-galera-10.0.32
mariadb-galera-10.0.33
mariadb-galera-10.0.34
mariadb-galera-10.0.35
mariadb-galera-10.0.36
mariadb-galera-10.0.37
mariadb-galera-5.*
mariadb-galera-5.5.49
mariadb-galera-5.5.50
mariadb-galera-5.5.51
mariadb-galera-5.5.52
mariadb-galera-5.5.53
mariadb-galera-5.5.54
mariadb-galera-5.5.55
mariadb-galera-5.5.56
mariadb-galera-5.5.57
mariadb-galera-5.5.58
mariadb-galera-5.5.59
mariadb-galera-5.5.60
mariadb-galera-5.5.61
mariadb-galera-5.5.62
mysql-5.*
mysql-5.5.49
mysql-5.5.50
mysql-5.5.51
mysql-5.5.52
mysql-5.5.53
mysql-5.5.54
mysql-5.5.55
mysql-5.5.56
mysql-5.5.57
mysql-5.5.58
mysql-5.5.59
mysql-5.5.60
mysql-5.5.61
mysql-5.5.62
mysql-5.5.63
mysql-5.6.33
mysql-5.6.34
mysql-5.6.35
mysql-5.6.36
mysql-5.6.37
mysql-5.6.38
mysql-5.6.39
mysql-5.6.40
mysql-5.6.41
mysql-5.6.42
mysql-5.6.43
mysql-5.6.45
mysql-5.6.46
mysql-5.6.47
mysql-5.6.48
mysql-5.6.49
mysql-5.6.50
mysql-5.6.51
mysql-5.7-22-ndb-7.6.6
mysql-5.7.15
mysql-5.7.16
mysql-5.7.17
mysql-5.7.18
mysql-5.7.19
mysql-5.7.20
mysql-5.7.21
mysql-5.7.22
mysql-5.7.24
mysql-5.7.25
mysql-5.7.26
mysql-5.7.27
mysql-5.7.28
mysql-5.7.29
mysql-5.7.30
mysql-5.7.31
mysql-5.7.32
mysql-5.7.33
mysql-5.7.34
mysql-8.*
mysql-8.0.0
mysql-8.0.1
mysql-8.0.11
mysql-8.0.12
mysql-8.0.13
mysql-8.0.14
mysql-8.0.15
mysql-8.0.16
mysql-8.0.17
mysql-8.0.18
mysql-8.0.19
mysql-8.0.2
mysql-8.0.20
mysql-8.0.21
mysql-8.0.22
mysql-8.0.23
mysql-8.0.24
mysql-8.0.25
mysql-8.0.26
mysql-8.0.3
mysql-8.0.4
mysql-cluster-7.*
mysql-cluster-7.2.24
mysql-cluster-7.2.25
mysql-cluster-7.2.26
mysql-cluster-7.2.27
mysql-cluster-7.2.28
mysql-cluster-7.2.29
mysql-cluster-7.2.30
mysql-cluster-7.2.31
mysql-cluster-7.2.32
mysql-cluster-7.2.33
mysql-cluster-7.2.34
mysql-cluster-7.2.35
mysql-cluster-7.2.37
mysql-cluster-7.2.38
mysql-cluster-7.2.39
mysql-cluster-7.2.40
mysql-cluster-7.3.13
mysql-cluster-7.3.14
mysql-cluster-7.3.15
mysql-cluster-7.3.16
mysql-cluster-7.3.17
mysql-cluster-7.3.18
mysql-cluster-7.3.19
mysql-cluster-7.3.20
mysql-cluster-7.3.21
mysql-cluster-7.3.22
mysql-cluster-7.3.23
mysql-cluster-7.3.24
mysql-cluster-7.3.25
mysql-cluster-7.3.26
mysql-cluster-7.3.27
mysql-cluster-7.3.28
mysql-cluster-7.3.29
mysql-cluster-7.3.30
mysql-cluster-7.3.31
mysql-cluster-7.3.33
mysql-cluster-7.4.11
mysql-cluster-7.4.12
mysql-cluster-7.4.13
mysql-cluster-7.4.14
mysql-cluster-7.4.15
mysql-cluster-7.4.16
mysql-cluster-7.4.17
mysql-cluster-7.4.18
mysql-cluster-7.4.19
mysql-cluster-7.4.20
mysql-cluster-7.4.21
mysql-cluster-7.4.23
mysql-cluster-7.4.24
mysql-cluster-7.4.25
mysql-cluster-7.4.26
mysql-cluster-7.4.27
mysql-cluster-7.4.28
mysql-cluster-7.4.29
mysql-cluster-7.4.30
mysql-cluster-7.4.32
mysql-cluster-7.5.1
mysql-cluster-7.5.10
mysql-cluster-7.5.11
mysql-cluster-7.5.12
mysql-cluster-7.5.13
mysql-cluster-7.5.14
mysql-cluster-7.5.15
mysql-cluster-7.5.16
mysql-cluster-7.5.17
mysql-cluster-7.5.18
mysql-cluster-7.5.19
mysql-cluster-7.5.2
mysql-cluster-7.5.20
mysql-cluster-7.5.21
mysql-cluster-7.5.3
mysql-cluster-7.5.4
mysql-cluster-7.5.5
mysql-cluster-7.5.6
mysql-cluster-7.5.7
mysql-cluster-7.5.8
mysql-cluster-7.5.9
mysql-cluster-7.6.10
mysql-cluster-7.6.11
mysql-cluster-7.6.12
mysql-cluster-7.6.13
mysql-cluster-7.6.14
mysql-cluster-7.6.15
mysql-cluster-7.6.16
mysql-cluster-7.6.17
mysql-cluster-7.6.2
mysql-cluster-7.6.3
mysql-cluster-7.6.4
mysql-cluster-7.6.5
mysql-cluster-7.6.6
mysql-cluster-7.6.7
mysql-cluster-7.6.8
mysql-cluster-7.6.9
mysql-cluster-8.*
mysql-cluster-8.0.16
mysql-cluster-8.0.18
mysql-cluster-8.0.19
mysql-cluster-8.0.20
mysql-cluster-8.0.21
mysql-cluster-8.0.22
mysql-cluster-8.0.23
mysql-cluster-8.0.24
mysql-cluster-8.0.25
mysql-cluster-8.0.26

Database specific

vanir_signatures
[
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "131649957694533731721940309055820975752",
                "249452647439853322414702137565205958351",
                "201969777012246482841882403852745931746",
                "95578070551738783324854304889376330162",
                "249398730562238721197312579126910521732",
                "272906839712165971131454335608419438521",
                "107318663712936600961191413243544821067",
                "180839139384475678538465324643300020059",
                "282394023504767334221966027397455256851"
            ]
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2021-35604-0f0e4c3d",
        "target": {
            "file": "sql/sp_head.cc"
        },
        "source": "https://github.com/mariadb/server/commit/561b6c7e513abc4ceba263252b519bf715ce80f4"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "246197311705367672488779414942418338437",
                "276461508094209904860358154457724219596",
                "119856287420192600807656416768471292892",
                "307523178086602816378726753514303591471"
            ]
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2021-35604-a5b111ca",
        "target": {
            "file": "sql/sql_class.h"
        },
        "source": "https://github.com/mariadb/server/commit/561b6c7e513abc4ceba263252b519bf715ce80f4"
    },
    {
        "digest": {
            "length": 526.0,
            "function_hash": "313645379892638120418940088368384842330"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2021-35604-c0b6a67c",
        "target": {
            "function": "trans_cannot_safely_rollback",
            "file": "sql/log.cc"
        },
        "source": "https://github.com/mariadb/server/commit/561b6c7e513abc4ceba263252b519bf715ce80f4"
    },
    {
        "digest": {
            "length": 5738.0,
            "function_hash": "58969679078610265830587969385269203468"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2021-35604-c2087e13",
        "target": {
            "function": "MYSQL_BIN_LOG::write",
            "file": "sql/log.cc"
        },
        "source": "https://github.com/mariadb/server/commit/561b6c7e513abc4ceba263252b519bf715ce80f4"
    },
    {
        "digest": {
            "length": 1646.0,
            "function_hash": "306699274100027957454330329145370130558"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2021-35604-c7e73326",
        "target": {
            "function": "binlog_rollback",
            "file": "sql/log.cc"
        },
        "source": "https://github.com/mariadb/server/commit/561b6c7e513abc4ceba263252b519bf715ce80f4"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "37241440461655139304666183504430673984",
                "321123901233127987586838407173769763021",
                "72261390377549520472738172439120219059",
                "177685578562853608336609164621767055897",
                "89819371651002091070891492658372534238",
                "51099385615472244965869900895991310181",
                "46580225994766933062920841006192426125",
                "315917086551178982883049352244998712855",
                "151578589657138643687922568393137771305",
                "17554905964382256978464037543366371516",
                "44471072352567830517014260687216170718",
                "24734019721218526304965298857312980362",
                "170961031791040395953313676921959415915",
                "270863138330118960816828040809003942807",
                "193741668719766893391486278801760873722",
                "187930135527712657567073811467820013048",
                "463263057525947197303571514490382636",
                "339713228808563234771781256013265010488",
                "60867587337001395239385720816441536057",
                "201702182182638939619765504430616936017",
                "57432871140975116606615382999074109620",
                "84713255884193508387326659336658799628",
                "26176627625780710469062407865406490363",
                "43796184043138950845306782231229762899",
                "324404121552377421361400005592716783209",
                "327933765027016333514108949053193264778",
                "64468012293600814982757536651285167827",
                "7202594327949745606575738191994274437",
                "262509239196084693497735668412073064246",
                "337977078646117299838774945463804836390",
                "10862040297338291254194597838720262756",
                "83515971079454692103282106460082729171",
                "189738111660857520124962685258236418556",
                "32778699285218945562928993184558074443",
                "218701964979892061313721302653462012734",
                "187533463339481117482532077546372282049",
                "202341581865934325003292198703136040956",
                "155258852623302621764107560349238231581",
                "159919742848761288642405190297761552689",
                "147668741816814608585313009494181079624",
                "218818688557001123571703121311150830495",
                "148772925594895409927511713164729652512",
                "95985790907239484288997369415539433967",
                "255840666226744218838219627455521697435",
                "255600561411523879536850015147493893481",
                "27747137695801633233169226083338797085"
            ]
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2021-35604-cbcd0de0",
        "target": {
            "file": "sql/log.cc"
        },
        "source": "https://github.com/mariadb/server/commit/561b6c7e513abc4ceba263252b519bf715ce80f4"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "119521046618748345254444704918727070434",
                "200452323826260590731762179699296029024",
                "251509020612362925913253356211500341353",
                "261751524541214367584170806104141027470",
                "201306130400997636080714619460096506715",
                "35155932094167429544231535939915658820"
            ]
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2021-35604-cd9394d7",
        "target": {
            "file": "sql/handler.h"
        },
        "source": "https://github.com/mariadb/server/commit/561b6c7e513abc4ceba263252b519bf715ce80f4"
    },
    {
        "digest": {
            "length": 2658.0,
            "function_hash": "336328390458211521927718962871514707351"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2021-35604-ed8021c5",
        "target": {
            "function": "sp_lex_keeper::reset_lex_and_exec_core",
            "file": "sql/sp_head.cc"
        },
        "source": "https://github.com/mariadb/server/commit/561b6c7e513abc4ceba263252b519bf715ce80f4"
    }
]
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "5.7.0"
            },
            {
                "last_affected": "5.7.35"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "33"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "34"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "35"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35604.json"