CVE-2021-46667

Source
https://cve.org/CVERecord?id=CVE-2021-46667
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-46667.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-46667
Aliases
Downstream
Related
Published
2022-02-01T02:15:07.077Z
Modified
2026-02-05T09:58:53.761102Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.

References

Affected packages

Git / github.com/mariadb/server

Affected versions

mariadb-10.*
mariadb-10.0.38
mariadb-10.1.38
mariadb-10.1.39
mariadb-10.1.40
mariadb-10.1.41
mariadb-10.1.42
mariadb-10.1.43
mariadb-10.1.44
mariadb-10.1.45
mariadb-10.1.46
mariadb-10.1.47
mariadb-10.2.19
mariadb-10.2.20
mariadb-10.2.21
mariadb-10.2.22
mariadb-10.2.23
mariadb-10.2.24
mariadb-10.2.25
mariadb-10.2.26
mariadb-10.2.27
mariadb-10.2.28
mariadb-10.2.29
mariadb-10.2.30
mariadb-10.2.31
mariadb-10.2.32
mariadb-10.2.33
mariadb-10.2.34
mariadb-10.2.35
mariadb-10.2.36
mariadb-10.2.37
mariadb-10.2.38
mariadb-10.2.39
mariadb-10.2.40
mariadb-10.2.41
mariadb-10.3.11
mariadb-10.3.12
mariadb-10.3.13
mariadb-10.3.14
mariadb-10.3.15
mariadb-10.3.16
mariadb-10.3.17
mariadb-10.3.18
mariadb-10.3.19
mariadb-10.3.20
mariadb-10.3.21
mariadb-10.3.22
mariadb-10.3.23
mariadb-10.3.24
mariadb-10.3.25
mariadb-10.3.26
mariadb-10.3.27
mariadb-10.3.28
mariadb-10.3.29
mariadb-10.3.30
mariadb-10.3.31
mariadb-10.3.32
mariadb-10.4.0
mariadb-10.4.1
mariadb-10.4.10
mariadb-10.4.11
mariadb-10.4.12
mariadb-10.4.13
mariadb-10.4.14
mariadb-10.4.15
mariadb-10.4.16
mariadb-10.4.17
mariadb-10.4.18
mariadb-10.4.19
mariadb-10.4.2
mariadb-10.4.20
mariadb-10.4.21
mariadb-10.4.22
mariadb-10.4.3
mariadb-10.4.4
mariadb-10.4.5
mariadb-10.4.6
mariadb-10.4.7
mariadb-10.4.8
mariadb-10.4.9
mariadb-10.5.0
mariadb-10.5.1
mariadb-10.5.10
mariadb-10.5.11
mariadb-10.5.12
mariadb-10.5.2
mariadb-10.5.3
mariadb-10.5.4
mariadb-10.5.5
mariadb-10.5.6
mariadb-10.5.7
mariadb-10.5.8
mariadb-10.5.9
mariadb-5.*
mariadb-5.5.63
mariadb-5.5.64
mariadb-5.5.65
mariadb-5.5.66
mariadb-5.5.67
mariadb-5.5.68
mariadb-galera-10.*
mariadb-galera-10.0.37
mariadb-galera-5.*
mariadb-galera-5.5.62

Database specific

vanir_signatures
[
    {
        "target": {
            "file": "sql/sql_class.h"
        },
        "id": "CVE-2021-46667-03089408",
        "source": "https://github.com/mariadb/server/commit/d6cb0c83462e6af0fd38afcb46d714070f4af4d0",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "246197311705367672488779414942418338437",
                "276461508094209904860358154457724219596",
                "119856287420192600807656416768471292892",
                "307523178086602816378726753514303591471"
            ]
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "sql/sp_head.cc"
        },
        "id": "CVE-2021-46667-12addb8d",
        "source": "https://github.com/mariadb/server/commit/d6cb0c83462e6af0fd38afcb46d714070f4af4d0",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "131649957694533731721940309055820975752",
                "249452647439853322414702137565205958351",
                "201969777012246482841882403852745931746",
                "95578070551738783324854304889376330162",
                "249398730562238721197312579126910521732",
                "272906839712165971131454335608419438521",
                "107318663712936600961191413243544821067",
                "180839139384475678538465324643300020059",
                "282394023504767334221966027397455256851"
            ]
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "sql/handler.h"
        },
        "id": "CVE-2021-46667-53641f98",
        "source": "https://github.com/mariadb/server/commit/d6cb0c83462e6af0fd38afcb46d714070f4af4d0",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "119521046618748345254444704918727070434",
                "200452323826260590731762179699296029024",
                "251509020612362925913253356211500341353",
                "261751524541214367584170806104141027470",
                "201306130400997636080714619460096506715",
                "35155932094167429544231535939915658820"
            ]
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "sql/log.cc",
            "function": "binlog_rollback"
        },
        "id": "CVE-2021-46667-62ebee97",
        "source": "https://github.com/mariadb/server/commit/d6cb0c83462e6af0fd38afcb46d714070f4af4d0",
        "digest": {
            "length": 1646.0,
            "function_hash": "306699274100027957454330329145370130558"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "sql/sp_head.cc",
            "function": "sp_lex_keeper::reset_lex_and_exec_core"
        },
        "id": "CVE-2021-46667-7f0b712f",
        "source": "https://github.com/mariadb/server/commit/d6cb0c83462e6af0fd38afcb46d714070f4af4d0",
        "digest": {
            "length": 2658.0,
            "function_hash": "336328390458211521927718962871514707351"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "sql/log.cc",
            "function": "trans_cannot_safely_rollback"
        },
        "id": "CVE-2021-46667-aa3e08bd",
        "source": "https://github.com/mariadb/server/commit/d6cb0c83462e6af0fd38afcb46d714070f4af4d0",
        "digest": {
            "length": 526.0,
            "function_hash": "313645379892638120418940088368384842330"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "sql/log.cc",
            "function": "MYSQL_BIN_LOG::write"
        },
        "id": "CVE-2021-46667-cfbf81de",
        "source": "https://github.com/mariadb/server/commit/d6cb0c83462e6af0fd38afcb46d714070f4af4d0",
        "digest": {
            "length": 5738.0,
            "function_hash": "58969679078610265830587969385269203468"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "sql/log.cc"
        },
        "id": "CVE-2021-46667-d964f1cf",
        "source": "https://github.com/mariadb/server/commit/d6cb0c83462e6af0fd38afcb46d714070f4af4d0",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "37241440461655139304666183504430673984",
                "321123901233127987586838407173769763021",
                "72261390377549520472738172439120219059",
                "177685578562853608336609164621767055897",
                "89819371651002091070891492658372534238",
                "51099385615472244965869900895991310181",
                "46580225994766933062920841006192426125",
                "315917086551178982883049352244998712855",
                "151578589657138643687922568393137771305",
                "17554905964382256978464037543366371516",
                "44471072352567830517014260687216170718",
                "24734019721218526304965298857312980362",
                "170961031791040395953313676921959415915",
                "270863138330118960816828040809003942807",
                "193741668719766893391486278801760873722",
                "187930135527712657567073811467820013048",
                "463263057525947197303571514490382636",
                "339713228808563234771781256013265010488",
                "60867587337001395239385720816441536057",
                "201702182182638939619765504430616936017",
                "57432871140975116606615382999074109620",
                "84713255884193508387326659336658799628",
                "26176627625780710469062407865406490363",
                "43796184043138950845306782231229762899",
                "324404121552377421361400005592716783209",
                "327933765027016333514108949053193264778",
                "64468012293600814982757536651285167827",
                "7202594327949745606575738191994274437",
                "262509239196084693497735668412073064246",
                "337977078646117299838774945463804836390",
                "10862040297338291254194597838720262756",
                "83515971079454692103282106460082729171",
                "189738111660857520124962685258236418556",
                "32778699285218945562928993184558074443",
                "218701964979892061313721302653462012734",
                "187533463339481117482532077546372282049",
                "202341581865934325003292198703136040956",
                "155258852623302621764107560349238231581",
                "159919742848761288642405190297761552689",
                "147668741816814608585313009494181079624",
                "218818688557001123571703121311150830495",
                "148772925594895409927511713164729652512",
                "95985790907239484288997369415539433967",
                "255840666226744218838219627455521697435",
                "255600561411523879536850015147493893481",
                "27747137695801633233169226083338797085"
            ]
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-46667.json"