Security update for mariadb
This update for mariadb fixes the following issues: - Updated to 10.6.9: - CVE-2022-32082: Fixed a reachable assertion that would crash the server (bsc#1201162). - CVE-2022-32089: Fixed a segmentation fault that coudl be triggered via a crafted query (bsc#1201169). - CVE-2022-32081: Fixed a buffer overflow on instant ADD/DROP of generated column (bsc#1201161). - CVE-2022-32091: Fixed a memory corruption issue that could be triggered via a crafted query (bsc#1201170). - CVE-2022-32084: Fixed a segmentation fault on INSERT SELECT queries (bsc#1201164). - Additionaly, the following issues were previously fixed: - CVE-2022-32088: Fixed a server crash when using ORDER BY with window function and UNION(bsc#1201168). - CVE-2022-32087: Fixed a segmentation fault that could be triggered via a crafted query (bsc#1201167). - CVE-2022-32086: Fixed a server crash on INSERT SELECT queries (bsc#1201166). - CVE-2022-32085: Fixed a segmentation fault that could be triggered via a crafted query (bsc#1201165). - CVE-2022-32083: Fixed a segmentation fault that could be triggered via a crafted query (bsc#1201163). Bugfixes: - Update mysql-systemd-helper to be aware of custom group (bsc#1200105).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for mariadb fixes the following issues: - Updated to 10.6.9: - CVE-2022-32082: Fixed a reachable assertion that would crash the server (bsc#1201162). - CVE-2022-32089: Fixed a segmentation fault that coudl be triggered via a crafted query (bsc#1201169). - CVE-2022-32081: Fixed a buffer overflow on instant ADD/DROP of generated column (bsc#1201161). - CVE-2022-32091: Fixed a memory corruption issue that could be triggered via a crafted query (bsc#1201170). - CVE-2022-32084: Fixed a segmentation fault on INSERT SELECT queries (bsc#1201164). - Additionaly, the following issues were previously fixed: - CVE-2022-32088: Fixed a server crash when using ORDER BY with window function and UNION(bsc#1201168). - CVE-2022-32087: Fixed a segmentation fault that could be triggered via a crafted query (bsc#1201167). - CVE-2022-32086: Fixed a server crash on INSERT SELECT queries (bsc#1201166). - CVE-2022-32085: Fixed a segmentation fault that could be triggered via a crafted query (bsc#1201165). - CVE-2022-32083: Fixed a segmentation fault that could be triggered via a crafted query (bsc#1201163). Bugfixes: - Update mysql-systemd-helper to be aware of custom group (bsc#1200105).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1200105
- https://bugzilla.suse.com/1201161
- https://bugzilla.suse.com/1201162
- https://bugzilla.suse.com/1201163
- https://bugzilla.suse.com/1201164
- https://bugzilla.suse.com/1201165
- https://bugzilla.suse.com/1201166
- https://bugzilla.suse.com/1201167
- https://bugzilla.suse.com/1201168
- https://bugzilla.suse.com/1201169
- https://bugzilla.suse.com/1201170
- https://www.suse.com/security/cve/CVE-2022-32081
- https://www.suse.com/security/cve/CVE-2022-32082
- https://www.suse.com/security/cve/CVE-2022-32083
- https://www.suse.com/security/cve/CVE-2022-32084
- https://www.suse.com/security/cve/CVE-2022-32085
- https://www.suse.com/security/cve/CVE-2022-32086
- https://www.suse.com/security/cve/CVE-2022-32087
- https://www.suse.com/security/cve/CVE-2022-32088
- https://www.suse.com/security/cve/CVE-2022-32089
- https://www.suse.com/security/cve/CVE-2022-32091
- https://www.suse.com/support/update/announcement/2022/suse-su-20223159-1/