<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:04:40 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1556 — Moderate: mariadb:10.3 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1556</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: Judy, AlmaLinux:8: galera, AlmaLinux:8: mariadb, AlmaLinux:8: mariadb-backup, AlmaLinux:8: mariadb-common, AlmaLinux:8: mariadb-devel, AlmaLinux:8: mariadb-embedded, AlmaLinux:8: mariadb-embedded-devel, AlmaLinux:8: mariadb-errmsg, AlmaLinux:8: mariadb-gssapi-server and 5 more&lt;/p&gt;
&lt;p&gt;MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: mariadb (10.3.32), galera (25.3.34). (BZ#2050543)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* mysql: Server: DML unspecified vulnerability (CPU Apr 2021) (CVE-2021-2154)&lt;/p&gt;
&lt;p&gt;* mysql: Server: DML unspecified vulnerability (CPU Apr 2021) (CVE-2021-2166)&lt;/p&gt;
&lt;p&gt;* mysql: InnoDB unspecified vulnerability (CPU Jul 2021) (CVE-2021-2372)&lt;/p&gt;
&lt;p&gt;* mysql: InnoDB unspecified vulnerability (CPU Jul 2021) (CVE-2021-2389)&lt;/p&gt;
&lt;p&gt;* mysql: InnoDB unspecified vulnerability (CPU Oct 2021) (CVE-2021-35604)&lt;/p&gt;
&lt;p&gt;* mariadb: Integer overflow in sql_lex.cc integer leading to crash (CVE-2021-46667)&lt;/p&gt;
&lt;p&gt;* mariadb: Crash in get_sort_by_table() in subquery with ORDER BY having outer ref (CVE-2021-46657)&lt;/p&gt;
&lt;p&gt;* mariadb: save_window_function_values triggers an abort during IN subquery (CVE-2021-46658)&lt;/p&gt;
&lt;p&gt;* mariadb: Crash in set_var.cc via certain UPDATE queries with nested subqueries (CVE-2021-46662)&lt;/p&gt;
&lt;p&gt;* mariadb: Crash caused by mishandling of a pushdown from a HAVING clause to a WHERE clause (CVE-2021-46666)&lt;/p&gt;
&lt;p&gt;* mariadb: No password masking in audit log when using ALTER USER &amp;lt;user&amp;gt; IDENTIFIED BY &amp;lt;password&amp;gt; command (BZ#1981332)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* mariadb:10.3/mariadb: /etc/security/user_map.conf getting over…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: Judy, AlmaLinux:8: galera, AlmaLinux:8: mariadb, AlmaLinux:8: mariadb-backup, AlmaLinux:8: mariadb-common, AlmaLinux:8: mariadb-devel, AlmaLinux:8: mariadb-embedded, AlmaLinux:8: mariadb-embedded-devel, AlmaLinux:8: mariadb-errmsg, AlmaLinux:8: mariadb-gssapi-server and 5 more&lt;/p&gt;
&lt;p&gt;MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: mariadb (10.3.32), galera (25.3.34). (BZ#2050543)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* mysql: Server: DML unspecified vulnerability (CPU Apr 2021) (CVE-2021-2154)&lt;/p&gt;
&lt;p&gt;* mysql: Server: DML unspecified vulnerability (CPU Apr 2021) (CVE-2021-2166)&lt;/p&gt;
&lt;p&gt;* mysql: InnoDB unspecified vulnerability (CPU Jul 2021) (CVE-2021-2372)&lt;/p&gt;
&lt;p&gt;* mysql: InnoDB unspecified vulnerability (CPU Jul 2021) (CVE-2021-2389)&lt;/p&gt;
&lt;p&gt;* mysql: InnoDB unspecified vulnerability (CPU Oct 2021) (CVE-2021-35604)&lt;/p&gt;
&lt;p&gt;* mariadb: Integer overflow in sql_lex.cc integer leading to crash (CVE-2021-46667)&lt;/p&gt;
&lt;p&gt;* mariadb: Crash in get_sort_by_table() in subquery with ORDER BY having outer ref (CVE-2021-46657)&lt;/p&gt;
&lt;p&gt;* mariadb: save_window_function_values triggers an abort during IN subquery (CVE-2021-46658)&lt;/p&gt;
&lt;p&gt;* mariadb: Crash in set_var.cc via certain UPDATE queries with nested subqueries (CVE-2021-46662)&lt;/p&gt;
&lt;p&gt;* mariadb: Crash caused by mishandling of a pushdown from a HAVING clause to a WHERE clause (CVE-2021-46666)&lt;/p&gt;
&lt;p&gt;* mariadb: No password masking in audit log when using ALTER USER &amp;lt;user&amp;gt; IDENTIFIED BY &amp;lt;password&amp;gt; command (BZ#1981332)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* mariadb:10.3/mariadb: /etc/security/user_map.conf getting over…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1556</guid>
    </item>
    <item>
      <title>BIT-mariadb-2021-46658</title>
      <link>https://cve.radiocsirt.org/vuln/bit-mariadb-2021-46658</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mariadb&lt;/p&gt;
&lt;p&gt;save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mariadb&lt;/p&gt;
&lt;p&gt;save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-mariadb-2021-46658</guid>
    </item>
    <item>
      <title>EUVD-2026-34090</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-34090</link>
      <description>EUVD-2026-34090</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-34090</guid>
    </item>
    <item>
      <title>fkie_cve-2021-46658</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-46658</link>
      <description>&lt;p&gt;save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-46658</guid>
    </item>
    <item>
      <title>GHSA-2vgr-c24v-3xf3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2vgr-c24v-3xf3</link>
      <description>&lt;p&gt;save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2vgr-c24v-3xf3</guid>
    </item>
    <item>
      <title>gsd-2021-46658</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-46658</link>
      <description>gsd-2021-46658</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-46658</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-46658 — save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-46658</link>
      <description>msrc_CVE-2021-46658</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-46658</guid>
    </item>
    <item>
      <title>OESA-2022-1616 — mariadb security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1616</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: mariadb&lt;/p&gt;
&lt;p&gt;MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities.&#13;
&#13;
MariaDB turns data into structured information in a wide array of applications, ranging from banking to websites. It is an enhanced, drop-in replacement for MySQL. MariaDB is used because it is fast, scalable and robust, with a rich ecosystem of storage engines, plugins and many other tools make it very versatile for a wide variety of use cases.&#13;
&#13;
Security Fix(es):&#13;
&#13;
save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=True for a subquery.(CVE-2021-46658)&lt;/p&gt;
&lt;p&gt;MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.(CVE-2021-46668)&lt;/p&gt;
&lt;p&gt;MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacke…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: mariadb&lt;/p&gt;
&lt;p&gt;MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities.&#13;
&#13;
MariaDB turns data into structured information in a wide array of applications, ranging from banking to websites. It is an enhanced, drop-in replacement for MySQL. MariaDB is used because it is fast, scalable and robust, with a rich ecosystem of storage engines, plugins and many other tools make it very versatile for a wide variety of use cases.&#13;
&#13;
Security Fix(es):&#13;
&#13;
save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=True for a subquery.(CVE-2021-46658)&lt;/p&gt;
&lt;p&gt;MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.(CVE-2021-46668)&lt;/p&gt;
&lt;p&gt;MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacke…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1616</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0731-1 — Security update for mariadb</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0731-1</link>
      <description>&lt;p&gt;Security update for mariadb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for mariadb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0731-1</guid>
    </item>
    <item>
      <title>RHSA-2022:1007 — Red Hat Security Advisory: rh-mariadb105-mariadb security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:1007</link>
      <description>&lt;p&gt;mysql: Server: DML unspecified vulnerability (CPU Apr 2021) mysql: Server: DML unspecified vulnerability (CPU Apr 2021) mysql: InnoDB unspecified vulnerability (CPU Jul 2021) mysql: InnoDB unspecified vulnerability (CPU Jul 2021) mysql: InnoDB unspecified vulnerability (CPU Oct 2021) mariadb: Crash in get_sort_by_table() in subquery with ORDER BY having outer ref mariadb: save_window_function_values triggers an abort during IN subquery mariadb: Crash in set_var.cc via certain UPDATE queries with nested subqueries mariadb: Crash caused by mishandling of a pushdown from a HAVING clause to a WHERE clause mariadb: Integer overflow in sql_lex.cc integer leading to crash mysql: InnoDB unspecified vulnerability (CPU Apr 2022) mariadb: crash in Used_tables_and_const_cache::used_tables_and_const_cache_join mariadb: improper locking due to unreleased lock in the ds_xbstream.cc mariadb: DoS due to improper locking due to unreleased lock in plugin/server_audit/server_audit.c&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mysql: Server: DML unspecified vulnerability (CPU Apr 2021) mysql: Server: DML unspecified vulnerability (CPU Apr 2021) mysql: InnoDB unspecified vulnerability (CPU Jul 2021) mysql: InnoDB unspecified vulnerability (CPU Jul 2021) mysql: InnoDB unspecified vulnerability (CPU Oct 2021) mariadb: Crash in get_sort_by_table() in subquery with ORDER BY having outer ref mariadb: save_window_function_values triggers an abort during IN subquery mariadb: Crash in set_var.cc via certain UPDATE queries with nested subqueries mariadb: Crash caused by mishandling of a pushdown from a HAVING clause to a WHERE clause mariadb: Integer overflow in sql_lex.cc integer leading to crash mysql: InnoDB unspecified vulnerability (CPU Apr 2022) mariadb: crash in Used_tables_and_const_cache::used_tables_and_const_cache_join mariadb: improper locking due to unreleased lock in the ds_xbstream.cc mariadb: DoS due to improper locking due to unreleased lock in plugin/server_audit/server_audit.c&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:1007</guid>
    </item>
    <item>
      <title>SUSE-RU-2023:3956-1 — Recommended update for mariadb104</title>
      <link>https://cve.radiocsirt.org/vuln/suse-ru-2023:3956-1</link>
      <description>&lt;p&gt;Recommended update for mariadb104&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for mariadb104&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-ru-2023:3956-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-46658</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-46658</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: mariadb-10.3&lt;/p&gt;
&lt;p&gt;save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: mariadb-10.3&lt;/p&gt;
&lt;p&gt;save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-46658</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0843 — MariaDB: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0843</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in MariaDB ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in MariaDB ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0843</guid>
    </item>
  </channel>
</rss>
