Logo
vulnerabilityCVE-2023-22084
Name
CVE-2023-22084
Source
NVD ( link)Debian ( link)
Description
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.43 and prior, 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CWEs
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
mariadb
Patched

Vulnerability Rating#


4.9
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
10.11.17
Not Affected
buildroot
master
10.11.17
Not Affected
openwrt
master
3.4.8-r3
Not Affected
openwrt
master
11.8.3-r1
Not Affected
openwrt
openwrt-25.12
3.4.8-r3
Not Affected
openwrt
openwrt-25.12
11.8.3-r1
Not Affected
yocto
master
11.4.12
Not Affected
yocto
scarthgap
10.11.16
Not Affected

Resolved with patches#


mariadb (yocto:kirkstone)

#
Title
Author
Resolve
1
MDEV-32578 row_merge_fts_doc_tokenize() handles parser plugin
Marko Mäkelä <marko.makela@mariadb.com>
CVE-2023-22084