CVE-2021-46659
published 2022-01-29CVE-2021-46659: MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.55%
43.0th percentile
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mariadb-10.5 | < mariadb-10.5 1:10.5.15-0+deb11u1 (bullseye) | mariadb-10.5 1:10.5.15-0+deb11u1 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mariadb | mariadb | >= 10.3.0 < 10.3.33 | 10.3.33 |
| mariadb | mariadb | >= 10.4.0 < 10.4.23 | 10.4.23 |
| mariadb | mariadb | >= 10.5.0 < 10.5.14 | 10.5.14 |
| mariadb | mariadb | >= 10.6.0 < 10.6.6 | 10.6.6 |
| mariadb | mariadb | >= 10.7.0 < 10.7.2 | 10.7.2 |
| mariadb | mariadb | >= 5.5.0 < 10.2.42 | 10.2.42 |
| msrc | cbl2_mariadb_10.6.7-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_mariadb_10.3.34-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hpgh-p2hm-xrpr: MariaDB before 10
ghsa_unreviewed·2022-01-31
CVE-2021-46659 [MEDIUM] GHSA-hpgh-p2hm-xrpr: MariaDB before 10
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
OSV
CVE-2021-46659: MariaDB before 10
osv·2022-01-29·CVSS 5.5
CVE-2021-46659 [MEDIUM] CVE-2021-46659: MariaDB before 10
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
Ubuntu
MariaDB vulnerabilities
vendor_ubuntu·2022-02-28
CVE-2021-46663 MariaDB vulnerabilities
Title: MariaDB vulnerabilities
Summary: Several security issues were fixed in MariaDB.
Several security issues were discovered in MariaDB and this update includes
new upstream MariaDB versions to fix these issues.
MariaDB has been updated to 10.3.34 in Ubuntu 20.04 LTS and to 10.5.15 in
Ubuntu 21.10.
In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Microsoft
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
vendor_msrc·2022-01-11·CVSS 5.5
CVE-2021-46659 [MEDIUM] MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action
Red Hat
mariadb: Crash executing query with VIEW, aggregate and subquery
vendor_redhat·2021-05-10·CVSS 5.5
CVE-2021-46659 [MEDIUM] CWE-20 mariadb: Crash executing query with VIEW, aggregate and subquery
mariadb: Crash executing query with VIEW, aggregate and subquery
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
Package: mariadb (Red Hat Enterprise Linux 7) - Out of support scope
Package: mariadb (Red Hat OpenStack Platform 13 (Queens)) - Out of support scope
Debian
CVE-2021-46659: mariadb-10.5 - MariaDB before 10.7.2 allows an application crash because it does not recognize ...
vendor_debian·2021·CVSS 5.5
CVE-2021-46659 [MEDIUM] CVE-2021-46659: mariadb-10.5 - MariaDB before 10.7.2 allows an application crash because it does not recognize ...
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
Scope: local
bullseye: resolved (fixed in 1:10.5.15-0+deb11u1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://jira.mariadb.org/browse/MDEV-25631https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKJRBYJAQCOPHSED43A3HUPNKQLDTFGD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZFZVMJL5UDTOZMARLXQIMG3BTG6UNYW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJ4KDAGF3H4D4BDTHRAM6ZEAJJWWMRUO/https://mariadb.com/kb/en/security/https://security.netapp.com/advisory/ntap-20220311-0003/https://jira.mariadb.org/browse/MDEV-25631https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKJRBYJAQCOPHSED43A3HUPNKQLDTFGD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZFZVMJL5UDTOZMARLXQIMG3BTG6UNYW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJ4KDAGF3H4D4BDTHRAM6ZEAJJWWMRUO/https://mariadb.com/kb/en/security/https://security.netapp.com/advisory/ntap-20220311-0003/
2022-01-29
Published