Severity
7.5HIGHNVD
EPSS
0.1%
top 66.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 1
Latest updateJan 27

Description

MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDmariadb/mariadb10.4.010.4.26+5

Also affects: Fedora 35, 36, 37

🔴Vulnerability Details

3
GHSA
GHSA-vcx9-8fp4-h37w: MariaDB v102022-07-02
CVEList
CVE-2022-32081: MariaDB v102022-07-01
OSV
CVE-2022-32081: MariaDB v102022-07-01

📋Vendor Advisories

5
CISA ICS
Festo Didactic SE MES PC2026-01-27
Ubuntu
MariaDB vulnerabilities2022-11-23
Microsoft
MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc.2022-07-12
Debian
CVE-2022-32081: mariadb-10.5 - MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_...2022
Red Hat
mariadb: use-after-poison in prepare_inplace_add_virtual in handler0alter.cc2021-08-19