{"schema_version":"1.9.0","id":"BIT-mariadb-min-2022-31623","published":"2025-06-10T11:51:18.181Z","modified":"2026-09-08T08:48:12.724095096Z","aliases":["BIT-mariadb-2022-31623","BIT-mysql-client-2022-31623","CVE-2022-31623"],"details":"MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (i.e., going to the err label) while executing the method create_worker_threads, the held lock thd->ctrl_mutex is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug and not a vulnerability with adverse effects.","affected":[{"package":{"name":"mariadb-min","ecosystem":"Bitnami","purl":"pkg:bitnami/mariadb-min"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"10.2.42"},{"introduced":"10.3.0"},{"fixed":"10.3.33"},{"introduced":"10.4.0"},{"fixed":"10.4.23"},{"introduced":"10.5.0"},{"fixed":"10.5.14"},{"introduced":"10.6.0"},{"fixed":"10.6.6"},{"introduced":"10.7.0"},{"fixed":"10.7.2"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/mariadb-min/BIT-mariadb-min-2022-31623.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}],"references":[{"type":"ADVISORY","url":"https://github.com/MariaDB/server/commit/7c30bc38a588b22b01f11130cfe99e7f36accf94"},{"type":"ADVISORY","url":"https://github.com/MariaDB/server/pull/1938"},{"type":"WEB","url":"https://jira.mariadb.org/browse/MDEV-26561"},{"type":"WEB","url":"https://jira.mariadb.org/browse/MDEV-26574"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31623"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220707-0006/"}],"database_specific":{"cpes":["cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*"],"severity":"Medium"}}