{"schema_version":"1.7.3","id":"SUSE-SU-2022:3159-1","published":"2022-09-07T12:33:51Z","modified":"2026-02-04T02:28:00.493223Z","related":["CVE-2022-32081","CVE-2022-32082","CVE-2022-32083","CVE-2022-32084","CVE-2022-32085","CVE-2022-32086","CVE-2022-32087","CVE-2022-32088","CVE-2022-32089","CVE-2022-32091"],"upstream":["CVE-2022-32081","CVE-2022-32082","CVE-2022-32083","CVE-2022-32084","CVE-2022-32085","CVE-2022-32086","CVE-2022-32087","CVE-2022-32088","CVE-2022-32089","CVE-2022-32091"],"summary":"Security update for mariadb","details":"This update for mariadb fixes the following issues:\n\n- Updated to 10.6.9:\n  - CVE-2022-32082: Fixed a reachable assertion that would crash the server (bsc#1201162).\n  - CVE-2022-32089: Fixed a segmentation fault that coudl be triggered via a crafted query (bsc#1201169).\n  - CVE-2022-32081: Fixed a buffer overflow on instant ADD/DROP of generated column (bsc#1201161).\n  - CVE-2022-32091: Fixed a memory corruption issue that could be triggered via a crafted query (bsc#1201170).\n  - CVE-2022-32084: Fixed a segmentation fault on INSERT SELECT queries (bsc#1201164).\n\n- Additionaly, the following issues were previously fixed:\n  - CVE-2022-32088: Fixed a server crash when using ORDER BY with window function and UNION(bsc#1201168).\n  - CVE-2022-32087: Fixed a segmentation fault that could be triggered via a crafted query (bsc#1201167).\n  - CVE-2022-32086: Fixed a server crash on INSERT SELECT queries (bsc#1201166).\n  - CVE-2022-32085: Fixed a segmentation fault that could be triggered via a crafted query (bsc#1201165).\n  - CVE-2022-32083: Fixed a segmentation fault that could be triggered via a crafted query (bsc#1201163).\n\nBugfixes:\n\n- Update mysql-systemd-helper to be aware of custom group (bsc#1200105).\n","affected":[{"package":{"name":"mariadb","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP4","purl":"pkg:rpm/suse/mariadb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.6.9-150400.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"libmariadbd-devel":"10.6.9-150400.3.12.1","libmariadbd19":"10.6.9-150400.3.12.1","mariadb":"10.6.9-150400.3.12.1","mariadb-client":"10.6.9-150400.3.12.1","mariadb-errormessages":"10.6.9-150400.3.12.1","mariadb-tools":"10.6.9-150400.3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3159-1.json"}},{"package":{"name":"mariadb","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/mariadb&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.6.9-150400.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"libmariadbd-devel":"10.6.9-150400.3.12.1","libmariadbd19":"10.6.9-150400.3.12.1","mariadb":"10.6.9-150400.3.12.1","mariadb-bench":"10.6.9-150400.3.12.1","mariadb-client":"10.6.9-150400.3.12.1","mariadb-errormessages":"10.6.9-150400.3.12.1","mariadb-galera":"10.6.9-150400.3.12.1","mariadb-rpm-macros":"10.6.9-150400.3.12.1","mariadb-test":"10.6.9-150400.3.12.1","mariadb-tools":"10.6.9-150400.3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3159-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223159-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1200105"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201161"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201162"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201163"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201164"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201165"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201166"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201167"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201168"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201169"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201170"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32081"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32082"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32083"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32084"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32085"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32086"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32087"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32088"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32089"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32091"}]}