VDB
BDU%3A2025-15222
BDU%3A2025-15222
PUBLISHED
CVSS 4.900000095367432 MEDIUM
Уязвимость функции JOIN::fix_all_splittings_in_plan системы управления базами данных MariaDB, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 3.1
4.900000095367432
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| MariaDB | MariaDB | 10.10, 11.0 |
| Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра», MariaDB Foundation | OpenSUSE Leap, Red Hat Enterprise Linux, SUSE Linux Enterprise Module for Server Applications, SUSE Enterprise Storage, SUSE Linux Enterprise High Performance Computing, Suse Linux Enterprise Server, SUSE Manager Proxy, SUSE Manager Retail Branch Server, SUSE Manager Server, Debian GNU/Linux, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Real Time, SUSE Linux Enterprise Module for Package Hub, Astra Linux Special Edition (запись в едином реестре российских программ №369), MariaDB |
Timeline
- Mar 8, 2025 CVE Published
- Mar 8, 2025 PoC Published
- Mar 9, 2025 PoC Published
- Mar 9, 2025 PoC Published
- Mar 9, 2025 PoC Published
- Mar 10, 2025 PoC Published
- Feb 16, 2026 CVE Updated
References
- https://security-tracker.debian.org/tracker/CVE-2023-52971 url
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-1113SE18 url
- https://www.suse.com/security/cve/CVE-2023-52971.html advisory
- https://jira.mariadb.org/browse/MDEV-32084 url
- https://access.redhat.com/security/cve/cve-2023-52971 url
- https://wiki.astralinux.ru/astra-linux-se38-bulletin-2026-0126SE38 url