MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.
| Software | From | Fixed in |
|---|---|---|
| mariadb / mariadb | 10.3.0 | 10.3.35 |
| mariadb / mariadb | 10.7.0 | 10.7.4 |
| mariadb / mariadb | 10.4.0 | 10.4.25 |
| mariadb / mariadb | 10.5.0 | 10.5.16 |
| mariadb / mariadb | 10.6.0 | 10.6.8 |
| mariadb / mariadb | 10.2.0 | 10.2.44 |
| mariadb / mariadb | 10.8.0 | 10.8.3 |
| debian / debian_linux | 10.0 | 10.0.x |