Details
-
Bug
-
Status: Closed (View Workflow)
-
Critical
-
Resolution: Duplicate
-
11.4.0
-
None
-
ubuntu20.04,x86
-
Not for Release Notes
Description
This vulnerability in MariaDB lies in the Window_funcs_sort::setup function in sql/sql_window.cc at line 3092. It results from dereferencing a null pointer spec->partition_list without prior validation. When the SELECT query contains window functions with improperly initialized or missing partition specifications, the server crashes due to a segmentation fault, leading to a potential denial-of-service (DoS).
Attachments
Issue Links
- duplicates
-
MDEV-32609 Derived subquery selecting from dummy table causes segv
-
- Confirmed
-