Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-36580

a NULL pointer dereference in the function Item_direct_view_ref::derived_field_transformer_for_where, located at sql/item.cc:7831

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • Critical
    • Resolution: Cannot Reproduce
    • 11.4.0
    • N/A
    • Optimizer
    • None
    • ubuntu20.04,x86
    • Not for Release Notes

    Description

      This MariaDB vulnerability is a NULL pointer dereference in the function Item_direct_view_ref::derived_field_transformer_for_where, located at sql/item.cc:7831. During a condition pushdown transformation for derived tables, the function calls find_producing_item(this, sel) where sel is not properly initialized, resulting in a segmentation fault. This can be triggered by crafted SQL queries involving views and complex WHERE clause transformations, leading to a crash and denial-of-service (DoS).

      Attachments

        Activity

          People

            Unassigned Unassigned
            yx yx
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Git Integration

                Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.