[USN-5022-2] MariaDB vulnerabilities

Severity Medium
Affected Packages 49
CVEs 2

Several security issues were fixed in MariaDB.

USN-5022-1 fixed multiple vulnerabilities in MySQL. This update provides the
corresponding fixes for CVE-2021-2372 and CVE-2021-2389 in MariaDB 10.3 and
10.5.

In addition to security fixes, the updated package contain bug fixes, new
features, and possibly incompatible changes.

Please see the following for more information:
https://mariadb.com/kb/en/mariadb-10331-changelog/
https://mariadb.com/kb/en/mariadb-10512-changelog/

Original advisory details:

Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.

MySQL has been updated to 8.0.26 in Ubuntu 20.04 LTS and Ubuntu 21.04.
Ubuntu 18.04 LTS has been updated to MySQL 5.7.35.

In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.

Please see the following for more information:

https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-35.html
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-26.html
https://www.oracle.com/security-alerts/cpujul2021.html

Package Affected Version
pkg:deb/ubuntu/mariadb-test?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-test?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-test-data?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-test-data?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-server?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-server?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-server-core-10.5?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-server-core-10.3?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-server-10.5?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-server-10.3?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-plugin-tokudb?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-plugin-spider?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-plugin-spider?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-plugin-s3?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-plugin-rocksdb?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-plugin-rocksdb?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-plugin-oqgraph?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-plugin-oqgraph?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-plugin-mroonga?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-plugin-mroonga?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-plugin-gssapi-server?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-plugin-gssapi-server?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-plugin-gssapi-client?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-plugin-gssapi-client?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-plugin-cracklib-password-check?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-plugin-cracklib-password-check?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-plugin-connect?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-plugin-connect?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-common?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-common?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-client?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-client?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-client-core-10.5?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-client-core-10.3?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-client-10.5?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-client-10.3?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/mariadb-backup?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/mariadb-backup?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/libmariadbd19?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/libmariadbd19?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/libmariadbd-dev?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/libmariadbd-dev?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/libmariadbclient-dev?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/libmariadb3?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/libmariadb3?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/libmariadb-dev?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/libmariadb-dev?distro=focal < 10.3.31-0ubuntu0.20.04.1
pkg:deb/ubuntu/libmariadb-dev-compat?distro=hirsute < 10.5.12-0ubuntu0.21.04.1
pkg:deb/ubuntu/libmariadb-dev-compat?distro=focal < 10.3.31-0ubuntu0.20.04.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/mariadb-test?distro=hirsute ubuntu mariadb-test < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-test?distro=focal ubuntu mariadb-test < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-test-data?distro=hirsute ubuntu mariadb-test-data < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-test-data?distro=focal ubuntu mariadb-test-data < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-server?distro=hirsute ubuntu mariadb-server < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-server?distro=focal ubuntu mariadb-server < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-server-core-10.5?distro=hirsute ubuntu mariadb-server-core-10.5 < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-server-core-10.3?distro=focal ubuntu mariadb-server-core-10.3 < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-server-10.5?distro=hirsute ubuntu mariadb-server-10.5 < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-server-10.3?distro=focal ubuntu mariadb-server-10.3 < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-plugin-tokudb?distro=focal ubuntu mariadb-plugin-tokudb < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-plugin-spider?distro=hirsute ubuntu mariadb-plugin-spider < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-plugin-spider?distro=focal ubuntu mariadb-plugin-spider < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-plugin-s3?distro=hirsute ubuntu mariadb-plugin-s3 < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-plugin-rocksdb?distro=hirsute ubuntu mariadb-plugin-rocksdb < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-plugin-rocksdb?distro=focal ubuntu mariadb-plugin-rocksdb < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-plugin-oqgraph?distro=hirsute ubuntu mariadb-plugin-oqgraph < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-plugin-oqgraph?distro=focal ubuntu mariadb-plugin-oqgraph < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-plugin-mroonga?distro=hirsute ubuntu mariadb-plugin-mroonga < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-plugin-mroonga?distro=focal ubuntu mariadb-plugin-mroonga < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-plugin-gssapi-server?distro=hirsute ubuntu mariadb-plugin-gssapi-server < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-plugin-gssapi-server?distro=focal ubuntu mariadb-plugin-gssapi-server < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-plugin-gssapi-client?distro=hirsute ubuntu mariadb-plugin-gssapi-client < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-plugin-gssapi-client?distro=focal ubuntu mariadb-plugin-gssapi-client < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-plugin-cracklib-password-check?distro=hirsute ubuntu mariadb-plugin-cracklib-password-check < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-plugin-cracklib-password-check?distro=focal ubuntu mariadb-plugin-cracklib-password-check < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-plugin-connect?distro=hirsute ubuntu mariadb-plugin-connect < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-plugin-connect?distro=focal ubuntu mariadb-plugin-connect < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-common?distro=hirsute ubuntu mariadb-common < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-common?distro=focal ubuntu mariadb-common < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-client?distro=hirsute ubuntu mariadb-client < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-client?distro=focal ubuntu mariadb-client < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-client-core-10.5?distro=hirsute ubuntu mariadb-client-core-10.5 < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-client-core-10.3?distro=focal ubuntu mariadb-client-core-10.3 < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-client-10.5?distro=hirsute ubuntu mariadb-client-10.5 < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-client-10.3?distro=focal ubuntu mariadb-client-10.3 < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/mariadb-backup?distro=hirsute ubuntu mariadb-backup < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/mariadb-backup?distro=focal ubuntu mariadb-backup < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/libmariadbd19?distro=hirsute ubuntu libmariadbd19 < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/libmariadbd19?distro=focal ubuntu libmariadbd19 < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/libmariadbd-dev?distro=hirsute ubuntu libmariadbd-dev < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/libmariadbd-dev?distro=focal ubuntu libmariadbd-dev < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/libmariadbclient-dev?distro=focal ubuntu libmariadbclient-dev < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/libmariadb3?distro=hirsute ubuntu libmariadb3 < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/libmariadb3?distro=focal ubuntu libmariadb3 < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/libmariadb-dev?distro=hirsute ubuntu libmariadb-dev < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/libmariadb-dev?distro=focal ubuntu libmariadb-dev < 10.3.31-0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/libmariadb-dev-compat?distro=hirsute ubuntu libmariadb-dev-compat < 10.5.12-0ubuntu0.21.04.1 hirsute
Affected pkg:deb/ubuntu/libmariadb-dev-compat?distro=focal ubuntu libmariadb-dev-compat < 10.3.31-0ubuntu0.20.04.1 focal
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...