CVE-2023-5157

NameCVE-2023-5157
DescriptionA vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
galera-3 (PTS)buster25.3.25-2fixed
bullseye25.3.37-0+deb11u1fixed
sid, bookworm25.3.37-1fixed
galera-4 (PTS)bullseye26.4.11-0+deb11u1vulnerable
bookworm26.4.13-1fixed
sid, trixie26.4.18-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
galera-3source(unstable)(not affected)
galera-4source(unstable)26.4.13-1

Notes

[bullseye] - galera-4 <no-dsa> (Minor issue; can be fixed via point release)
- galera-3 <not-affected> (vulnerable code not backported to galera-3)
https://jira.mariadb.org/browse/MDEV-25068
Introduced by: https://github.com/codership/galera/commit/c27596d06a221f6c14d36759c681149964008749 (26.4.8)
Fixed by: https://github.com/codership/galera/commit/930c016108d7086b472ad7a8b9d0f6989202b48a (26.4.12)

Search for package or bug name: Reporting problems