Vulnerability Description
MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://jira.mariadb.org/browse/MDEV-32086
- https://lists.debian.org/debian-lts-announce/2025/05/msg00006.html
FAQ
What is CVE-2023-52970?
CVE-2023-52970 is a vulnerability with a CVSS score of 4.9 (MEDIUM). MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where.
How severe is CVE-2023-52970?
CVE-2023-52970 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-52970?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.