CVE-2023-52970: MariaDB

Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.

MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where.

Affected products

  • MariaDB MariaDB: from 10.4, before 10.6 (fixed in 10.6); from 10.6, before 10.7 (fixed in 10.7); from 10.7, before 10.12 (fixed in 10.12); from 11.0, before 11.1 (fixed in 11.1); from 11.1, before 11.5 (fixed in 11.5)

Published 2025-03-08. Last modified 2026-06-17.