CVE-2023-52969 describes a vulnerability in MariaDB Server versions 10.4 through 11.0 that can lead to a server crash with an empty backtrace log, potentially related to internal optimization processes. With a CVSS score of 4.9 (Medium), this vulnerability requires high privileges (PR:H) for exploitation and results in high availability impact (A:H) but no confidentiality or integrity impact. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| MariaDB | MariaDB | >= 10.7, < 10.11.*, >= 10.4, < 10.5.*, >= 10.6, < 10.6.*, >= 11.0, < 11.0.*CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This may be related to make_aggr_tables_info and optimize_stage2.
Mar 11, 2025mariadb: MariaDB Server Crash Due to Empty Backtrace Log
Mar 8, 2025