CVE-2023-52971 is a medium-severity denial-of-service vulnerability affecting MariaDB Server versions 10.10 through 10.11.* and 11.0 through 11.4.*, causing the server to crash in the JOIN::fix_all_splittings_in_plan function. With a CVSS score of 4.9, it requires high privileges for exploitation and results in high availability impact without affecting confidentiality or integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| MariaDB | MariaDB | >= 10.10, < 10.11.*, >= 11.0, < 11.4.*CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan.
Jul 8, 2025MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan.
Mar 11, 2025mariadb: MariaDB Server Crash
Mar 8, 2025