---
cve: "CVE-2022-38791"
severity: "LOW"
cvss: 3.1
epss: "25%"
vendor: "n/a"
kev: false
exploited: false
published: "2022-08-27 20:15:08"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T06:57:31+02:00"
---

# CVE-2022-38791

> 3.1 LOW

## Beschreibung

In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.

## Patch verfügbar (OSV)

- faddcf3c395da640b760c3f701f5bc1f3baae6c4 (Commit)
- 65e8506ca9d03967191b6ed207cf107d311f7f99 (Commit)

## Referenzen

- <https://jira.mariadb.org/browse/MDEV-28719>
- <https://security.netapp.com/advisory/ntap-20221104-0008/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZHISY4YVO4S5QJYYIXCIAXBM7INOL4VY/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WCOEGSVMIEXDZHBOSV6WVF7FAVRBR2JE/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTVAONAZXJFGHAJ4RP2OF3EAMQCOTDSQ/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2022-38791) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
