diff options
| -rw-r--r-- | meta-oe/recipes-dbs/mysql/mariadb.inc | 1 | ||||
| -rw-r--r-- | meta-oe/recipes-dbs/mysql/mariadb/CVE-2023-22084.patch | 91 |
2 files changed, 92 insertions, 0 deletions
diff --git a/meta-oe/recipes-dbs/mysql/mariadb.inc b/meta-oe/recipes-dbs/mysql/mariadb.inc index a84f8d134f..7c4b0a467f 100644 --- a/meta-oe/recipes-dbs/mysql/mariadb.inc +++ b/meta-oe/recipes-dbs/mysql/mariadb.inc | |||
| @@ -22,6 +22,7 @@ SRC_URI = "https://archive.mariadb.org/${BP}/source/${BP}.tar.gz \ | |||
| 22 | file://cross-compiling.patch \ | 22 | file://cross-compiling.patch \ |
| 23 | file://0001-sql-CMakeLists.txt-fix-gen_lex_hash-not-found.patch \ | 23 | file://0001-sql-CMakeLists.txt-fix-gen_lex_hash-not-found.patch \ |
| 24 | file://0001-MDEV-29644-a-potential-bug-of-null-pointer-dereferen.patch \ | 24 | file://0001-MDEV-29644-a-potential-bug-of-null-pointer-dereferen.patch \ |
| 25 | file://CVE-2023-22084.patch \ | ||
| 25 | " | 26 | " |
| 26 | SRC_URI:append:libc-musl = " file://ppc-remove-glibc-dep.patch" | 27 | SRC_URI:append:libc-musl = " file://ppc-remove-glibc-dep.patch" |
| 27 | 28 | ||
diff --git a/meta-oe/recipes-dbs/mysql/mariadb/CVE-2023-22084.patch b/meta-oe/recipes-dbs/mysql/mariadb/CVE-2023-22084.patch new file mode 100644 index 0000000000..3053614854 --- /dev/null +++ b/meta-oe/recipes-dbs/mysql/mariadb/CVE-2023-22084.patch | |||
| @@ -0,0 +1,91 @@ | |||
| 1 | From 15ae97b1c2c14f1263cdc853673c4129625323de Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Marko Mäkelä <marko.makela@mariadb.com> | ||
| 3 | Date: Thu, 8 Feb 2024 08:09:20 +0000 | ||
| 4 | Subject: [PATCH] MDEV-32578 row_merge_fts_doc_tokenize() handles parser plugin | ||
| 5 | inconsistently | ||
| 6 | |||
| 7 | When mysql/mysql-server@0c954c2 | ||
| 8 | added a plugin interface for FULLTEXT INDEX tokenization to MySQL 5.7, | ||
| 9 | fts_tokenize_ctx::processed_len got a second meaning, which is only | ||
| 10 | partly implemented in row_merge_fts_doc_tokenize(). | ||
| 11 | |||
| 12 | This inconsistency could cause a crash when using FULLTEXT...WITH PARSER. | ||
| 13 | A test case that would crash MySQL 8.0 when using an n-gram parser and | ||
| 14 | single-character words would fail to crash in MySQL 5.7, because the | ||
| 15 | buf_full condition in row_merge_fts_doc_tokenize() was not met. | ||
| 16 | |||
| 17 | This change is inspired by | ||
| 18 | mysql/mysql-server@38e9a07 | ||
| 19 | that appeared in MySQL 5.7.44. | ||
| 20 | |||
| 21 | CVE: CVE-2023-22084 | ||
| 22 | Upstream-Status: Backport [https://github.com/MariaDB/server/commit/15ae97b1c2c1] | ||
| 23 | |||
| 24 | Signed-off-by: Yogita Urade <yogita.urade@windriver.com> | ||
| 25 | --- | ||
| 26 | storage/innobase/include/row0ftsort.h | 6 +++++- | ||
| 27 | storage/innobase/row/row0ftsort.cc | 11 ++++++++--- | ||
| 28 | 2 files changed, 13 insertions(+), 4 deletions(-) | ||
| 29 | |||
| 30 | diff --git a/storage/innobase/include/row0ftsort.h b/storage/innobase/include/row0ftsort.h | ||
| 31 | index 65508caf..3ffa8243 100644 | ||
| 32 | --- a/storage/innobase/include/row0ftsort.h | ||
| 33 | +++ b/storage/innobase/include/row0ftsort.h | ||
| 34 | @@ -104,7 +104,10 @@ typedef UT_LIST_BASE_NODE_T(row_fts_token_t) fts_token_list_t; | ||
| 35 | |||
| 36 | /** Structure stores information from string tokenization operation */ | ||
| 37 | struct fts_tokenize_ctx { | ||
| 38 | - ulint processed_len; /*!< processed string length */ | ||
| 39 | + /** the processed string length in bytes | ||
| 40 | + (when using the built-in tokenizer), | ||
| 41 | + or the number of row_merge_fts_doc_tokenize_by_parser() calls */ | ||
| 42 | + ulint processed_len; | ||
| 43 | ulint init_pos; /*!< doc start position */ | ||
| 44 | ulint buf_used; /*!< the sort buffer (ID) when | ||
| 45 | tokenization stops, which | ||
| 46 | @@ -115,6 +118,7 @@ struct fts_tokenize_ctx { | ||
| 47 | ib_rbt_t* cached_stopword;/*!< in: stopword list */ | ||
| 48 | dfield_t sort_field[FTS_NUM_FIELDS_SORT]; | ||
| 49 | /*!< in: sort field */ | ||
| 50 | + /** parsed tokens (when using an external parser) */ | ||
| 51 | fts_token_list_t fts_token_list; | ||
| 52 | |||
| 53 | fts_tokenize_ctx() : | ||
| 54 | diff --git a/storage/innobase/row/row0ftsort.cc b/storage/innobase/row/row0ftsort.cc | ||
| 55 | index 86e96624..406ff60f 100644 | ||
| 56 | --- a/storage/innobase/row/row0ftsort.cc | ||
| 57 | +++ b/storage/innobase/row/row0ftsort.cc | ||
| 58 | @@ -491,7 +491,10 @@ row_merge_fts_doc_tokenize( | ||
| 59 | |||
| 60 | /* Tokenize the data and add each word string, its corresponding | ||
| 61 | doc id and position to sort buffer */ | ||
| 62 | - while (t_ctx->processed_len < doc->text.f_len) { | ||
| 63 | + while (parser | ||
| 64 | + ? (!t_ctx->processed_len | ||
| 65 | + || UT_LIST_GET_LEN(t_ctx->fts_token_list)) | ||
| 66 | + : t_ctx->processed_len < doc->text.f_len) { | ||
| 67 | ulint idx = 0; | ||
| 68 | ulint cur_len; | ||
| 69 | doc_id_t write_doc_id; | ||
| 70 | @@ -831,7 +834,8 @@ void fts_parallel_tokenization( | ||
| 71 | /* Not yet finish processing the "doc" on hand, | ||
| 72 | continue processing it */ | ||
| 73 | ut_ad(doc.text.f_str); | ||
| 74 | - ut_ad(t_ctx.processed_len < doc.text.f_len); | ||
| 75 | + ut_ad(buf[0]->index->parser | ||
| 76 | + || t_ctx.processed_len < doc.text.f_len); | ||
| 77 | } | ||
| 78 | |||
| 79 | processed = row_merge_fts_doc_tokenize( | ||
| 80 | @@ -841,7 +845,8 @@ void fts_parallel_tokenization( | ||
| 81 | |||
| 82 | /* Current sort buffer full, need to recycle */ | ||
| 83 | if (!processed) { | ||
| 84 | - ut_ad(t_ctx.processed_len < doc.text.f_len); | ||
| 85 | + ut_ad(buf[0]->index->parser | ||
| 86 | + || t_ctx.processed_len < doc.text.f_len); | ||
| 87 | ut_ad(t_ctx.rows_added[t_ctx.buf_used]); | ||
| 88 | break; | ||
| 89 | } | ||
| 90 | -- | ||
| 91 | 2.40.0 | ||
