Security readout for executives and security teams
Plain-English summary
CVE-2021-46663 is a MariaDB crash issue. MariaDB through 10.5.13 can crash when handling certain SELECT statements. The disclosed impact is availability, not data theft or privilege escalation. Business urgency depends on whether untrusted users or applications can submit SQL to affected MariaDB instances.
Executive priority
Treat as an availability risk requiring inventory and normal patch management attention. Escalate priority for customer-facing, multi-tenant, or business-critical databases where users can influence SQL generation. The supplied evidence does not support emergency active-exploitation handling.
Technical view
The record describes an application crash in ha_maria::extra triggered by certain SELECT statements in MariaDB through 10.5.13. The bundle provides no CVSS, CWE, or detailed affected CPEs. Public references include MariaDB Jira, MariaDB security page, NetApp advisory, and Fedora package advisories.
Likely exposure
Exposure is most likely where MariaDB through 10.5.13 is deployed directly or embedded in vendor products. Internet exposure is not established by the sources. Risk rises if application users, tenants, or compromised accounts can cause crafted SELECT queries to reach MariaDB.
Exploitation context
The provided sources do not show CISA KEV listing or active exploitation. The described trigger is certain SELECT statements causing a crash. No exploit maturity, authentication requirements, or remote reachability details are supplied in the bundle.
Researcher notes
The source bundle is sparse: no CVSS vector, CWE, CPE list, proof-of-concept status, or fixed version is included. Analysis should stay anchored to the documented MariaDB through 10.5.13 crash in ha_maria::extra and vendor advisories for platform-specific remediation.
Mitigation direction
- Inventory MariaDB deployments and identify versions through 10.5.13.
- Check MariaDB, Fedora, NetApp, and appliance vendor guidance for patched packages.
- Prioritize systems where untrusted users can submit SQL or query-building input.
- Limit unnecessary database access and ad hoc query privileges where operationally feasible.
- Monitor database crash loops and availability alerts on affected systems.
Validation and detection
- Confirm MariaDB server versions from asset inventory or package management records.
- Map applications and appliances that embed or depend on MariaDB.
- Review vendor advisories for the exact fixed package applicable to each platform.
- Check logs for unexplained MariaDB crashes during SELECT query handling.
- Verify post-remediation versions against the relevant vendor advisory.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-46663 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://jira.mariadb.org/browse/MDEV-26351CVE reference · x_refsource_MISC
- https://security.netapp.com/advisory/ntap-20220221-0002/CVE reference · x_refsource_CONFIRM
- https://mariadb.com/kb/en/security/CVE reference · x_refsource_CONFIRM
- FEDORA-2022-263f7cc483CVE reference · vendor-advisory, x_refsource_FEDORA
- FEDORA-2022-03350936eeCVE reference · vendor-advisory, x_refsource_FEDORA
- FEDORA-2022-5cfe372ab7CVE reference · vendor-advisory, x_refsource_FEDORA
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
