PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it will check the expression between 'Agg' and 'GroupBy', but does not check the return type. NOTE: PingCAP disputes this, arguing that reproduction did not cause the security impact of service interruption to other users. They maintain it is a complex query bug in the product but not a DoS.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 04 Sep 2025 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:pingcap:tidb:8.1.0:-:*:*:*:*:*:*

Wed, 25 Sep 2024 21:15:00 +0000

Type Values Removed Values Added
Description PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it will check the expression between 'Agg' and 'GroupBy', but does not check the return type. PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it will check the expression between 'Agg' and 'GroupBy', but does not check the return type. NOTE: PingCAP disputes this, arguing that reproduction did not cause the security impact of service interruption to other users. They maintain it is a complex query bug in the product but not a DoS.

Tue, 03 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Pingcap
Pingcap tidb
Weaknesses CWE-400
CPEs cpe:2.3:a:pingcap:tidb:8.1.0:*:*:*:*:*:*:*
Vendors & Products Pingcap
Pingcap tidb
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Sep 2024 20:15:00 +0000

Type Values Removed Values Added
Description PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it will check the expression between 'Agg' and 'GroupBy', but does not check the return type.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-25T21:04:05.076467

Reserved: 2024-07-18T00:00:00

Link: CVE-2024-41434

cve-icon Vulnrichment

Updated: 2024-09-03T20:48:20.025Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-03T20:15:07.573

Modified: 2025-09-04T18:48:19.997

Link: CVE-2024-41434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses