Skip to content
tidbGHSA-9g6g-xqv5-8g5w

PingCAP TiDB nil pointer dereference

Medium5.4CVE-2024-37820 · Published Jun 25, 2024 · updated Sep 10, 2026

A nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expression.inferCollation.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/pingcap/tidb
Go
< 8.2.08.2.0
Details and references

More tidb advisories

All tidb
Advisory
TiDB vulnerable to Use of Externally-Controlled Format String
Critical9.8Nov 4, 2022
TiDB authentication bypass vulnerability
High7.8Jun 6, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.