KB5104824 - Cumulative Update 27 for SQL Server 2022

Release Date:   September 15, 2026
Version:   16.0.4295.3

Summary

This article describes Cumulative Update package 27 (CU27) for Microsoft SQL Server 2022. This update contains 41 fixes that were issued after the release of SQL Server 2022 Cumulative Update 26. It updates components in the following builds:

  • SQL Server - Product version: 16.0.4295.3, file version: 2022.160.4295.3
  • Analysis Services - Product version: 16.0.43.252, file version: 2022.160.43.252

Important

To help secure SQL Server on Windows, enable encryption with Extended Protection.

Known issues in this update

Incorrect behavior of SESSION_CONTEXT in parallel plans

Queries that use the built-in SESSION_CONTEXT function might return incorrect results or trigger access violation (AV) dump files when they're run in parallel query plans. This issue occurs because of the manner in which SESSION_CONTEXT interacts with parallel execution threads, particularly if the session is reset for reuse.

For more information, see the "Known issues" section in SESSION_CONTEXT.

Linked server queries that use MSDASQL fail with error 7416

Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

Msg 7416, Level 16
Access to the remote server is denied because no login-mapping exists.

A stricter connection validation check in the database engine can reject connections for certain linked server configurations that use the MSDASQL provider. This is true even if earlier builds allowed those connections.

For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

Access violation when you query sys.dm_exec_requests during database recovery

Queries against sys.dm_exec_requests might raise an access violation and generate a dump file if they run while a database is still recovering. This issue can occur during a database RESTORE operation, during startup recovery, or before an availability group replica finishes coming online.

When this issue occurs, the SQL Server error log contains entries that resemble the following text:

The database '<DatabaseName>' is marked RESTORING and is in a state that does not allow recovery to be run.
***Stack Dump being sent to <SQLServerLogFolder>\SQLDump0215.txt
SqlDumpExceptionHandler: Process 77 generated fatal exception c0000005 EXCEPTION_ACCESS_VIOLATION. SQL Server is terminating this process.
*******************************************************************************

BEGIN STACK DUMP:
  07/30/26 07:37:23 spid 77

Exception Address = <frame id="00" address="0x7FFDED94970D" pdb="sqlmin.pdb" age="2" guid="E1039014-237E-4DB6-88FD-4A2AB31C651F" module="sqlmin" rva="0x2970D" />
Exception Code    = c0000005 EXCEPTION_ACCESS_VIOLATION
Access Violation occurred reading address 00000000000000F0
Input Buffer <size> bytes -
          <dbo.sp_YourMonitoringStoredProcedure>

This issue occurs because of a change that causes internal in-memory structures to be referenced before they're fully initialized.

Microsoft is aware of this issue and is investigating a fix. Until a fix is available, use one of the following mitigations:

  • Enable trace flag 4696 to opt out of the code change that causes this issue. If you enable this trace flag, monitoring queries that query sys.dm_exec_requests or sys.sysprocesses on secondary replicas might return error 976 or error 978, as they did before you installed this update.
  • Avoid queries against sys.dm_exec_requests for databases that are recovering.
  • Uninstall this update.

Improvements and fixes included in this update

A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists for SQL Server 2022, SQL Server 2019, and SQL Server 2017. Download this Excel file now.

Note

Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

For more information about the bugs that are fixed and enhancements that are included in this cumulative update, see the following table.

Bug reference Description Fix area Component Platform
2796714 Fixes a rare issue in which rolling back a user transaction causes database corruption that DBCC CHECKDB reports as Page Free Space (PFS) page errors if Accelerated Database Recovery (ADR) is disabled. SQL Server Engine Storage Management All
4929823 Fixes an issue in which restoring a database by using Volume Shadow Copy Service (VSS) and WITH MOVE takes a long time or times out if the server contains hundreds of databases. SQL Server Engine Backup Restore Windows
5126055 Fixes an issue in which creating a database user fails and returns character mapping or token errors if the display name of the user contains Kanji or other Unicode characters that the system default code page doesn't support. SQL Server Engine Security Infrastructure Windows
5383380 Fixes a vulnerability that affects the SQL Server-managed backup to Microsoft Azure stored procedures, managed_backup.sp_get_encryption_option and managed_backup.sp_do_backup. Customers who use managed backup should apply this update through the standard SQL Server servicing process. SQL Server Engine Management Services All
5421858 Fixes a timing-dependent race condition that occurs during interrupt delivery while SQL Server on Linux handles exceptions. SQL Server Engine Linux Linux
5434228 Improves the validation of backup metadata that the SQL Server VSS Writer processes so that malformed or undersized metadata is rejected safely. SQL Server Engine Backup Restore Windows
5442243 Improves security validation when SQL Server Agent loads task agent components. SQL Server Engine SQL Agent Windows
5456077 Improves the reliability and security of SQL Server Agent when it processes certain input. SQL Server Engine Management Services All
5459626 Fixes an issue in which the SQL Server WMI provider processes malformed input incorrectly, while preserving the existing behavior for valid input. SQL Server Client Tools SQL Server WMI Provider Windows
5462844 Fixes a security vulnerability in the handling of sign-in requests that use Microsoft Entra authentication. SQL Server Engine Security Infrastructure All
5473595 Fixes an issue in which creating a database user from Microsoft Entra ID by using the WITH OBJECT_ID option fails if the display name of the user contains Kanji or other Unicode characters that the system default code page doesn't support. SQL Server Engine Security Infrastructure Windows
5478465 Fixes an issue in which a secondary replica fails to join an availability group that has a 64-character name and a cluster type of NONE or EXTERNAL. SQL Server Engine High Availability and Disaster Recovery All
5481778 Fixes an issue that affects the security and reliability of SQL Server Agent under certain operating conditions. SQL Server Engine Management Services All
5482772 Fixes an issue in which the SUBSTRING function reads beyond the allocated buffer when it processes a malformed DBCS varchar value in a natively compiled stored procedure. SQL Server Engine In-Memory OLTP All
5482827 Fixes an access violation that causes the SQL Server process to end unexpectedly when an nvarchar value that contains an ideographic variation sequence is converted or truncated under a variation selector sensitive (_VSS) collation in a natively compiled stored procedure. SQL Server Engine In-Memory OLTP All
5482833 Fixes an issue in which streaming nvarchar(max) data under a variation selector sensitive (_VSS) collation in a natively compiled stored procedure causes a heap buffer overwrite or causes the server to stop responding. This issue occurs when the TEXTSIZE setting truncates the data and small Tabular Data Stream (TDS) packet sizes are used. SQL Server Engine In-Memory OLTP All
5487409 Improves the validation of responses from S3-compatible external storage endpoints during external data access. SQL Server Engine PolyBase All
5494968 Fixes an issue in which a raw TCP listener is opened for the DW Engine and DMS control and data channels when the PolyBase services are started by using modified command-line parameters. SQL Server Engine PolyBase All
5495398 Fixes an issue in the handling of DTD attribute lists for the xml data type. SQL Server Engine XML All
5495725 Fixes an access violation that occurs if a query includes an extremely large OPTION (USE PLAN) XML declaration. This issue can cause the SQL Server process to end unexpectedly. SQL Server Engine XML All
5496454 Fixes arithmetic overflow and out-of-bounds memory access in the LEFT_SHIFT and RIGHT_SHIFT functions when they process specially crafted shift values or binary input. This issue can cause the SQL Server process to end unexpectedly. SQL Server Engine Programmability All
5496499 Improves the manner in which SQL Server processes and outputs certain internal event data to help better protect information. SQL Server Engine Programmability All
5498913 Fixes a security issue in SQL Server in which insufficient validation in Extended Events can cause memory corruption. SQL Server Engine Extended Events All
5499855 Fixes several security vulnerabilities that allow information disclosure or a denial of service if the Database Engine reads a specially crafted Extended Events (.xel) file. SQL Server Engine Extended Events All
5499869 Fixes an integer overflow in the XML reader that occurs if a specially crafted XML format file is processed through OPENROWSET(BULK ...) or BULK INSERT. This activity can cause the SQL Server process to stop responding or end unexpectedly. SQL Server Engine XML All
5504497 Fixes an issue in which the data_sensitivity_information field isn't consistently populated in audit records that are generated by the SCHEMA_OBJECT_ACCESS_GROUP audit action group. This fix ensures that sensitivity information is reliably included in all applicable audit records. SQL Server Engine Security Infrastructure All
5505127 Fixes an issue in which a class ID lookup in enclave code reads arbitrary memory. SQL Server Engine Security Infrastructure Windows
5505432 Adds bounds validation for embedded attestation fields that are parsed by sys.sp_describe_parameter_encryption. SQL Server Engine Security Infrastructure Windows
5505445 Improves Object Store Format (OSF) deserialization to protect against malformed or malicious stream data. SQL Server Engine Security Infrastructure Windows
5505476 Improves buffer length validation in enclave code. SQL Server Engine Security Infrastructure Windows
5505598 Fixes an improper input validation issue in SQL Server that allows an authenticated user to disclose a limited amount of memory. This fix strengthens input validation. SQL Server Engine Query Optimizer All
5506056 Fixes an improper input validation issue in SQL Server that allows an authenticated user to disclose in-memory information. This fix strengthens input validation. SQL Server Engine Query Optimizer All
5506116 Fixes an improper input validation issue in SQL Server in which an authenticated user can provide a pointer that SQL Server dereferences and reads but does not execute. This issue can cause dump file generation or out-of-memory conditions. This fix strengthens input validation. SQL Server Engine Query Optimizer All
5529156 Fixes improper field offset validation in the SqlDataRecord.SetBytes API for sql_variant values that can cause an out-of-bounds heap write if CLR integration is turned on. SQL Server Engine Programmability Windows
5529195 Improves the handling of Showplan input to enhance security and reliability. SQL Server Engine Query Store Windows
5529339 Improves the protection of internal replication data during processing operations. SQL Server Engine Replication All
5529351 Improves the handling of text data in merge replication to enhance security and reliability. SQL Server Engine Replication All
5529363 Improves the validation and handling of replication operations to enhance security and reliability. SQL Server Engine Replication All
5529375 Improves the security and reliability of queued updating subscriptions in transactional replication. SQL Server Engine Replication Windows
5529387 Improves the security and reliability of queued updating subscriptions in transactional replication. SQL Server Engine Replication Windows
5558709 Fixes an issue in which an upgrade from SQL Server 2019 to SQL Server 2022 stops responding during the replicated_model database upgrade phase on an instance that hosts one or more contained availability groups. SQL Server Engine Programmability All

How to obtain or download this or the latest cumulative update package

How to obtain or download the latest cumulative update package for Windows (recommended)

The following update is available from the Microsoft Download Center:

Download the latest cumulative update package for SQL Server 2022 now

Note

  • Microsoft Download Center always offers the latest SQL Server 2022 CU release.
  • If the download page doesn't appear, contact Microsoft Customer Service and Support to obtain the cumulative update package.
How to obtain or download this cumulative update package for Windows from Microsoft Update Catalog

The following update is available from the Microsoft Update Catalog:

Note

  • Microsoft Update Catalog contains this SQL Server 2022 CU and previously released SQL Server 2022 CU releases.
  • This CU is also available through Windows Server Update Services (WSUS).
  • We recommend that you always install the latest cumulative update that is available.
How to obtain or download the latest cumulative update package for Linux

To update SQL Server 2022 on Linux to the latest CU, you must first have the Cumulative Update repository configured. Then, update your SQL Server packages by using the appropriate platform-specific update command.

For installation instructions and direct links to the CU package downloads, see the SQL Server 2022 Release Notes.

File information

File hash information

You can verify the download by computing the hash of the SQLServer2022-KB5104824-x64.exe file through the following command:

certutil -hashfile SQLServer2022-KB5104824-x64.exe SHA256

File name SHA256 hash
SQLServer2022-KB5104824-x64.exe 675E3CEDD6C7A3D0FFBE713E46E54A86A92AF7B96CA4A6BEB987AE99C79B96F5
Cumulative Update package file information

Download the list of files that are included in KB5104824.

Notes for this update

Prerequisites

To apply this cumulative update package, you must be running SQL Server 2022.

Restart information

You might have to restart the computer after you apply this cumulative update package.

Registry information

To use one of the hotfixes in this package, you don't have to make any changes to the registry.

Important notices

This article also provides the following important information.

Analysis Services CU build version

Beginning in Microsoft SQL Server 2017, the Analysis Services build version number and SQL Server Database Engine build version number don't match. For more information, see Verify Analysis Services cumulative update build version.

Cumulative updates (CU)

  • Each new CU contains all the fixes that were included with the previous CU for the installed version of SQL Server.
  • SQL Server CUs are certified to the same levels as service packs, and should be installed at the same level of confidence.
  • We recommend ongoing, proactive installation of CUs as they become available according to these guidelines:
    • Historical data shows that a significant number of support cases involve an issue that has already been addressed in a released CU.
    • CUs might contain added value over and above hotfixes. This includes supportability, manageability, and reliability updates.
  • We recommend that you test SQL Server CUs before you deploy them to production environments.
Hybrid environment deployment

When you deploy an update to a hybrid environment (such as Always On, replication, cluster, and mirroring), we recommend that you refer to the following articles before you deploy the update:

Language support

SQL Server CUs are currently multilingual. Therefore, this CU package isn't specific to one language. It applies to all supported languages.

Components (features) updated

One CU package includes all available updates for all SQL Server 2022 components (features). However, the cumulative update package updates only those components that are currently installed on the SQL Server instance that you select to be serviced. If a SQL Server feature (for example, Analysis Services) is added to the instance after this CU is applied, you must reapply this CU to update the new feature to this CU.

Support for this update

If other issues occur, or if any troubleshooting is required, you might have to create a service request. The usual support costs will apply to additional support questions and to issues that don't qualify for this specific cumulative update package. For a complete list of Microsoft Customer Service and Support telephone numbers, or to create a separate service request, go to the Microsoft support website.

How to uninstall this update

How to uninstall this update on Windows
  1. In Control Panel, open the Programs and Features item, and then select View installed updates.
  2. Locate the entry that corresponds to this cumulative update package under SQL Server 2022.
  3. Press and hold (or right-click) the entry, and then select Uninstall.
How to uninstall this update on Linux

To uninstall this CU on Linux, you must roll back the package to the previous version. For more information about how to roll back the installation, see Rollback SQL Server.

References