Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4gx-34mg-95q5

Опубликовано: 07 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

insufficient validation of binary frm data when opening a table

Impact

MariaDB was insufficiently validating the content of binary frm files it was parsing. Specially constructed invalid frm files could've caused server crashes, OOB reads or writes, and exploited to get a remote code execution.

Patches

Fixed in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2.

Workarounds

To be able to drop a poisoned frm into a datadir one needs to be granted FILE privilege and secure-file-priv must allow access to the datadir. Properly configured server does not allow file level access to the datadir and FILE — a very powerful privilege — is normally granted very sparingly.

References

https://jira.mariadb.org/browse/MDEV-40571

Credits

Reported by pinebudweiser and Ph4nt0m

Пакеты

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=10.6.1, <=10.6.27

10.6.28

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=10.11.1, <=10.11.18

10.11.19

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=11.4.1, <=11.4.12

11.4.13

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=11.8.1, <=11.8.8

11.8.9

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=12.3.1, <=12.3.2

12.3.3

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

13.0.1

13.0.2

8 High

CVSS3

Дефекты

CWE-1285

8 High

CVSS3

Дефекты

CWE-1285