Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-33464

Опубликовано: 30 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-33464: mariadb:10.11 security, bug fix, and enhancement update (IMPORTANT)

galera [26.4.27-1]

  • Rebased to 26.4.27

[26.4.26-1]

  • Rebased to 26.4.26

[26.4.25-1]

  • Rebased to 26.4.25

[26.4.24-1]

  • Rebase to 26.4.24

Judy [1.0.5-18]

  • Remove README.Fedora; no longer needed since 1.0.5 version
  • Resolves: #1638717

[1.0.5-17]

  • ldconfig scriptlets replaced by RPM File Triggers from Fedora 28
  • Drop legacy BuildRoot: and Group: tags
  • Drop redundant explicit buildroot cleaning
  • Specify all explicitly-used build requirements
  • Use %license where possible
  • Drop %defattr, redundant since rpm 4.4

[1.0.5-16]

[1.0.5-15]

[1.0.5-14]

[1.0.5-13]

[1.0.5-12]

[1.0.5-11]

[1.0.5-10]

[1.0.5-9]

mariadb [3:10.11.18-1]

  • Rebase to 10.11.18

[3:10.11.17-1]

  • Rebase to 10.11.17

[3:10.11.16-1]

  • Rebase to 10.11.16

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module mariadb:10.11 is enabled

Judy

1.0.5-18.module+el8.10.0+90753+7c7ea859

galera

26.4.27-1.module+el8.10.0+90935+8cfac62f

mariadb

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-backup

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-common

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-devel

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-embedded

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-embedded-devel

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-errmsg

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-gssapi-server

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-oqgraph-engine

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-pam

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-server

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-server-galera

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-server-utils

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-test

10.11.18-1.module+el8.10.0+90935+8cfac62f

Oracle Linux x86_64

Module mariadb:10.11 is enabled

Judy

1.0.5-18.module+el8.10.0+90753+7c7ea859

galera

26.4.27-1.module+el8.10.0+90935+8cfac62f

mariadb

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-backup

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-common

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-devel

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-embedded

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-embedded-devel

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-errmsg

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-gssapi-server

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-oqgraph-engine

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-pam

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-server

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-server-galera

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-server-utils

10.11.18-1.module+el8.10.0+90935+8cfac62f

mariadb-test

10.11.18-1.module+el8.10.0+90935+8cfac62f

Связанные CVE

Связанные уязвимости

CVSS3: 10
ubuntu
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 9
redhat
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 10
nvd
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 10
debian
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions ...

CVSS3: 10
github
около 2 месяцев назад

unsafe parameter handing in `wsrep_notify_cmd`