Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-33481

Опубликовано: 02 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-33481: mariadb:11.8 security, bug fix, and enhancement update (IMPORTANT)

galera [26.4.27-1.0.1]

  • Drop nmap-ncat requirement. [Orabug: 34116228]
  • Requirement to delete lp1184034 test case without using patches.

[26.4.27-1]

  • Rebased to 26.4.27

[26.4.26-1]

  • Rebased to 26.4.26

mariadb [3:11.8.8-1]

  • Rebase to 11.8.8

[3:11.8.7-1]

  • Rebase to 11.8.7

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

Module mariadb:11.8 is enabled

galera

26.4.27-1.0.1.module+el9.8.0+90939+4d45f560

mariadb

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-backup

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-client-utils

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-common

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-devel

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-embedded

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-embedded-devel

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-errmsg

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-gssapi-server

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-oqgraph-engine

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-pam

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-server

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-server-galera

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-server-utils

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-test

11.8.8-1.module+el9.8.0+90939+4d45f560

Oracle Linux x86_64

Module mariadb:11.8 is enabled

galera

26.4.27-1.0.1.module+el9.8.0+90939+4d45f560

mariadb

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-backup

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-client-utils

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-common

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-devel

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-embedded

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-embedded-devel

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-errmsg

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-gssapi-server

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-oqgraph-engine

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-pam

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-server

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-server-galera

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-server-utils

11.8.8-1.module+el9.8.0+90939+4d45f560

mariadb-test

11.8.8-1.module+el9.8.0+90939+4d45f560

Связанные CVE

Связанные уязвимости

CVSS3: 10
ubuntu
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 9
redhat
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 10
nvd
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 10
debian
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions ...

CVSS3: 10
github
около 2 месяцев назад

unsafe parameter handing in `wsrep_notify_cmd`