Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-33482

Опубликовано: 02 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-33482: mariadb:10.11 security, bug fix, and enhancement update (IMPORTANT)

galera [26.4.20-1.0.1]

  • Drop nmap-ncat requirement. [Orabug: 34116228]
  • Requirement to delete garbd-wrapper script and lp1184034 test case without using patches. [Orabug: 34116228]

[26.4.20-1]

  • Rebase to 26.4.20

[26.4.19-1]

  • Rebase to 26.4.19

[26.4.18-1]

  • Rebase to 26.4.18

[26.4.16-1]

  • Rebase to 26.4.16

[26.4.14-1]

  • Rebase to 26.4.14

mariadb [3:10.11.18-1]

  • Rebase to 10.11.18

[3:10.11.17-1]

  • Rebase to 10.11.17

[3:10.11.16-1]

  • Rebase to 10.11.16

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

Module mariadb:10.11 is enabled

galera

26.4.20-1.0.1.module+el9.5.0+90507+82ceef20

mariadb

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-backup

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-common

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-devel

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-embedded

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-embedded-devel

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-errmsg

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-gssapi-server

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-oqgraph-engine

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-pam

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-server

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-server-galera

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-server-utils

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-test

10.11.18-1.module+el9.8.0+90943+a8062e5c

Oracle Linux x86_64

Module mariadb:10.11 is enabled

galera

26.4.20-1.0.1.module+el9.5.0+90507+82ceef20

mariadb

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-backup

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-common

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-devel

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-embedded

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-embedded-devel

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-errmsg

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-gssapi-server

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-oqgraph-engine

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-pam

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-server

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-server-galera

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-server-utils

10.11.18-1.module+el9.8.0+90943+a8062e5c

mariadb-test

10.11.18-1.module+el9.8.0+90943+a8062e5c

Связанные CVE

Связанные уязвимости

CVSS3: 10
ubuntu
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 9
redhat
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 10
nvd
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 10
debian
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions ...

CVSS3: 10
github
около 2 месяцев назад

unsafe parameter handing in `wsrep_notify_cmd`