Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44171

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 5.8
EPSS Низкий

Описание

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper backup can never contain such paths, but a specially crafted archive could have caused mbstream to create files outside of the target-dir path. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

A flaw was found in MariaDB's mbstream utility. This vulnerability allows a highly privileged local attacker, who can provide a specially crafted archive, to create files outside of the intended target directory. This is due to mbstream not properly validating paths containing directory traversal sequences (e.g., "/../") during archive unpacking. Successful exploitation could lead to unauthorized file creation, potentially impacting system integrity or availability.

Отчет

This Moderate vulnerability in MariaDB's mbstream utility could allow a highly privileged local attacker to create arbitrary files outside of the designated target directory. By providing a specially crafted archive, an attacker could exploit a path traversal flaw during archive unpacking, potentially impacting the integrity and availability of Red Hat systems utilizing MariaDB.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mariadbNot affected
Red Hat Enterprise Linux 9mariadbNot affected
Red Hat Enterprise Linux 10mariadb10.11FixedRHSA-2026:3309329.06.2026
Red Hat Enterprise Linux 10mariadb11.8FixedRHSA-2026:3341230.06.2026
Red Hat Enterprise Linux 8mariadbFixedRHSA-2026:3346430.06.2026
Red Hat Enterprise Linux 9mariadbFixedRHSA-2026:3348130.06.2026
Red Hat Enterprise Linux 9mariadbFixedRHSA-2026:3348230.06.2026
Red Hat Hardened Imagesmariadb11-8-main-11.8.8-1.hum1FixedRHSA-2026:2514310.06.2026
Red Hat Hardened Imagesmariadb10-11-main-10.11.18-1.hum1FixedRHSA-2026:2514510.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2488453mariadb: mbstream: Unauthorized file creation via path traversal

EPSS

Процентиль: 3%
0.00135
Низкий

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper backup can never contain such paths, but a specially crafted archive could have caused mbstream to create files outside of the target-dir path. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

CVSS3: 6.3
nvd
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper backup can never contain such paths, but a specially crafted archive could have caused mbstream to create files outside of the target-dir path. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

CVSS3: 6.3
debian
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. From ver ...

CVSS3: 6.3
github
2 месяца назад

path traversal in mbstream

rocky
26 дней назад

Important: mariadb:10.11 security, bug fix, and enhancement update

EPSS

Процентиль: 3%
0.00135
Низкий

5.8 Medium

CVSS3