Описание
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper backup can never contain such paths, but a specially crafted archive could have caused mbstream to create files outside of the target-dir path. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
A flaw was found in MariaDB's mbstream utility. This vulnerability allows a highly privileged local attacker, who can provide a specially crafted archive, to create files outside of the intended target directory. This is due to mbstream not properly validating paths containing directory traversal sequences (e.g., "/../") during archive unpacking. Successful exploitation could lead to unauthorized file creation, potentially impacting system integrity or availability.
Отчет
This Moderate vulnerability in MariaDB's mbstream utility could allow a highly privileged local attacker to create arbitrary files outside of the designated target directory. By providing a specially crafted archive, an attacker could exploit a path traversal flaw during archive unpacking, potentially impacting the integrity and availability of Red Hat systems utilizing MariaDB.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 7 | mariadb | Not affected | ||
| Red Hat Enterprise Linux 9 | mariadb | Not affected | ||
| Red Hat Enterprise Linux 10 | mariadb10.11 | Fixed | RHSA-2026:33093 | 29.06.2026 |
| Red Hat Enterprise Linux 10 | mariadb11.8 | Fixed | RHSA-2026:33412 | 30.06.2026 |
| Red Hat Enterprise Linux 8 | mariadb | Fixed | RHSA-2026:33464 | 30.06.2026 |
| Red Hat Enterprise Linux 9 | mariadb | Fixed | RHSA-2026:33481 | 30.06.2026 |
| Red Hat Enterprise Linux 9 | mariadb | Fixed | RHSA-2026:33482 | 30.06.2026 |
| Red Hat Hardened Images | mariadb11-8-main-11.8.8-1.hum1 | Fixed | RHSA-2026:25143 | 10.06.2026 |
| Red Hat Hardened Images | mariadb10-11-main-10.11.18-1.hum1 | Fixed | RHSA-2026:25145 | 10.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.8 Medium
CVSS3
Связанные уязвимости
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper backup can never contain such paths, but a specially crafted archive could have caused mbstream to create files outside of the target-dir path. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper backup can never contain such paths, but a specially crafted archive could have caused mbstream to create files outside of the target-dir path. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
MariaDB server is a community developed fork of MySQL server. From ver ...
EPSS
5.8 Medium
CVSS3