Описание
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with wsrep_notify_cmd enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable wsrep_notify_cmd.
A flaw was found in MariaDB server. When the wsrep_notify_cmd feature is enabled, a remote attacker could exploit this vulnerability by embedding shell commands in the name of a joiner node. This could lead to arbitrary code execution on the server, allowing the attacker to take full control of the affected system.
Отчет
Red Hat has assessed this vulnerability as Important. Exploitation requires the wsrep_notify_cmd server variable to be explicitly set to a notification script by the administrator. This variable is empty by default in the upstream configuration, and Red Hat's shipped Galera configuration additionally defaults to wsrep_on=0. Additionally, the attacker must stand up a MariaDB/Galera node that is accepted into the cluster membership view in order to inject a malicious node name.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 7 | mariadb | Not affected | ||
| Red Hat Enterprise Linux 9 | mariadb | Not affected | ||
| Red Hat Enterprise Linux 10 | mariadb10.11 | Fixed | RHSA-2026:33093 | 29.06.2026 |
| Red Hat Enterprise Linux 10 | mariadb11.8 | Fixed | RHSA-2026:33412 | 30.06.2026 |
| Red Hat Enterprise Linux 8 | mariadb | Fixed | RHSA-2026:33464 | 30.06.2026 |
| Red Hat Enterprise Linux 9 | mariadb | Fixed | RHSA-2026:33481 | 30.06.2026 |
| Red Hat Enterprise Linux 9 | mariadb | Fixed | RHSA-2026:33482 | 30.06.2026 |
| Red Hat Hardened Images | mariadb11-8-main-11.8.8-1.hum1 | Fixed | RHSA-2026:25143 | 10.06.2026 |
| Red Hat Hardened Images | mariadb10-11-main-10.11.18-1.hum1 | Fixed | RHSA-2026:25145 | 10.06.2026 |
Показывать по
Дополнительная информация
Статус:
9 Critical
CVSS3
Связанные уязвимости
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.
MariaDB server is a community developed fork of MySQL server. Versions ...
unsafe parameter handing in `wsrep_notify_cmd`
ELSA-2026-33482: mariadb:10.11 security, bug fix, and enhancement update (IMPORTANT)
9 Critical
CVSS3