Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:19584

Опубликовано: 06 нояб. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: galera and mariadb security update

Galera is a fast synchronous multimaster wsrep provider (replication engine) for transactional databases and similar applications. For more information about wsrep API see https://github.com/codership/wsrep-API repository. For a description of Galera replication engine see https://www.galeracluster.com web.

Security Fix(es):

  • mysql: High Privilege Denial of Service Vulnerability in MySQL Server (CVE-2025-21490)

  • mariadb: MariaDB Server Crash Due to Empty Backtrace Log (CVE-2023-52969)

  • mariadb: MariaDB Server Crash via Item_direct_view_ref (CVE-2023-52970)

  • mysql: mysqldump unspecified vulnerability (CPU Apr 2025) (CVE-2025-30722)

  • mysql: InnoDB unspecified vulnerability (CPU Apr 2025) (CVE-2025-30693)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
galerax86_641.el9_6galera-26.4.22-1.el9_6.x86_64.rpm

Показывать по

Связанные уязвимости

rocky
12 дней назад

Moderate: mariadb:10.5 security update

oracle-oval
около 1 месяца назад

ELSA-2025-19584: galera and mariadb security update (MODERATE)

oracle-oval
около 1 месяца назад

ELSA-2025-19572: mariadb:10.5 security update (MODERATE)

suse-cvrf
3 месяца назад

Security update for mariadb

CVSS3: 4.9
ubuntu
9 месяцев назад

MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This may be related to make_aggr_tables_info and optimize_stage2.