Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:19021

Опубликовано: 29 мая 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: galera and mariadb11.8 security update

MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities.

Security Fix(es):

  • MariaDB: MariaDB: Remote Code Execution or Denial of Service via JSON_SCHEMA_VALID() function vulnerability (CVE-2026-32710)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
mariadb11.8-client-utilsnoarch2.el10_2mariadb11.8-client-utils-11.8.6-2.el10_2.noarch.rpm
mariadb11.8-errmsgnoarch2.el10_2mariadb11.8-errmsg-11.8.6-2.el10_2.noarch.rpm
mariadb11.8-commonnoarch2.el10_2mariadb11.8-common-11.8.6-2.el10_2.noarch.rpm
mariadb11.8-testaarch642.el10_2mariadb11.8-test-11.8.6-2.el10_2.aarch64.rpm
mariadb11.8-embeddedaarch642.el10_2mariadb11.8-embedded-11.8.6-2.el10_2.aarch64.rpm
mariadb11.8-embedded-develaarch642.el10_2mariadb11.8-embedded-devel-11.8.6-2.el10_2.aarch64.rpm
mariadb11.8-server-utilsnoarch2.el10_2mariadb11.8-server-utils-11.8.6-2.el10_2.noarch.rpm
mariadb11.8-oqgraph-engineaarch642.el10_2mariadb11.8-oqgraph-engine-11.8.6-2.el10_2.aarch64.rpm
mariadb11.8-develaarch642.el10_2mariadb11.8-devel-11.8.6-2.el10_2.aarch64.rpm
mariadb11.8-pamaarch642.el10_2mariadb11.8-pam-11.8.6-2.el10_2.aarch64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.5
ubuntu
4 месяца назад

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.

CVSS3: 7.5
redhat
4 месяца назад

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.

CVSS3: 8.5
nvd
4 месяца назад

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.

CVSS3: 8.5
debian
4 месяца назад

MariaDB server is a community developed fork of MySQL server. An authe ...

suse-cvrf
3 месяца назад

Security update for mariadb