MariaDB 服务器是 MySQL 服务器的一个社区开发的分支。在 10.6.1 至 10.6.28、10.11.19、11.4.13、11.8.9、12.3.3 和 13.0.2 版本之间,MariaDB RPM 安装包在创建专用的 服务账户时,将其数据库数据目录设置为该账户的家目录。具有 权限的数据库用户可以将启动时加载的点文件(如 )写入 目录,当管理员为 账户打开登录 shell 时,这些文件将被执行。Debian 包不受此问题影响,因为它们使用 作为账户的家目录。该问题已在版本 10.6.28、10.1
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107815 | 8.5 HIGH | MariaDB: one byte OOB write in DOS tables of the CONNECT engine |
| CVE-2026-107818 | 8.4 HIGH | MariaDB: environment injection via wsrep bootstrap in the mariadb.service file |
| CVE-2026-107821 | 8.0 HIGH | MariaDB: insufficient validation of binary frm data when opening a table |
| CVE-2026-107823 | 7.2 HIGH | MariaDB: privilege escalation via incorrect view frm parsing |
| CVE-2026-107816 | 6.4 MEDIUM | MariaDB: `qc_info` plugin can do OOB reads if query contains \0 |
| CVE-2026-107822 | 6.4 MEDIUM | MariaDB: database privilege escalation via user / role name collision in the acl cache |
| CVE-2026-107819 | 5.9 MEDIUM | MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verific |
| CVE-2026-107817 | 4.4 MEDIUM | MariaDB: mysql_json plugin OOB reads |
No comments yet