MariaDB 服务器是 MySQL 服务器的一个社区开发的分支。在版本 10.6.1 到 10.6.28、10.11.19、11.4.13、11.8.9、12.3.3 以及 13.0.2 之间,mariadb.service 单元在下次服务重启时会使用 /run/mysqld/wsrep-new-cluster。如果一个数据库用户拥有 FILE 权限,并且 secure-file-priv 配置允许向 /run/mysqld 写入文件,那么该用户可以创建此文件,并将攻击者控制的環境变量注入到重启后的服务中。此问题
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107815 | 8.5 HIGH | MariaDB: one byte OOB write in DOS tables of the CONNECT engine |
| CVE-2026-107814 | 8.4 HIGH | MariaDB: Insecure $HOME in MariaDB rpm packages |
| CVE-2026-107821 | 8.0 HIGH | MariaDB: insufficient validation of binary frm data when opening a table |
| CVE-2026-107823 | 7.2 HIGH | MariaDB: privilege escalation via incorrect view frm parsing |
| CVE-2026-107816 | 6.4 MEDIUM | MariaDB: `qc_info` plugin can do OOB reads if query contains \0 |
| CVE-2026-107822 | 6.4 MEDIUM | MariaDB: database privilege escalation via user / role name collision in the acl cache |
| CVE-2026-107819 | 5.9 MEDIUM | MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verific |
| CVE-2026-107817 | 4.4 MEDIUM | MariaDB: mysql_json plugin OOB reads |
No comments yet