MariaDB 服务器是 MySQL 服务器的一个社区开发分支。在版本 10.6.1 到 10.6.28、10.11.19、11.4.13、11.8.9、12.3.3 以及 13.0.2 之间,MariaDB 的访问控制列表(ACL)缓存可能会为角色(role)和本地主机(localhost)用户名生成相同的数据库权限缓存键,原因是两者都使用了空的 IP 组件。攻击者若拥有 CREATE USER 权限,便可创建产生碰撞的主账户;当原始主账户的数据库权限被缓存后,攻击者即可利用该缓存行使分配给另一账户的权限。此问题
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107815 | 8.5 HIGH | MariaDB: one byte OOB write in DOS tables of the CONNECT engine |
| CVE-2026-107814 | 8.4 HIGH | MariaDB: Insecure $HOME in MariaDB rpm packages |
| CVE-2026-107818 | 8.4 HIGH | MariaDB: environment injection via wsrep bootstrap in the mariadb.service file |
| CVE-2026-107821 | 8.0 HIGH | MariaDB: insufficient validation of binary frm data when opening a table |
| CVE-2026-107823 | 7.2 HIGH | MariaDB: privilege escalation via incorrect view frm parsing |
| CVE-2026-107816 | 6.4 MEDIUM | MariaDB: `qc_info` plugin can do OOB reads if query contains \0 |
| CVE-2026-107819 | 5.9 MEDIUM | MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verific |
| CVE-2026-107817 | 4.4 MEDIUM | MariaDB: mysql_json plugin OOB reads |
No comments yet