MariaDB 服务器是 MySQL 服务器的社区开发分支。在版本 10.6.1 至 10.6.27、10.11.18、11.4.12、11.8.8 和 12.3.2 中,MariaDB 的视图 FRM 解析器未能对用户名字符中嵌入的换行符进行安全编码。拥有 CREATE USER 和 CREATE VIEW WITH GRANT OPTION 权限的账户可以创建一个精心构造的用户名,其中包含额外的视图元数据,导致解析器将用户名的部分数据误认为安全元数据,从而可能提升数据库权限。该问题已在版本 10.6.28、10
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107815 | 8.5 HIGH | MariaDB: one byte OOB write in DOS tables of the CONNECT engine |
| CVE-2026-107814 | 8.4 HIGH | MariaDB: Insecure $HOME in MariaDB rpm packages |
| CVE-2026-107818 | 8.4 HIGH | MariaDB: environment injection via wsrep bootstrap in the mariadb.service file |
| CVE-2026-107821 | 8.0 HIGH | MariaDB: insufficient validation of binary frm data when opening a table |
| CVE-2026-107816 | 6.4 MEDIUM | MariaDB: `qc_info` plugin can do OOB reads if query contains \0 |
| CVE-2026-107822 | 6.4 MEDIUM | MariaDB: database privilege escalation via user / role name collision in the acl cache |
| CVE-2026-107819 | 5.9 MEDIUM | MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verific |
| CVE-2026-107817 | 4.4 MEDIUM | MariaDB: mysql_json plugin OOB reads |
No comments yet