Lack of data validation In mariadb
Description
MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 1:11.8.6-0+deb13u1 | ||
rpm rhel9 | 3:11.8.6-2.module+el9.8.0+24146+e179c349 | ||
debian 14 | 1:11.8.6-1 | ||
rpm rhel10 | 3:11.8.6-2.el10_2 | ||
rpm rhel10 | 0:26.4.25-1.el10_2 |
Aliases
1. 2. 3. 4. 5.
References
1.