CVE-2026-32710
EUVD-2026-1376420.03.2026, 19:16
MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | 11.4.1 ≤ 𝑥 < 11.4.10 |
| mariadb | mariadb | 11.8.1 ≤ 𝑥 < 11.8.6 |
| mariadb | mariadb | 12.1.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| mariadb |
| ||||||||||
| mariadb-10.0 |
| ||||||||||
| mariadb-10.1 |
| ||||||||||
| mariadb-10.3 |
| ||||||||||
| mariadb-10.6 |
|
openSUSE / SLES Releases
openSUSE Product | |||||
|---|---|---|---|---|---|
| libmariadbd-devel |
| ||||
| libmariadbd19 |
| ||||
| mariadb |
| ||||
| mariadb-client |
| ||||
| mariadb-errormessages |
| ||||
| mariadb-tools |
|
Vulnerability Media Exposure