{"cves":[{"id":"CVE-2025-55642","published":"2026-06-15T00:00:00","updated_at":"2026-06-26T07:27:25.282799+00:00","description":"\nGPAC MP4Box v2.4 was discovered to contain a floating point exception in\nthe avidmx_process function (isomedia/isom_write.c).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-55642"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-55641","published":"2026-06-15T00:00:00","updated_at":"2026-06-26T07:27:25.282799+00:00","description":"\nA NULL pointer dereference in the gf_isom_copy_sample_info function\n(isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a\nDenial of Service (DoS) via supplying a crafted MP4 file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-55641"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-54411","published":"2026-06-14T18:17:00","updated_at":"2026-08-13T20:05:29.049336+00:00","description":"\nLinux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208)\nin the pam_userdb module's plaintext-password comparison path in\nmodules/pam_userdb/pam_userdb.c that allows a local or network-adjacent\nattacker able to repeatedly drive authentication through a calling service\nto recover the plaintext password of a target account by measuring\nresponse-timing differences.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is only an issue when pam_userdb is used with crypt set to\nnone, which means configured to store password in plaintext in\nthe database."}],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/AU:N/V:D","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54411","https://ubuntu.com/security/notices/USN-8601-1"],"bugs":["https://github.com/linux-pam/linux-pam/issues/992"],"patches":{"pam":["upstream: https://github.com/linux-pam/linux-pam/commit/30708d973b63891bf700299ce3ae0f1086398284"]},"tags":{},"packages":[{"name":"pam","source":"https://ubuntu.com/security/cve?package=pam","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pam","debian":"https://tracker.debian.org/pkg/pam","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.4.0-11ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.5.3-5ubuntu5.6","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.7.0-5ubuntu3.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8601-1"],"notices":[{"id":"USN-8601-1","title":"PAM vulnerability","summary":"PAM could be made to expose sensitive information.","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.","references":[],"published":"2026-07-23T14:49:52.150101","description":"It was discovered that PAM had a timing discrepancy in the pam_userdb\nmodule when comparing plaintext passwords. An attacker could possibly use\nthis issue to obtain sensitive information by measuring response-timing\ndifferences during repeated authentication attempts.","is_hidden":false,"release_packages":{"jammy":[{"name":"pam","version":"1.4.0-11ubuntu2.7","description":"Pluggable Authentication Modules","is_source":true},{"name":"libpam-cracklib","version":"1.4.0-11ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.4.0-11ubuntu2.7","pocket":"security"},{"name":"libpam-doc","version":"1.4.0-11ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.4.0-11ubuntu2.7","pocket":"security"},{"name":"libpam-modules","version":"1.4.0-11ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.4.0-11ubuntu2.7","pocket":"security"},{"name":"libpam-modules-bin","version":"1.4.0-11ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.4.0-11ubuntu2.7","pocket":"security"},{"name":"libpam-runtime","version":"1.4.0-11ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.4.0-11ubuntu2.7","pocket":"security"},{"name":"libpam0g","version":"1.4.0-11ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.4.0-11ubuntu2.7","pocket":"security"},{"name":"libpam0g-dev","version":"1.4.0-11ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.4.0-11ubuntu2.7","pocket":"security"}],"noble":[{"name":"pam","version":"1.5.3-5ubuntu5.6","description":"Pluggable Authentication Modules","is_source":true},{"name":"libpam-doc","version":"1.5.3-5ubuntu5.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.5.3-5ubuntu5.6","pocket":"security"},{"name":"libpam-modules","version":"1.5.3-5ubuntu5.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.5.3-5ubuntu5.6","pocket":"security"},{"name":"libpam-modules-bin","version":"1.5.3-5ubuntu5.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.5.3-5ubuntu5.6","pocket":"security"},{"name":"libpam-runtime","version":"1.5.3-5ubuntu5.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.5.3-5ubuntu5.6","pocket":"security"},{"name":"libpam0g","version":"1.5.3-5ubuntu5.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.5.3-5ubuntu5.6","pocket":"security"},{"name":"libpam0g-dev","version":"1.5.3-5ubuntu5.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.5.3-5ubuntu5.6","pocket":"security"}],"resolute":[{"name":"pam","version":"1.7.0-5ubuntu3.1","description":"Pluggable Authentication Modules","is_source":true},{"name":"libpam-doc","version":"1.7.0-5ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.7.0-5ubuntu3.1","pocket":"security"},{"name":"libpam-modules","version":"1.7.0-5ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.7.0-5ubuntu3.1","pocket":"security"},{"name":"libpam-modules-bin","version":"1.7.0-5ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.7.0-5ubuntu3.1","pocket":"security"},{"name":"libpam-runtime","version":"1.7.0-5ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.7.0-5ubuntu3.1","pocket":"security"},{"name":"libpam0g","version":"1.7.0-5ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.7.0-5ubuntu3.1","pocket":"security"},{"name":"libpam0g-dev","version":"1.7.0-5ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.7.0-5ubuntu3.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-54411"]}]},{"id":"CVE-2026-11526","published":"2026-06-14T12:16:00","updated_at":"2026-06-30T18:09:32.697094+00:00","description":"\nGD versions before 2.86 for Perl allow OS command injection and file\noverwrite via a 2-arg open() of filename arguments in _make_filehandle.\nGD::Image::_make_filehandle opens a filename argument with Perl's 2-arg\nopen(), so a filename that begins or ends with a pipe (\"| cmd\", \"cmd |\") or\nbegins with a redirect (\"> path\", \">> path\") is run as a command or\nredirect rather than opened as a file. _make_filehandle is the single open\npath behind every filename-accepting constructor (new, newFromPng,\nnewFromJpeg, and the rest); the in-memory *Data variants do not open a path\nand are unaffected.\nAny caller that forwards untrusted input to one of these constructors as a\npathname can run an arbitrary command or truncate a file under the process\nUID.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11526","https://lists.security.metacpan.org/cve-announce/msg/41004664/","https://ubuntu.com/security/notices/USN-8484-1"],"bugs":[""],"patches":{"libgd-perl":["upstream: https://github.com/lstein/Perl-GD/commit/67b163713c6c78dfeb693da0978ae934e5cd8210"]},"tags":{},"packages":[{"name":"libgd-perl","source":"https://ubuntu.com/security/cve?package=libgd-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libgd-perl","debian":"https://tracker.debian.org/pkg/libgd-perl","statuses":[{"release_codename":"jammy","status":"released","description":"2.76-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.78-1ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"2.78-1ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.84-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.84-3","component":null,"pocket":"security"}]}],"notices_ids":["USN-8484-1"],"notices":[{"id":"USN-8484-1","title":"GD.pm vulnerability","summary":"GD.pm could be made to run programs or overwrite files if it opened a\nspecially crafted file.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-30T11:42:57.258734","description":"It was discovered that GD.pm incorrectly handled filename arguments. An\nattacker could possibly use this issue to execute arbitrary commands or\noverwrite files.","is_hidden":false,"release_packages":{"jammy":[{"name":"libgd-perl","version":"2.76-2ubuntu0.1","description":"Perl module wrapper for libgd","is_source":true},{"name":"libgd-perl","version":"2.76-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgd-perl","version_link":"https://launchpad.net/ubuntu/+source/libgd-perl/2.76-2ubuntu0.1","pocket":"security"}],"noble":[{"name":"libgd-perl","version":"2.78-1ubuntu0.24.04.1","description":"Perl module wrapper for libgd","is_source":true},{"name":"libgd-perl","version":"2.78-1ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgd-perl","version_link":"https://launchpad.net/ubuntu/+source/libgd-perl/2.78-1ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"libgd-perl","version":"2.78-1ubuntu0.25.10.1","description":"Perl module wrapper for libgd","is_source":true},{"name":"libgd-perl","version":"2.78-1ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgd-perl","version_link":"https://launchpad.net/ubuntu/+source/libgd-perl/2.78-1ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"libgd-perl","version":"2.84-2ubuntu0.1","description":"Perl module wrapper for libgd","is_source":true},{"name":"libgd-perl","version":"2.84-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgd-perl","version_link":"https://launchpad.net/ubuntu/+source/libgd-perl/2.84-2ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-11526"]}]},{"id":"CVE-2026-54421","published":"2026-06-14T04:16:00","updated_at":"2026-06-26T07:35:35.288860+00:00","description":"\nIn OpenStack Ironic before 37.0.1, when applying a PATCH to update fields\nin volume properties the user is authorized for, Ironic can return\nunredacted sensitive information (such as iSCSI credentials). The PATCH\noutcome is a security issue; the POST outcome is not a security issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54421","https://bugs.launchpad.net/ironic/+bug/2155049"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140012"],"patches":{"ironic":[]},"tags":{},"packages":[{"name":"ironic","source":"https://ubuntu.com/security/cve?package=ironic","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ironic","debian":"https://tracker.debian.org/pkg/ironic","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-54057","published":"2026-06-12T21:16:00","updated_at":"2026-09-15T20:01:52.632299+00:00","description":"\nKitty is a cross-platform GPU based terminal. In versions prior to 0.47.3,\nkitty's OSC 21 (color-control) query reply reflects attacker-controlled\nbytes, including newlines, into the shell's input without sanitization.\nVersion 0.47.3 fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54057","https://github.com/kovidgoyal/kitty/security/advisories/GHSA-5gmr-9gwg-hhq6","https://ubuntu.com/security/notices/USN-8763-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139898"],"patches":{"kitty":[]},"tags":{},"packages":[{"name":"kitty","source":"https://ubuntu.com/security/cve?package=kitty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kitty","debian":"https://tracker.debian.org/pkg/kitty","statuses":[{"release_codename":"upstream","status":"released","description":"0.47.3-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.45.0-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8763-1"],"notices":[{"id":"USN-8763-1","title":"kitty vulnerabilities","summary":"Several security issues were fixed in kitty.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-15T13:31:45.928117","description":"It was discovered that kitty incorrectly escaped error messages when\nhandling specially crafted terminal escape sequences. A remote attacker\ncould possibly use this issue to execute arbitrary commands.\n(CVE-2026-42850)\n\nIt was discovered that kitty incorrectly handled remote edit requests in\nterminal output. An attacker could possibly use this issue to execute\narbitrary code with the user's privileges.\n(CVE-2026-42851)\n\nThai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly\nhandled destination paths in its file transmission protocol. A local\nattacker could possibly use this issue to overwrite arbitrary files with\nthe user's privileges.\n(CVE-2026-54055)\n\nIt was discovered that kitty incorrectly sanitized responses to color\nqueries. An attacker could possibly use this issue to execute arbitrary\ncommands with the user's privileges. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-54057)","is_hidden":false,"release_packages":{"noble":[{"name":"kitty","version":"0.32.2-1ubuntu0.4+esm2","description":"fast, featureful, GPU based terminal emulator","is_source":true},{"name":"kitty","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-doc","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-shell-integration","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-terminfo","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"}],"resolute":[{"name":"kitty","version":"0.45.0-1ubuntu0.1~esm2","description":"fast, featureful, GPU based terminal emulator","is_source":true},{"name":"kitty","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-doc","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-shell-integration","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-terminfo","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-42851","CVE-2026-42850","CVE-2026-54055","CVE-2026-54057"]}]},{"id":"CVE-2026-54056","published":"2026-06-12T21:16:00","updated_at":"2026-06-19T08:57:16.954900+00:00","description":"\nKitty is a cross-platform GPU based terminal. In versions 0.47.0 and\n0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to\noverwrite or truncate arbitrary files writable by the local kitty user.\nRemote `text/uri-list` drops are staged in a temporary directory, but on\ncase-sensitive filesystems duplicate remote basenames are not\nde-duplicated. An attacker can first create a staged symlink and then send\na same-name regular-file entry. The regular-file write uses\n`utils.CreateAt()` / `openat(O_RDWR|O_CREAT|O_TRUNC)` without `O_NOFOLLOW`,\nso it follows the attacker-created symlink and writes outside the staging\ndirectory before final overwrite confirmation runs. This appears related in\nclass to the file-transfer symlink advisory, but it is a different bug: it\naffects `kitten dnd` remote drag-and-drop staging, uses different\nvulnerable code (`kittens/dnd/drop.go` and `tools/utils/file_at_fd.go`),\nand reproduces on commit `4aa4a5c0567a92553a8c20a88a4352da637fca5d`, after\nthe file-transfer `O_NOFOLLOW` fix. Version 0.47.2 patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":7.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54056","https://github.com/kovidgoyal/kitty/security/advisories/GHSA-r892-cv7q-fw8x"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139898"],"patches":{"kitty":[]},"tags":{},"packages":[{"name":"kitty","source":"https://ubuntu.com/security/cve?package=kitty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kitty","debian":"https://tracker.debian.org/pkg/kitty","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.47.3-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-54055","published":"2026-06-12T20:16:00","updated_at":"2026-09-15T20:00:49.807495+00:00","description":"\nKitty is a cross-platform GPU based terminal. In versions prior to 0.47.2,\na local privilege escalation vulnerability exists in kitty's file\ntransmission protocol where a child process running in the terminal can\nwrite to arbitrary files on the filesystem by exploiting a TOCTOU\n(Time-of-Check-Time-of-Use) race condition between symlink validation and\nfile creation. The `os.open()` call used to create files does not use\n`O_NOFOLLOW`, allowing an attacker to create a symlink between the initial\nstat check and the actual file open, causing the write to follow the\nsymlink to an arbitrary destination. Version 0.47.2 fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":5.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54055","https://github.com/kovidgoyal/kitty/security/advisories/GHSA-q446-x7q6-vcxh","https://ubuntu.com/security/notices/USN-8763-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139898"],"patches":{"kitty":[]},"tags":{},"packages":[{"name":"kitty","source":"https://ubuntu.com/security/cve?package=kitty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kitty","debian":"https://tracker.debian.org/pkg/kitty","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.47.3-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.32.2-1ubuntu0.4+esm2","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"0.45.0-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8763-1"],"notices":[{"id":"USN-8763-1","title":"kitty vulnerabilities","summary":"Several security issues were fixed in kitty.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-15T13:31:45.928117","description":"It was discovered that kitty incorrectly escaped error messages when\nhandling specially crafted terminal escape sequences. A remote attacker\ncould possibly use this issue to execute arbitrary commands.\n(CVE-2026-42850)\n\nIt was discovered that kitty incorrectly handled remote edit requests in\nterminal output. An attacker could possibly use this issue to execute\narbitrary code with the user's privileges.\n(CVE-2026-42851)\n\nThai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly\nhandled destination paths in its file transmission protocol. A local\nattacker could possibly use this issue to overwrite arbitrary files with\nthe user's privileges.\n(CVE-2026-54055)\n\nIt was discovered that kitty incorrectly sanitized responses to color\nqueries. An attacker could possibly use this issue to execute arbitrary\ncommands with the user's privileges. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-54057)","is_hidden":false,"release_packages":{"noble":[{"name":"kitty","version":"0.32.2-1ubuntu0.4+esm2","description":"fast, featureful, GPU based terminal emulator","is_source":true},{"name":"kitty","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-doc","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-shell-integration","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-terminfo","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"}],"resolute":[{"name":"kitty","version":"0.45.0-1ubuntu0.1~esm2","description":"fast, featureful, GPU based terminal emulator","is_source":true},{"name":"kitty","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-doc","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-shell-integration","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-terminfo","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-42851","CVE-2026-42850","CVE-2026-54055","CVE-2026-54057"]}]},{"id":"CVE-2026-42851","published":"2026-06-12T20:16:00","updated_at":"2026-09-15T20:00:35.888114+00:00","description":"\nKitty is a cross-platform GPU based terminal. In versions prior to 0.47.0,\na program able to write bytes to a kitty terminal — a remote SSH peer, a\ndownloaded file viewed with `cat`, a log line, an email body rendered in\n`less`, an issue body in a TUI, etc. — can cause kitty to execute\nattacker-supplied Python inside the running kitty process, with the user's\nfull privileges. There is no approval prompt, no remote-control permission\nrequirement, no shell-integration interaction, no clipboard touch, and no\neditor interaction. Version 0.47.0 fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42851","https://github.com/kovidgoyal/kitty/security/advisories/GHSA-w98g-hpvr-r332","https://ubuntu.com/security/notices/USN-8763-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139898"],"patches":{"kitty":[]},"tags":{},"packages":[{"name":"kitty","source":"https://ubuntu.com/security/cve?package=kitty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kitty","debian":"https://tracker.debian.org/pkg/kitty","statuses":[{"release_codename":"upstream","status":"released","description":"0.47.0-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.32.2-1ubuntu0.4+esm2","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"0.45.0-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8763-1"],"notices":[{"id":"USN-8763-1","title":"kitty vulnerabilities","summary":"Several security issues were fixed in kitty.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-15T13:31:45.928117","description":"It was discovered that kitty incorrectly escaped error messages when\nhandling specially crafted terminal escape sequences. A remote attacker\ncould possibly use this issue to execute arbitrary commands.\n(CVE-2026-42850)\n\nIt was discovered that kitty incorrectly handled remote edit requests in\nterminal output. An attacker could possibly use this issue to execute\narbitrary code with the user's privileges.\n(CVE-2026-42851)\n\nThai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly\nhandled destination paths in its file transmission protocol. A local\nattacker could possibly use this issue to overwrite arbitrary files with\nthe user's privileges.\n(CVE-2026-54055)\n\nIt was discovered that kitty incorrectly sanitized responses to color\nqueries. An attacker could possibly use this issue to execute arbitrary\ncommands with the user's privileges. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-54057)","is_hidden":false,"release_packages":{"noble":[{"name":"kitty","version":"0.32.2-1ubuntu0.4+esm2","description":"fast, featureful, GPU based terminal emulator","is_source":true},{"name":"kitty","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-doc","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-shell-integration","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-terminfo","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"}],"resolute":[{"name":"kitty","version":"0.45.0-1ubuntu0.1~esm2","description":"fast, featureful, GPU based terminal emulator","is_source":true},{"name":"kitty","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-doc","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-shell-integration","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-terminfo","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-42851","CVE-2026-42850","CVE-2026-54055","CVE-2026-54057"]}]},{"id":"CVE-2026-42850","published":"2026-06-12T20:16:00","updated_at":"2026-09-15T20:00:49.807495+00:00","description":"\nKitty is a cross-platform GPU based terminal. In versions prior to 0.47.0,\nit is possible to inject commands within the subshell through kitty error.\nA special escape code will make kitty return an error, this error is not\nescaped and will be correctly echoed back to the terminal with CRLF, as\nsuch it will be run by the shell in use. To exploit this bug, the victim\nmust use a netcat or a similar program to connect to the attacker, or else\nlistening for someone to connect. Once this condition is set, an attacker\ncould pwn the computer of the victim using a special kitty's escape code\nthat will run a command in the shell in use. Version 04.7.0 fixes the\nissue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42850","https://github.com/kovidgoyal/kitty/security/advisories/GHSA-p64q-59hq-5q65","https://ubuntu.com/security/notices/USN-8763-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139898"],"patches":{"kitty":[]},"tags":{},"packages":[{"name":"kitty","source":"https://ubuntu.com/security/cve?package=kitty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kitty","debian":"https://tracker.debian.org/pkg/kitty","statuses":[{"release_codename":"upstream","status":"released","description":"0.47.0-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.45.0-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.32.2-1ubuntu0.4+esm2","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8763-1"],"notices":[{"id":"USN-8763-1","title":"kitty vulnerabilities","summary":"Several security issues were fixed in kitty.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-15T13:31:45.928117","description":"It was discovered that kitty incorrectly escaped error messages when\nhandling specially crafted terminal escape sequences. A remote attacker\ncould possibly use this issue to execute arbitrary commands.\n(CVE-2026-42850)\n\nIt was discovered that kitty incorrectly handled remote edit requests in\nterminal output. An attacker could possibly use this issue to execute\narbitrary code with the user's privileges.\n(CVE-2026-42851)\n\nThai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly\nhandled destination paths in its file transmission protocol. A local\nattacker could possibly use this issue to overwrite arbitrary files with\nthe user's privileges.\n(CVE-2026-54055)\n\nIt was discovered that kitty incorrectly sanitized responses to color\nqueries. An attacker could possibly use this issue to execute arbitrary\ncommands with the user's privileges. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-54057)","is_hidden":false,"release_packages":{"noble":[{"name":"kitty","version":"0.32.2-1ubuntu0.4+esm2","description":"fast, featureful, GPU based terminal emulator","is_source":true},{"name":"kitty","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-doc","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-shell-integration","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-terminfo","version":"0.32.2-1ubuntu0.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"}],"resolute":[{"name":"kitty","version":"0.45.0-1ubuntu0.1~esm2","description":"fast, featureful, GPU based terminal emulator","is_source":true},{"name":"kitty","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-doc","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-shell-integration","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"},{"name":"kitty-terminfo","version":"0.45.0-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-42851","CVE-2026-42850","CVE-2026-54055","CVE-2026-54057"]}]},{"id":"CVE-2026-42306","published":"2026-06-12T19:16:00","updated_at":"2026-06-19T08:55:56.324750+00:00","description":"\nMoby is an open source container framework. In Docker Engine prior to\nversion 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon\nprior to version 2.0.0-beta.14, a race condition during docker cp mount\nsetup allows a malicious container to redirect a bind mount target to an\narbitrary host path, potentially overwriting host files or causing denial\nof service. This issue has been patched in Docker Engine version 29.5.1 and\nMoby Daemon version 2.0.0-beta.14.","ubuntu_description":"","notes":[{"author":"alexmurray","note":"Traditionally the docker.io source package contained both the\nlibrary and docker application. However, in releases that\ncontain the\ndocker.io-app source package, the docker.io source package\ncontains only\nthe library whilst the docker application itself is contained\nin the\ndocker.io-app package."},{"author":"sbeattie","note":"docker packages contain an embedded copy of github:moby/buildkit"}],"codename":null,"priority":"medium","cvss3":7.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42306","https://github.com/moby/moby/security/advisories/GHSA-rg2x-37c3-w2rh"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139967"],"patches":{"docker.io":[],"docker.io-app":[]},"tags":{},"packages":[{"name":"docker.io","source":"https://ubuntu.com/security/cve?package=docker.io","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=docker.io","debian":"https://tracker.debian.org/pkg/docker.io","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"docker.io-app","source":"https://ubuntu.com/security/cve?package=docker.io-app","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=docker.io-app","debian":"https://tracker.debian.org/pkg/docker.io-app","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41568","published":"2026-06-12T19:16:00","updated_at":"2026-06-19T08:55:56.324750+00:00","description":"\nMoby is an open source container framework. In Docker Engine prior to\nversion 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon\nprior to version 2.0.0-beta.14, a race condition during docker cp mount\nsetup allows a malicious container to create empty files or directories at\narbitrary absolute paths on the host filesystem. This issue has been\npatched in Docker Engine version 29.5.1 and Moby Daemon version\n2.0.0-beta.14.","ubuntu_description":"","notes":[{"author":"alexmurray","note":"Traditionally the docker.io source package contained both the\nlibrary and docker application. However, in releases that\ncontain the\ndocker.io-app source package, the docker.io source package\ncontains only\nthe library whilst the docker application itself is contained\nin the\ndocker.io-app package."},{"author":"sbeattie","note":"docker packages contain an embedded copy of github:moby/buildkit"}],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41568","https://github.com/moby/moby/security/advisories/GHSA-vp62-88p7-qqf5"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139966"],"patches":{"docker.io":[],"docker.io-app":[]},"tags":{},"packages":[{"name":"docker.io","source":"https://ubuntu.com/security/cve?package=docker.io","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=docker.io","debian":"https://tracker.debian.org/pkg/docker.io","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"docker.io-app","source":"https://ubuntu.com/security/cve?package=docker.io-app","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=docker.io-app","debian":"https://tracker.debian.org/pkg/docker.io-app","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-12143","published":"2026-06-12T19:16:00","updated_at":"2026-06-19T08:55:12.509357+00:00","description":"\nform-data is a library for creating readable multipart/form-data streams.\nIn versions through 4.0.5, the `field` argument to `FormData#append` and\nthe `filename` option are concatenated verbatim into the\n`Content-Disposition` header without escaping carriage return (CR), line\nfeed (LF), or double-quote (\") characters. An application that passes\nattacker-controlled data as a field name or filename (for example, an API\ngateway that turns JSON object keys into multipart field names) allows the\nattacker to terminate the header line and inject additional headers, or to\nsmuggle entire additional multipart parts, into the request the application\nforwards to a backend. This can let the attacker add or override form\nfields (e.g. set `is_admin=true`) seen by the downstream parser. This is an\ninstance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `\"` as\n`%0D`, `%0A`, and `%22` in field names and filenames, matching the\nserialization browsers use per the WHATWG HTML multipart/form-data encoding\nalgorithm. Exploitation requires the consuming application to use untrusted\ninput as a field name or filename; applications that use only fixed/trusted\nfield names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-12143","https://github.com/form-data/form-data/security/advisories/GHSA-hmw2-7cc7-3qxx","https://cwe.mitre.org/data/definitions/93.html","https://github.com/form-data/form-data/commit/64190db548c0179e37206858e39f27cf513e9435","https://github.com/form-data/form-data/commit/be3f3cf553978bac15a5182f1f3c3d2d38ccf229","https://github.com/form-data/form-data/commit/c7133499c2ee1b80c678e411244f4442bf902045","https://html.spec.whatwg.org/multipage/form-control-infrastructure.html#multipart-form-data","https://www.npmjs.com/package/form-data"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139959"],"patches":{"node-form-data":[]},"tags":{},"packages":[{"name":"node-form-data","source":"https://ubuntu.com/security/cve?package=node-form-data","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=node-form-data","debian":"https://tracker.debian.org/pkg/node-form-data","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48165","published":"2026-06-12T18:16:00","updated_at":"2026-07-16T09:55:53.302982+00:00","description":"\nMariaDB server is a community developed fork of MySQL server. From versions\n10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before\n11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB\nuser could've used wsrep_sst_receive_address or wsrep_sst_donor global\nsystem variables to execute shell commands as the uid of the mariadbd\nprocess on the galera joiner node. This issue has been patched in versions\n10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48165","https://mariadb.com/docs/release-notes/community-server/11.8/11.8.8","https://ubuntu.com/security/notices/USN-8536-1"],"bugs":["https://jira.mariadb.org/browse/MDEV-39676"],"patches":{"mariadb":["upstream: https://github.com/MariaDB/server/commit/13e6808f0138175ad48bf91b6487f56f33c51919","upstream: https://github.com/MariaDB/server/commit/a9e2f7f648f339c6f49b5bbe0435fa6b04a27ed2"],"mariadb-10.0":[],"mariadb-10.1":[],"mariadb-10.3":[],"mariadb-10.6":[]},"tags":{},"packages":[{"name":"mariadb","source":"https://ubuntu.com/security/cve?package=mariadb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb","debian":"https://tracker.debian.org/pkg/mariadb","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:11.8.6-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.0","source":"https://ubuntu.com/security/cve?package=mariadb-10.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.0","debian":"https://tracker.debian.org/pkg/mariadb-10.0","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.1","source":"https://ubuntu.com/security/cve?package=mariadb-10.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.1","debian":"https://tracker.debian.org/pkg/mariadb-10.1","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.3","source":"https://ubuntu.com/security/cve?package=mariadb-10.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.3","debian":"https://tracker.debian.org/pkg/mariadb-10.3","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.6","source":"https://ubuntu.com/security/cve?package=mariadb-10.6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.6","debian":"https://tracker.debian.org/pkg/mariadb-10.6","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8536-1"],"notices":[{"id":"USN-8536-1","title":"MariaDB vulnerabilities","summary":"Several security issues were fixed in MariaDB.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-14T11:45:03.813587","description":"It was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the\nmariabackup method. An attacker could possibly use this issue to execute\narbitrary shell commands on the donor node. (CVE-2026-44168)\n\nIt was discovered that MariaDB did not properly enforce the SHOW CREATE\nROUTINE privilege when a user obtained access to a stored routine via a\nrole. An authenticated user could possibly use this issue to obtain\nsensitive information. (CVE-2026-44169)\n\nIt was discovered that MariaDB's mbstream utility did not properly validate\npaths when unpacking archives. An attacker could possibly use this issue to\nwrite files outside of the intended target directory. (CVE-2026-44171)\n\nIt was discovered that MariaDB's mysql_real_escape_string() function\nincorrectly handled the big5 character set. An attacker could possibly use\nthis issue to perform SQL injection attacks. (CVE-2026-44172)\n\nIt was discovered that MariaDB did not properly check the FILE privilege\nwhen the FROM clause of a SELECT ... INTO OUTFILE or SELECT ... INTO\nDUMPFILE statement contained only subqueries. An authenticated user could\npossibly use this issue to write files to unintended locations.\n(CVE-2026-44173)\n\nIt was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the rsync\nmethod. An attacker could possibly use this issue to execute arbitrary\nshell commands on the donor node. (CVE-2026-48163)\n\nIt was discovered that MariaDB allowed a high-privileged user to set\ncertain Galera system variables to values containing shell commands, which\nwere then executed by the server process. An authenticated user could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-48165)\n\nIt was discovered that MariaDB executed shell commands embedded in the name\nof a joiner node when wsrep_notify_cmd was enabled. A remote attacker could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-49261)","is_hidden":false,"release_packages":{"resolute":[{"name":"mariadb","version":"1:11.8.6-5ubuntu0.1","description":"MariaDB database","is_source":true},{"name":"libmariadb-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb-dev-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd19t64","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-backup","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-common","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect-jdbc","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-cracklib-password-check","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-hashicorp-key-management","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-mroonga","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-oqgraph","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-bzip2","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lz4","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzma","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzo","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-snappy","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-rocksdb","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-s3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-spider","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test-data","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-49261","CVE-2026-44168","CVE-2026-44169","CVE-2026-48163","CVE-2026-44172","CVE-2026-44173","CVE-2026-48165","CVE-2026-44171"]}]},{"id":"CVE-2026-48163","published":"2026-06-12T18:16:00","updated_at":"2026-07-16T09:55:53.302982+00:00","description":"\nMariaDB server is a community developed fork of MySQL server. From versions\n10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before\n11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node\nis interpolating parameters that the joiner sent into the command line. Not\nall parameters were properly validated which could allow a malicious joiner\nto execute arbitrary shell commands on the donor side via the rsync SST\nmethod. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12,\n11.8.8, and 12.3.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48163","https://mariadb.com/docs/release-notes/community-server/11.8/11.8.8","https://ubuntu.com/security/notices/USN-8536-1"],"bugs":["https://jira.mariadb.org/browse/MDEV-39648"],"patches":{"mariadb":["upstream: https://github.com/MariaDB/server/commit/dae315a7b2bf8bd2fd0449467e711e5a2db26669"],"mariadb-10.0":[],"mariadb-10.1":[],"mariadb-10.3":[],"mariadb-10.6":[]},"tags":{},"packages":[{"name":"mariadb","source":"https://ubuntu.com/security/cve?package=mariadb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb","debian":"https://tracker.debian.org/pkg/mariadb","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:11.8.6-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.0","source":"https://ubuntu.com/security/cve?package=mariadb-10.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.0","debian":"https://tracker.debian.org/pkg/mariadb-10.0","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.1","source":"https://ubuntu.com/security/cve?package=mariadb-10.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.1","debian":"https://tracker.debian.org/pkg/mariadb-10.1","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.3","source":"https://ubuntu.com/security/cve?package=mariadb-10.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.3","debian":"https://tracker.debian.org/pkg/mariadb-10.3","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.6","source":"https://ubuntu.com/security/cve?package=mariadb-10.6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.6","debian":"https://tracker.debian.org/pkg/mariadb-10.6","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8536-1"],"notices":[{"id":"USN-8536-1","title":"MariaDB vulnerabilities","summary":"Several security issues were fixed in MariaDB.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-14T11:45:03.813587","description":"It was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the\nmariabackup method. An attacker could possibly use this issue to execute\narbitrary shell commands on the donor node. (CVE-2026-44168)\n\nIt was discovered that MariaDB did not properly enforce the SHOW CREATE\nROUTINE privilege when a user obtained access to a stored routine via a\nrole. An authenticated user could possibly use this issue to obtain\nsensitive information. (CVE-2026-44169)\n\nIt was discovered that MariaDB's mbstream utility did not properly validate\npaths when unpacking archives. An attacker could possibly use this issue to\nwrite files outside of the intended target directory. (CVE-2026-44171)\n\nIt was discovered that MariaDB's mysql_real_escape_string() function\nincorrectly handled the big5 character set. An attacker could possibly use\nthis issue to perform SQL injection attacks. (CVE-2026-44172)\n\nIt was discovered that MariaDB did not properly check the FILE privilege\nwhen the FROM clause of a SELECT ... INTO OUTFILE or SELECT ... INTO\nDUMPFILE statement contained only subqueries. An authenticated user could\npossibly use this issue to write files to unintended locations.\n(CVE-2026-44173)\n\nIt was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the rsync\nmethod. An attacker could possibly use this issue to execute arbitrary\nshell commands on the donor node. (CVE-2026-48163)\n\nIt was discovered that MariaDB allowed a high-privileged user to set\ncertain Galera system variables to values containing shell commands, which\nwere then executed by the server process. An authenticated user could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-48165)\n\nIt was discovered that MariaDB executed shell commands embedded in the name\nof a joiner node when wsrep_notify_cmd was enabled. A remote attacker could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-49261)","is_hidden":false,"release_packages":{"resolute":[{"name":"mariadb","version":"1:11.8.6-5ubuntu0.1","description":"MariaDB database","is_source":true},{"name":"libmariadb-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb-dev-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd19t64","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-backup","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-common","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect-jdbc","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-cracklib-password-check","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-hashicorp-key-management","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-mroonga","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-oqgraph","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-bzip2","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lz4","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzma","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzo","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-snappy","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-rocksdb","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-s3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-spider","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test-data","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-49261","CVE-2026-44168","CVE-2026-44169","CVE-2026-48163","CVE-2026-44172","CVE-2026-44173","CVE-2026-48165","CVE-2026-44171"]}]},{"id":"CVE-2026-44173","published":"2026-06-12T18:16:00","updated_at":"2026-07-16T09:55:53.302982+00:00","description":"\nMariaDB server is a community developed fork of MySQL server. From versions\n10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before\n11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ...\nINTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE\nprivilege if the FROM clause contained only subqueries. This issue has been\npatched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44173","https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7","https://ubuntu.com/security/notices/USN-8536-1"],"bugs":["https://jira.mariadb.org/browse/MDEV-39493"],"patches":{"mariadb":["upstream: https://github.com/MariaDB/server/commit/c0fb8448332972fce3adc176f195a573f9fdc83d"],"mariadb-10.0":[],"mariadb-10.1":[],"mariadb-10.3":[],"mariadb-10.6":[]},"tags":{},"packages":[{"name":"mariadb","source":"https://ubuntu.com/security/cve?package=mariadb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb","debian":"https://tracker.debian.org/pkg/mariadb","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:11.8.6-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.0","source":"https://ubuntu.com/security/cve?package=mariadb-10.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.0","debian":"https://tracker.debian.org/pkg/mariadb-10.0","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.1","source":"https://ubuntu.com/security/cve?package=mariadb-10.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.1","debian":"https://tracker.debian.org/pkg/mariadb-10.1","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.3","source":"https://ubuntu.com/security/cve?package=mariadb-10.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.3","debian":"https://tracker.debian.org/pkg/mariadb-10.3","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.6","source":"https://ubuntu.com/security/cve?package=mariadb-10.6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.6","debian":"https://tracker.debian.org/pkg/mariadb-10.6","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8536-1"],"notices":[{"id":"USN-8536-1","title":"MariaDB vulnerabilities","summary":"Several security issues were fixed in MariaDB.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-14T11:45:03.813587","description":"It was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the\nmariabackup method. An attacker could possibly use this issue to execute\narbitrary shell commands on the donor node. (CVE-2026-44168)\n\nIt was discovered that MariaDB did not properly enforce the SHOW CREATE\nROUTINE privilege when a user obtained access to a stored routine via a\nrole. An authenticated user could possibly use this issue to obtain\nsensitive information. (CVE-2026-44169)\n\nIt was discovered that MariaDB's mbstream utility did not properly validate\npaths when unpacking archives. An attacker could possibly use this issue to\nwrite files outside of the intended target directory. (CVE-2026-44171)\n\nIt was discovered that MariaDB's mysql_real_escape_string() function\nincorrectly handled the big5 character set. An attacker could possibly use\nthis issue to perform SQL injection attacks. (CVE-2026-44172)\n\nIt was discovered that MariaDB did not properly check the FILE privilege\nwhen the FROM clause of a SELECT ... INTO OUTFILE or SELECT ... INTO\nDUMPFILE statement contained only subqueries. An authenticated user could\npossibly use this issue to write files to unintended locations.\n(CVE-2026-44173)\n\nIt was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the rsync\nmethod. An attacker could possibly use this issue to execute arbitrary\nshell commands on the donor node. (CVE-2026-48163)\n\nIt was discovered that MariaDB allowed a high-privileged user to set\ncertain Galera system variables to values containing shell commands, which\nwere then executed by the server process. An authenticated user could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-48165)\n\nIt was discovered that MariaDB executed shell commands embedded in the name\nof a joiner node when wsrep_notify_cmd was enabled. A remote attacker could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-49261)","is_hidden":false,"release_packages":{"resolute":[{"name":"mariadb","version":"1:11.8.6-5ubuntu0.1","description":"MariaDB database","is_source":true},{"name":"libmariadb-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb-dev-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd19t64","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-backup","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-common","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect-jdbc","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-cracklib-password-check","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-hashicorp-key-management","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-mroonga","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-oqgraph","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-bzip2","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lz4","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzma","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzo","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-snappy","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-rocksdb","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-s3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-spider","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test-data","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-49261","CVE-2026-44168","CVE-2026-44169","CVE-2026-48163","CVE-2026-44172","CVE-2026-44173","CVE-2026-48165","CVE-2026-44171"]}]},{"id":"CVE-2026-44172","published":"2026-06-12T18:16:00","updated_at":"2026-07-16T09:55:53.302982+00:00","description":"\nMariaDB server is a community developed fork of MySQL server. In versions\n3.3.18 and 3.4.8, an application that was taking non-validated user input,\nescaping it with mysql_real_escape_string() and sending it to the database\nusing text protocol and big5 character set was vulnerable to SQL\ninjections, even though mysql_real_escape_string() was supposed to prevent\nthem. This issue has been patched in versions 3.3.19 and 3.4.9.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"code is in libmariadb subdirectory"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44172","https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7","https://ubuntu.com/security/notices/USN-8536-1"],"bugs":["https://jira.mariadb.org/browse/CONC-819"],"patches":{"mariadb":["upstream: https://github.com/mariadb-corporation/mariadb-connector-c/commit/1f168de4e09838ffe14da061142ed387541aa25d"],"mariadb-10.0":[],"mariadb-10.1":[],"mariadb-10.3":[],"mariadb-10.6":[]},"tags":{},"packages":[{"name":"mariadb","source":"https://ubuntu.com/security/cve?package=mariadb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb","debian":"https://tracker.debian.org/pkg/mariadb","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:11.8.6-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.0","source":"https://ubuntu.com/security/cve?package=mariadb-10.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.0","debian":"https://tracker.debian.org/pkg/mariadb-10.0","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.1","source":"https://ubuntu.com/security/cve?package=mariadb-10.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.1","debian":"https://tracker.debian.org/pkg/mariadb-10.1","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.3","source":"https://ubuntu.com/security/cve?package=mariadb-10.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.3","debian":"https://tracker.debian.org/pkg/mariadb-10.3","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.6","source":"https://ubuntu.com/security/cve?package=mariadb-10.6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.6","debian":"https://tracker.debian.org/pkg/mariadb-10.6","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8536-1"],"notices":[{"id":"USN-8536-1","title":"MariaDB vulnerabilities","summary":"Several security issues were fixed in MariaDB.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-14T11:45:03.813587","description":"It was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the\nmariabackup method. An attacker could possibly use this issue to execute\narbitrary shell commands on the donor node. (CVE-2026-44168)\n\nIt was discovered that MariaDB did not properly enforce the SHOW CREATE\nROUTINE privilege when a user obtained access to a stored routine via a\nrole. An authenticated user could possibly use this issue to obtain\nsensitive information. (CVE-2026-44169)\n\nIt was discovered that MariaDB's mbstream utility did not properly validate\npaths when unpacking archives. An attacker could possibly use this issue to\nwrite files outside of the intended target directory. (CVE-2026-44171)\n\nIt was discovered that MariaDB's mysql_real_escape_string() function\nincorrectly handled the big5 character set. An attacker could possibly use\nthis issue to perform SQL injection attacks. (CVE-2026-44172)\n\nIt was discovered that MariaDB did not properly check the FILE privilege\nwhen the FROM clause of a SELECT ... INTO OUTFILE or SELECT ... INTO\nDUMPFILE statement contained only subqueries. An authenticated user could\npossibly use this issue to write files to unintended locations.\n(CVE-2026-44173)\n\nIt was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the rsync\nmethod. An attacker could possibly use this issue to execute arbitrary\nshell commands on the donor node. (CVE-2026-48163)\n\nIt was discovered that MariaDB allowed a high-privileged user to set\ncertain Galera system variables to values containing shell commands, which\nwere then executed by the server process. An authenticated user could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-48165)\n\nIt was discovered that MariaDB executed shell commands embedded in the name\nof a joiner node when wsrep_notify_cmd was enabled. A remote attacker could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-49261)","is_hidden":false,"release_packages":{"resolute":[{"name":"mariadb","version":"1:11.8.6-5ubuntu0.1","description":"MariaDB database","is_source":true},{"name":"libmariadb-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb-dev-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd19t64","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-backup","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-common","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect-jdbc","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-cracklib-password-check","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-hashicorp-key-management","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-mroonga","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-oqgraph","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-bzip2","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lz4","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzma","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzo","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-snappy","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-rocksdb","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-s3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-spider","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test-data","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-49261","CVE-2026-44168","CVE-2026-44169","CVE-2026-48163","CVE-2026-44172","CVE-2026-44173","CVE-2026-48165","CVE-2026-44171"]}]},{"id":"CVE-2026-44171","published":"2026-06-12T18:16:00","updated_at":"2026-07-16T09:55:53.302982+00:00","description":"\nMariaDB server is a community developed fork of MySQL server. From versions\n10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before\n11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for\n/../ in the path when unpacking the archive. A proper backup can never\ncontain such paths, but a specially crafted archive could have caused\nmbstream to create files outside of the target-dir path. This issue has\nbeen patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44171","https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7","https://ubuntu.com/security/notices/USN-8536-1"],"bugs":["https://jira.mariadb.org/browse/MDEV-39408"],"patches":{"mariadb":["upstream: https://github.com/MariaDB/server/commit/2bbfcb187602613611912238cbb765e6e7caed4b"],"mariadb-10.0":[],"mariadb-10.1":[],"mariadb-10.3":[],"mariadb-10.6":[]},"tags":{},"packages":[{"name":"mariadb","source":"https://ubuntu.com/security/cve?package=mariadb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb","debian":"https://tracker.debian.org/pkg/mariadb","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:11.8.6-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.0","source":"https://ubuntu.com/security/cve?package=mariadb-10.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.0","debian":"https://tracker.debian.org/pkg/mariadb-10.0","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.1","source":"https://ubuntu.com/security/cve?package=mariadb-10.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.1","debian":"https://tracker.debian.org/pkg/mariadb-10.1","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.3","source":"https://ubuntu.com/security/cve?package=mariadb-10.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.3","debian":"https://tracker.debian.org/pkg/mariadb-10.3","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.6","source":"https://ubuntu.com/security/cve?package=mariadb-10.6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.6","debian":"https://tracker.debian.org/pkg/mariadb-10.6","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8536-1"],"notices":[{"id":"USN-8536-1","title":"MariaDB vulnerabilities","summary":"Several security issues were fixed in MariaDB.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-14T11:45:03.813587","description":"It was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the\nmariabackup method. An attacker could possibly use this issue to execute\narbitrary shell commands on the donor node. (CVE-2026-44168)\n\nIt was discovered that MariaDB did not properly enforce the SHOW CREATE\nROUTINE privilege when a user obtained access to a stored routine via a\nrole. An authenticated user could possibly use this issue to obtain\nsensitive information. (CVE-2026-44169)\n\nIt was discovered that MariaDB's mbstream utility did not properly validate\npaths when unpacking archives. An attacker could possibly use this issue to\nwrite files outside of the intended target directory. (CVE-2026-44171)\n\nIt was discovered that MariaDB's mysql_real_escape_string() function\nincorrectly handled the big5 character set. An attacker could possibly use\nthis issue to perform SQL injection attacks. (CVE-2026-44172)\n\nIt was discovered that MariaDB did not properly check the FILE privilege\nwhen the FROM clause of a SELECT ... INTO OUTFILE or SELECT ... INTO\nDUMPFILE statement contained only subqueries. An authenticated user could\npossibly use this issue to write files to unintended locations.\n(CVE-2026-44173)\n\nIt was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the rsync\nmethod. An attacker could possibly use this issue to execute arbitrary\nshell commands on the donor node. (CVE-2026-48163)\n\nIt was discovered that MariaDB allowed a high-privileged user to set\ncertain Galera system variables to values containing shell commands, which\nwere then executed by the server process. An authenticated user could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-48165)\n\nIt was discovered that MariaDB executed shell commands embedded in the name\nof a joiner node when wsrep_notify_cmd was enabled. A remote attacker could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-49261)","is_hidden":false,"release_packages":{"resolute":[{"name":"mariadb","version":"1:11.8.6-5ubuntu0.1","description":"MariaDB database","is_source":true},{"name":"libmariadb-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb-dev-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd19t64","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-backup","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-common","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect-jdbc","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-cracklib-password-check","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-hashicorp-key-management","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-mroonga","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-oqgraph","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-bzip2","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lz4","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzma","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzo","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-snappy","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-rocksdb","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-s3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-spider","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test-data","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-49261","CVE-2026-44168","CVE-2026-44169","CVE-2026-48163","CVE-2026-44172","CVE-2026-44173","CVE-2026-48165","CVE-2026-44171"]}]},{"id":"CVE-2026-44170","published":"2026-06-12T18:16:00","updated_at":"2026-07-11T19:27:24.064550+00:00","description":"\nMariaDB server is a community developed fork of MySQL server. From versions\n10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before\n11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with\ninstalled CONNECT engine and enabled REST support interpolated table HTTP\nattribute into the curl command line without proper sanitizing. This allows\nthe user to execute shell commands on the server. This issue has been\npatched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is a windows-specific issue"}],"codename":null,"priority":"medium","cvss3":9.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44170","https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7"],"bugs":["https://jira.mariadb.org/browse/MDEV-39289"],"patches":{"mariadb":["upstream: https://github.com/MariaDB/server/commit/aca6743d5345ffa49a7c17db01734475cd3d2783"],"mariadb-10.0":[],"mariadb-10.1":[],"mariadb-10.3":[],"mariadb-10.6":[]},"tags":{},"packages":[{"name":"mariadb","source":"https://ubuntu.com/security/cve?package=mariadb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb","debian":"https://tracker.debian.org/pkg/mariadb","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was not-affected (windows only)","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.0","source":"https://ubuntu.com/security/cve?package=mariadb-10.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.0","debian":"https://tracker.debian.org/pkg/mariadb-10.0","statuses":[{"release_codename":"xenial","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.1","source":"https://ubuntu.com/security/cve?package=mariadb-10.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.1","debian":"https://tracker.debian.org/pkg/mariadb-10.1","statuses":[{"release_codename":"bionic","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.3","source":"https://ubuntu.com/security/cve?package=mariadb-10.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.3","debian":"https://tracker.debian.org/pkg/mariadb-10.3","statuses":[{"release_codename":"focal","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.6","source":"https://ubuntu.com/security/cve?package=mariadb-10.6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.6","debian":"https://tracker.debian.org/pkg/mariadb-10.6","statuses":[{"release_codename":"jammy","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44169","published":"2026-06-12T18:16:00","updated_at":"2026-07-16T09:55:53.302982+00:00","description":"\nMariaDB server is a community developed fork of MySQL server. From versions\n11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user\ngetting EXECUTE access to a stored routine via a role, could see the\nroutine definition even without SHOW CREATE ROUTINE privilege. This issue\nhas been patched in versions 11.4.11, 11.8.7, and 12.3.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44169","https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7","https://ubuntu.com/security/notices/USN-8536-1"],"bugs":["https://jira.mariadb.org/browse/MDEV-39288"],"patches":{"mariadb":["upstream: https://github.com/MariaDB/server/commit/f279551013d1319f27344080e2c0758f3959cebf"],"mariadb-10.0":[],"mariadb-10.1":[],"mariadb-10.3":[],"mariadb-10.6":[]},"tags":{},"packages":[{"name":"mariadb","source":"https://ubuntu.com/security/cve?package=mariadb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb","debian":"https://tracker.debian.org/pkg/mariadb","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:11.8.6-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.0","source":"https://ubuntu.com/security/cve?package=mariadb-10.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.0","debian":"https://tracker.debian.org/pkg/mariadb-10.0","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.1","source":"https://ubuntu.com/security/cve?package=mariadb-10.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.1","debian":"https://tracker.debian.org/pkg/mariadb-10.1","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.3","source":"https://ubuntu.com/security/cve?package=mariadb-10.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.3","debian":"https://tracker.debian.org/pkg/mariadb-10.3","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.6","source":"https://ubuntu.com/security/cve?package=mariadb-10.6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mariadb-10.6","debian":"https://tracker.debian.org/pkg/mariadb-10.6","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8536-1"],"notices":[{"id":"USN-8536-1","title":"MariaDB vulnerabilities","summary":"Several security issues were fixed in MariaDB.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-14T11:45:03.813587","description":"It was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the\nmariabackup method. An attacker could possibly use this issue to execute\narbitrary shell commands on the donor node. (CVE-2026-44168)\n\nIt was discovered that MariaDB did not properly enforce the SHOW CREATE\nROUTINE privilege when a user obtained access to a stored routine via a\nrole. An authenticated user could possibly use this issue to obtain\nsensitive information. (CVE-2026-44169)\n\nIt was discovered that MariaDB's mbstream utility did not properly validate\npaths when unpacking archives. An attacker could possibly use this issue to\nwrite files outside of the intended target directory. (CVE-2026-44171)\n\nIt was discovered that MariaDB's mysql_real_escape_string() function\nincorrectly handled the big5 character set. An attacker could possibly use\nthis issue to perform SQL injection attacks. (CVE-2026-44172)\n\nIt was discovered that MariaDB did not properly check the FILE privilege\nwhen the FROM clause of a SELECT ... INTO OUTFILE or SELECT ... INTO\nDUMPFILE statement contained only subqueries. An authenticated user could\npossibly use this issue to write files to unintended locations.\n(CVE-2026-44173)\n\nIt was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the rsync\nmethod. An attacker could possibly use this issue to execute arbitrary\nshell commands on the donor node. (CVE-2026-48163)\n\nIt was discovered that MariaDB allowed a high-privileged user to set\ncertain Galera system variables to values containing shell commands, which\nwere then executed by the server process. An authenticated user could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-48165)\n\nIt was discovered that MariaDB executed shell commands embedded in the name\nof a joiner node when wsrep_notify_cmd was enabled. A remote attacker could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-49261)","is_hidden":false,"release_packages":{"resolute":[{"name":"mariadb","version":"1:11.8.6-5ubuntu0.1","description":"MariaDB database","is_source":true},{"name":"libmariadb-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb-dev-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd19t64","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-backup","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-common","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect-jdbc","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-cracklib-password-check","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-hashicorp-key-management","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-mroonga","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-oqgraph","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-bzip2","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lz4","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzma","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzo","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-snappy","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-rocksdb","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-s3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-spider","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test-data","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-49261","CVE-2026-44168","CVE-2026-44169","CVE-2026-48163","CVE-2026-44172","CVE-2026-44173","CVE-2026-48165","CVE-2026-44171"]}]}],"offset":9660,"limit":20,"total_results":79316}