Back Linuxsecurity Fedora 42: Important Advisory for MariaDB 11.8.5 Remote Code Execution
MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities. Update Information : MariaDB 11.8.5 Release notes: server/11.8/11.8.5
MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded
SQL database server. It is a client/server implementation consisting of
a server daemon (mariadbd) and many different client programs and libraries.
The base package contains the standard MariaDB/MySQL client programs and
MariaDB 11.8.5 Release notes: server/11.8/11.8.5
* Thu Nov 20 2025 Pavol Sloboda - 3:11.8.5-1 - Rebase to 11.8.5 * Wed Oct 29 2025 Lukas Javorsky - 3:11.8.3-5 - Revert to soft static allocation of MariaDB and MySQL sysusers.d files * Wed Oct 29 2025 Nikola Davidova - 3:11.8.3-4 - Bump release for tmpfiles.d change * Tue Sep 30 2025 Petr Khartskhaev - 3:11.8.3-3 - Bump release for package rebuild * Tue Aug 12 2025 Michal Schorm - 3:11.8.3-2 - Bump release for package rebuild
* Thu Nov 20 2025 Pavol Sloboda - 3:11.8.5-1 - Rebase to 11.8.5 * Wed Oct 29 2025 Lukas Javorsky - 3:11.8.3-5 - Revert to soft static allocation of MariaDB and MySQL sysusers.d files * Wed Oct 29 2025 Nikola Davidova - 3:11.8.3-4 - Bump release for tmpfiles.d change * Tue Sep 30 2025 Petr Khartskhaev - 3:11.8.3-3 - Bump release for package rebuild * Tue Aug 12 2025 Michal Schorm - 3:11.8.3-2 - Bump release for package rebuild
[ 1 ] Bug #2413295 - mariadb11.8-11.8.5 is available [ 2 ] Bug #2417695 - CVE-2025-13699 mariadb11.8: MariaDB: mariadb-dump utility vulnerable to remote code execution via improper path validation [fedora-42] [ 3 ] Bug #2417697 - CVE-2025-13699 mariadb11.8: MariaDB: mariadb-dump utility vulnerable to remote code execution via improper path validation [fedora-43]
[ 1 ] Bug #2413295 - mariadb11.8-11.8.5 is available [ 2 ] Bug #2417695 - CVE-2025-13699 mariadb11.8: MariaDB: mariadb-dump utility vulnerable to remote code execution via improper path validation [fedora-42] [ 3 ] Bug #2417697 - CVE-2025-13699 mariadb11.8: MariaDB: mariadb-dump utility vulnerable to remote code execution via improper path validation [fedora-43]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f677c523ec' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
