Skip to content
Ubuntu 26.04 MariaDB Important Command Exec SQL Injection Fix 8536

Ubuntu 26.04 MariaDB Important Command Exec SQL Injection Fix 8536

Linuxsecurity •LinuxSecurity Advisories • July 14, 2026

Several security issues were fixed in MariaDB. Software Description: - mariadb: MariaDB database Details: It was discovered that MariaDB did not properly validate parameters supplied by a joiner node during a State Snapshot Transfer using the mariabackup method. An attacker could possibly use this issue to execute arbitrary shell commands on the donor node. (CVE-2026-44168) It was discovered that MariaDB did not properly enforce the SHOW CREATE ROUTINE privilege when a user obtained access to a stored routine via a role. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-44169) It was discovered that MariaDB's mbstream utility did not properly validate paths when unpacking archives. An attacker could possibly use this issue to write files outside of the intended target directory. (CVE-2026-44171) It was discovered that MariaDB's mysql_real_escape_string() function incorrectly handled the big5 character set. An attacker could possibl... Read the Full Advisory

Several security issues were fixed in MariaDB.

Software Description:

- mariadb: MariaDB database

It was discovered that MariaDB did not properly validate parameters

supplied by a joiner node during a State Snapshot Transfer using the

mariabackup method. An attacker could possibly use this issue to execute

arbitrary shell commands on the donor node. (CVE-2026-44168)

It was discovered that MariaDB did not properly enforce the SHOW CREATE

ROUTINE privilege when a user obtained access to a stored routine via a

role. An authenticated user could possibly use this issue to obtain

sensitive information. (CVE-2026-44169)

It was discovered that MariaDB's mbstream utility did not properly validate

paths when unpacking archives. An attacker could possibly use this issue to

write files outside of the intended target directory. (CVE-2026-44171)

It was discovered that MariaDB's mysql_real_escape_string() function

incorrectly handled the big5 character set. An attacker could possibl...

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS mariadb-server 1:11.8.6-5ubuntu0.1 In general, a standard system update will make all the necessary changes.

CVE-2026-44168, CVE-2026-44169, CVE-2026-44171, CVE-2026-44172,

CVE-2026-44173, CVE-2026-48163, CVE-2026-48165, CVE-2026-49261

Ubuntu Security Notice USN-8536-1

Get the latest Linux and open source security news straight to your inbox.