Back Linuxsecurity Ubuntu 26.04 MariaDB Important Command Exec SQL Injection Fix 8536
Several security issues were fixed in MariaDB. Software Description: - mariadb: MariaDB database Details: It was discovered that MariaDB did not properly validate parameters supplied by a joiner node during a State Snapshot Transfer using the mariabackup method. An attacker could possibly use this issue to execute arbitrary shell commands on the donor node. (CVE-2026-44168) It was discovered that MariaDB did not properly enforce the SHOW CREATE ROUTINE privilege when a user obtained access to a stored routine via a role. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-44169) It was discovered that MariaDB's mbstream utility did not properly validate paths when unpacking archives. An attacker could possibly use this issue to write files outside of the intended target directory. (CVE-2026-44171) It was discovered that MariaDB's mysql_real_escape_string() function incorrectly handled the big5 character set. An attacker could possibl... Read the Full Advisory
Several security issues were fixed in MariaDB.
Software Description:
- mariadb: MariaDB database
It was discovered that MariaDB did not properly validate parameters
supplied by a joiner node during a State Snapshot Transfer using the
mariabackup method. An attacker could possibly use this issue to execute
arbitrary shell commands on the donor node. (CVE-2026-44168)
It was discovered that MariaDB did not properly enforce the SHOW CREATE
ROUTINE privilege when a user obtained access to a stored routine via a
role. An authenticated user could possibly use this issue to obtain
sensitive information. (CVE-2026-44169)
It was discovered that MariaDB's mbstream utility did not properly validate
paths when unpacking archives. An attacker could possibly use this issue to
write files outside of the intended target directory. (CVE-2026-44171)
It was discovered that MariaDB's mysql_real_escape_string() function
incorrectly handled the big5 character set. An attacker could possibl...
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS mariadb-server 1:11.8.6-5ubuntu0.1 In general, a standard system update will make all the necessary changes.
CVE-2026-44168, CVE-2026-44169, CVE-2026-44171, CVE-2026-44172,
CVE-2026-44173, CVE-2026-48163, CVE-2026-48165, CVE-2026-49261
Ubuntu Security Notice USN-8536-1
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
