Redpacketsecurity Remote Code Execution Vulnerabilities Disclosed in MariaDB
Article Content
- •Two RCE vulnerabilities reported in MariaDB could be exploited by low-privilege users.
- •The vulnerabilities involve use-after-free and heap over-read conditions.
- •No patches or confirmed exploitation have been reported yet.
Two separate reports submitted to HackerOne detail vulnerabilities in MariaDB that could lead to remote code execution (RCE). The first report, submitted by Rick de Jager, describes a low-privilege RCE vulnerability involving an use-after-free condition in SYS_REFCURSOR and a heap over-read related to ST_Area. The second report, by Akhil Koul, highlights a heap use-after-free vulnerability in Materialized_cursor::open due to SYS_REFCURSOR array reallocation. Both vulnerabilities rely on memory safety issues and could potentially allow attackers with low-level privileges to execute arbitrary code on the database server. The reports lack detailed technical information, including proof of concept and affected versions. As of now, there is no confirmation of exploitation in the wild, and the vulnerabilities remain.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What are the main vulnerabilities reported?
Is there any patch available for these vulnerabilities?
Are these vulnerabilities being actively exploited?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…