critical
Security update for mariadb
SUSE-SLE-Module-Server-Applications-15-SP7-2026-2330
This update for mariadb fixes the following issues: - CVE-2026-3494: audit plugin comment handling bypass (bsc#1259176). - CVE-2026-34303: mysql: optimizer unspecified vulnerability (bsc#1266435). - CVE-2026-35549: SHA2 auth plugin crash on large packets (bsc#1261413). - CVE-2026-44168: wsrep SST unsafe parameter handling on the donor side (bsc#1266442). - CVE-2026-44169: authorization bypass in role-based routine-level privilege check exposes stored routine definitions (bsc#1266441). - CVE-2026-44170: argument injection in CONNECT REST Xcurl on Windows via unsanitized URL (bsc#1266440). - CVE-2026-44171: path traversal in mbstream (bsc#1266439). - CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438). - CVE-2026-44173: FILE privilege was not checked for subqueries in the FROM clause (bsc#1266437). - CVE-2026-48163: wsrep SST unsafe parameter handling on the donor side (bsc#1266815). - CVE-2026-48165: unsafe usage of `wsrep_sst_receive_address` values on the joiner side (bsc#1266814). - CVE-2026-49261: unsafe parameter handling in `wsrep_notify_cmd` (bsc#1267542). Changes for mariadb: - Update to 11.8.8: https://mariadb.com/docs/release-notes/community-server/11.8/11.8.8 https://mariadb.com/docs/release-notes/community-server/changelogs/11.8/11.8.8 - Update to 11.8.7: https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7 https://mariadb.com/docs/release-notes/community-server/changelogs/11.8/11.8.7
-
Release DateJun 10 2026
-
ReferencesBugzilla: 1259176, 1261413, 1266435, 1266437, 1266438, 1266439, 1266440, 1266441, 1266442, 1266814, 1266815, 1267542
CVEs: CVE-2026-3494, CVE-2026-34303, CVE-2026-35549, CVE-2026-44168, CVE-2026-44169, CVE-2026-44170, CVE-2026-44171, CVE-2026-44172, CVE-2026-44173, CVE-2026-48163, CVE-2026-48165, CVE-2026-49261 -
Typesecurity
-
Severitycritical
cloud_download Downloads
Server Applications Module 15.7 aarch64
-
Packageslibmariadbd-devel
MariaDB embedded server development fileslibmariadbd1911.8.8-150700.3.15.1 lock rpm
MariaDB embedded server librarymariadb11.8.8-150700.3.15.1 lock rpm
Server part of MariaDBmariadb-client11.8.8-150700.3.15.1 lock rpm lock src
Client for MariaDBmariadb-errormessages11.8.8-150700.3.15.1 lock rpm
The error messages files required by server, client and libmariadbdmariadb-tools11.8.8-150700.3.15.1 lock rpm
MariaDB tools11.8.8-150700.3.15.1 lock rpm
Server Applications Module 15.7 ppc64le
-
Packageslibmariadbd-devel
MariaDB embedded server development fileslibmariadbd1911.8.8-150700.3.15.1 lock rpm
MariaDB embedded server librarymariadb11.8.8-150700.3.15.1 lock rpm
Server part of MariaDBmariadb-client11.8.8-150700.3.15.1 lock rpm lock src
Client for MariaDBmariadb-errormessages11.8.8-150700.3.15.1 lock rpm
The error messages files required by server, client and libmariadbdmariadb-tools11.8.8-150700.3.15.1 lock rpm
MariaDB tools11.8.8-150700.3.15.1 lock rpm
Server Applications Module 15.7 s390x
-
Packageslibmariadbd-devel
MariaDB embedded server development fileslibmariadbd1911.8.8-150700.3.15.1 lock rpm
MariaDB embedded server librarymariadb11.8.8-150700.3.15.1 lock rpm
Server part of MariaDBmariadb-client11.8.8-150700.3.15.1 lock rpm lock src
Client for MariaDBmariadb-errormessages11.8.8-150700.3.15.1 lock rpm
The error messages files required by server, client and libmariadbdmariadb-tools11.8.8-150700.3.15.1 lock rpm
MariaDB tools11.8.8-150700.3.15.1 lock rpm
Server Applications Module 15.7 x86_64
-
Packageslibmariadbd-devel
MariaDB embedded server development fileslibmariadbd1911.8.8-150700.3.15.1 lock rpm
MariaDB embedded server librarymariadb11.8.8-150700.3.15.1 lock rpm
Server part of MariaDBmariadb-client11.8.8-150700.3.15.1 lock rpm lock src
Client for MariaDBmariadb-errormessages11.8.8-150700.3.15.1 lock rpm
The error messages files required by server, client and libmariadbdmariadb-tools11.8.8-150700.3.15.1 lock rpm
MariaDB tools11.8.8-150700.3.15.1 lock rpm