CVE-2026-107821: MariaDB: insufficient validation of binary frm data when opening a table
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB insufficiently validated counts, offsets, lengths, and field boundaries in FRM metadata while opening binary FRM files. An attacker able to place a crafted FRM file in the data directory could trigger out-of-bounds reads or writes, crash the server, or potentially execute code. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MariaDBto a version that resolves this vulnerability.Fixed in 10.6.28 - Upgrade
Upgrade
MariaDBto a version that resolves this vulnerability.Fixed in 10.11.19 - Upgrade
Upgrade
MariaDBto a version that resolves this vulnerability.Fixed in 11.4.13 - Upgrade
Upgrade
MariaDBto a version that resolves this vulnerability.Fixed in 11.8.9 - Upgrade
Upgrade
MariaDBto a version that resolves this vulnerability.Fixed in 12.3.3 - Upgrade
Upgrade
MariaDBto a version that resolves this vulnerability.Fixed in 13.0.2
Event History
Frequently Asked Questions
Who is realistically able to exploit this issue?
An attacker must be able to place a crafted binary FRM file in the MariaDB data directory. This requires a high level of privileges or another path that permits writing attacker-controlled files into that directory.
What can exploitation do?
Opening the crafted FRM file can cause out-of-bounds reads or writes. The stated impacts include crashing the MariaDB server and potential code execution.
Which releases contain the fix?
The issue is fixed in MariaDB 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. Versions from 10.6.1 through the releases immediately before those fixes are affected.
How can I assess whether my server is exposed before patching?
Determine whether the server runs an affected version and review who or what can write into its MariaDB data directory. The vulnerability requires a crafted FRM file to be placed there, so unauthorized or untrusted write access to that directory is the relevant exposure condition.