RHSA-2026:49522: Important: mariadb10.11 security update
MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities.Security Fix(es): mariadb: MariaDB Server: Arbitrary code execution via wsrepnotifycmd (CVE-2026-49261) mariadb: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer (CVE-2026-44168) mariadb: Arbitrary shell command execution via improper sanitization in CONNECT engine (CVE-2026-44170) mariadb: mbstream: Unauthorized file creation via path traversal (CVE-2026-44171) mariadb: Arbitrary code execution via improper parameter validation during SST (CVE-2026-48163) mariadb: Arbitrary code execution via global system variable manipulation by a high-privileged user (CVE-2026-48165) mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries (CVE-2026-44173) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/mariadb10.11to a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-backupto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-backup-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-client-utilsto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-commonto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-develto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-embeddedto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-embedded-develto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-errmsgto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-gssapi-serverto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-gssapi-server-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-oqgraph-engineto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-oqgraph-engine-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-pamto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-pam-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-serverto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-server-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-server-galerato a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-server-utilsto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-server-utils-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-testto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb-test-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb10.11-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadb10.11-debugsourceto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0 - Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-backupto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-backup-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-client-utilsto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-develto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-embeddedto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-embedded-develto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-gssapi-serverto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-gssapi-server-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-oqgraph-engineto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-oqgraph-engine-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-pamto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-pam-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-serverto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-server-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-server-galerato a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-server-utilsto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-server-utils-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-testto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb-test-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb10.11-debuginfoto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
redhat/mariadb10.11-debugsourceto a version that resolves this vulnerability.Fixed in 10.11.18-1.el10_0.aa - Upgrade
Upgrade
mariadbto a version that resolves this vulnerability.Fixed in mariadb10.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-44168 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-48165 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-48163 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-44170 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-44173 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-44171 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-49261
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49522?
The severity of RHSA-2026:49522 is rated at 77, indicating a significant risk.
How do I fix RHSA-2026:49522?
To fix RHSA-2026:49522, install the latest MariaDB security update provided in the official repository.
What vulnerabilities are addressed in RHSA-2026:49522?
RHSA-2026:49522 addresses a path traversal vulnerability in the MariaDB server.
Which software packages are affected by RHSA-2026:49522?
The affected software packages include redhat/mariadb, redhat/mariadb-backup, redhat/mariadb-client-utils, and several others.
When was RHSA-2026:49522 published?
RHSA-2026:49522 was published on August 3, 2026.