Description:
CVE-2026-49261 MariaDB server has unsafe parameter handling in
`wsrep_notify_cmd`
CVE-2026-48165 MariaDB: unsafe usage of `wsrep_sst_receive_address`
values on the joiner side
CVE-2026-48163 MariaDB: wsrep SST unsafe parameter handling on the donor
side (rsync)
- https://bugs.mageia.org/show_bug.cgi?id=35644
- https://mariadb.org/mariadb-community-server-corrective-releases/
- https://www.cve.org/CVERecord?id=CVE-2026-49261
- https://www.cve.org/CVERecord?id=CVE-2026-48165
- https://www.cve.org/CVERecord?id=CVE-2026-48163
- 9/core/mariadb-11.4.12-1.1.mga9
Publication date:13 Jun 2026
Get the latest Linux and open source security news straight to your inbox.