This update for mariadb fixes the following issues:
- Update to 11.8.5:
* CVE-2025-13699: Fixed Directory Traversal Remote Code Execution
Vulnerability (bsc#1254313)
Other fixes:
- Add %license tags to license files (bsc#1252162)
- Add INSTALL_DOCREADMEDIR cmake flag to install readme and license files
- Remove client plugin parsec.so, it is shipped by libmariadb_plugins
(bsc#1243040, bsc#1254476)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-116=1
- openSUSE Leap 16.0:
libmariadbd-devel-11.8.5-160000.1.1
libmariadbd19-11.8.5-160000.1.1
mariadb-11.8.5-160000.1.1
mariadb-bench-11.8.5-160000.1.1
mariadb-client-11.8.5-160000.1.1
mariadb-errormessages-11.8.5-160000.1.1
mariadb-galera-11.8.5-160000.1.1
mariadb-rpm-macros-11.8.5-160000.1.1
mariadb-test-11.8.5-160000.1.1
mariadb-tools-11.8.5-160000.1.1
* bsc#1243040
* bsc#1252162
* bsc#1254313
* bsc#1254476
References:
* https://www.suse.com/security/cve/CVE-2025-13699.html
Get the latest Linux and open source security news straight to your inbox.