Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

openSUSE Leap 16.0: mariadb Important Remote Exec CVE-2025-13699

opensuse
Calendar Grey December 23, 2025
Dist Opensuse Esm H88
Important security update for openSUSE mariadb resolves remote code execution risk while fixing additional bugs.
An update that solves one vulnerability and has 4 bug fixes can now be installed.

Description

This update for mariadb fixes the following issues:

- Update to 11.8.5:

* CVE-2025-13699: Fixed Directory Traversal Remote Code Execution

Vulnerability (bsc#1254313)

Other fixes:

- Add %license tags to license files (bsc#1252162)

- Add INSTALL_DOCREADMEDIR cmake flag to install readme and license files

- Remove client plugin parsec.so, it is shipped by libmariadb_plugins

(bsc#1243040, bsc#1254476)

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-116=1

Patch

Package List

- openSUSE Leap 16.0:

libmariadbd-devel-11.8.5-160000.1.1

libmariadbd19-11.8.5-160000.1.1

mariadb-11.8.5-160000.1.1

mariadb-bench-11.8.5-160000.1.1

mariadb-client-11.8.5-160000.1.1

mariadb-errormessages-11.8.5-160000.1.1

mariadb-galera-11.8.5-160000.1.1

mariadb-rpm-macros-11.8.5-160000.1.1

mariadb-test-11.8.5-160000.1.1

mariadb-tools-11.8.5-160000.1.1

References

* bsc#1243040

* bsc#1252162

* bsc#1254313

* bsc#1254476

References:

* https://www.suse.com/security/cve/CVE-2025-13699.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2025:20175-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here