Alerts This Week
Warning Icon 1 449
Alerts This Week
Warning Icon 1 449

SUSE Linux 16.0 MariaDB Urgent Update Multiple Vulnerabilities 2026-22095-1

suse
Calendar Grey June 15, 2026
Dist Suse Esm H88
Critical SUSE security update for mariadb reveals 12 vulnerabilities, requiring immediate installation to ensure system safety.
An update that solves 12 vulnerabilities can now be installed.

Summary

## This update for mariadb fixes the following issues Update to 11.8.8: * CVE-2026-3494: audit plugin comment handling bypass (bsc#1259176). * CVE-2026-34303: mysql: optimizer unspecified vulnerability (bsc#1266435). * CVE-2026-35549: SHA2 auth plugin crash on large packets (bsc#1261413). * CVE-2026-44168: wsrep SST unsafe parameter handling on the donor side (bsc#1266442). * CVE-2026-44169: authorization bypass in role-based routine-level privilege check exposes stored routine definitions (bsc#1266441). * CVE-2026-44170: argument injection in CONNECT REST Xcurl on Windows via unsanitized URL (bsc#1266440). * CVE-2026-44171: path traversal in mbstream (bsc#1266439). * CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438).

References

* bsc#1259176

* bsc#1261413

* bsc#1266435

* bsc#1266437

* bsc#1266438

* bsc#1266439

* bsc#1266440

* bsc#1266441

* bsc#1266442

* bsc#1266814

* bsc#1266815

* bsc#1267542

Cross-

* CVE-2026-34303

* CVE-2026-3494

* CVE-2026-35549

* CVE-2026-44168

* CVE-2026-44169

* CVE-2026-44170

* CVE-2026-44171

* CVE-2026-44172

* CVE-2026-44173

* CVE-2026-48163

* CVE-2026-48165

* CVE-2026-49261

CVSS scores:

* CVE-2026-34303 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-3494 ( SUSE ): 5.3

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2026-3494 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

* CVE-2026-3494 ( NVD ): 5.3

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22095-1
Release Date: 2026-06-10T10:57:17Z
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here