Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

openSUSE MariaDB Critical Issues Addressed Advisory 2026-2282-1

suse
Calendar Grey June 5, 2026
Dist Suse Esm H88
Critical security update for MariaDB addresses nine vulnerabilities, enhancing SUSE Linux Enterprise and openSUSE security.
An update that solves nine vulnerabilities can now be installed.

Summary

## This update for mariadb fixes the following issues: Security fixes: * CVE-2026-3494: audit plugin comment handling bypass (bsc#1259176). * CVE-2026-44168: wsrep SST unsafe parameter handling on the donor side (bsc#1266442). * CVE-2026-44170: argument injection in CONNECT REST Xcurl on Windows via unsanitized URL (bsc#1266440). * CVE-2026-44171: path traversal in mbstream (bsc#1266439). * CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438). * CVE-2026-44173: FILE privilege was not checked for subqueries in the FROM clause (bsc#1266437). * CVE-2026-48163: wsrep SST unsafe parameter handling on the donor side (bsc#1266815). * CVE-2026-48165: unsafe usage of `wsrep_sst_receive_address` values on the joiner side (bsc#1266814).

References

* bsc#1259176

* bsc#1266437

* bsc#1266438

* bsc#1266439

* bsc#1266440

* bsc#1266442

* bsc#1266814

* bsc#1266815

* bsc#1267542

Cross-

* CVE-2026-3494

* CVE-2026-44168

* CVE-2026-44170

* CVE-2026-44171

* CVE-2026-44172

* CVE-2026-44173

* CVE-2026-48163

* CVE-2026-48165

* CVE-2026-49261

CVSS scores:

* CVE-2026-3494 ( SUSE ): 5.3

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2026-3494 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

* CVE-2026-3494 ( NVD ): 5.3

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2026-3494 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2282-1
Release Date: 2026-06-05T12:14:38Z
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here