Explore top 10 tips to secure your open-source projects now. Read More
×MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This may be related to make_aggr_tables_info and optimize_stage2 - CVE-2023-52969. MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through . MGASA-2025-0186 - Updated mariadb packages fix security vulnerabilities Publication date: 11 Jun 2025 URL: https://advisories.mageia.org/MGASA-2025-0186.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-52969, CVE-2023-52970, CVE-2023-52971, CVE-2025-30693, CVE-2025-30722 MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This may be related to make_aggr_tables_info and optimize_stage2 - CVE-2023-52969. MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where - CVE-2023-52970. MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan - CVE-2023-52971. Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H) - CVE-2025-30693. Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Client accessible data as well as unauthorized update, insert or delete access to some of MySQL Client accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N) - CVE-2025-30722 References: - https://bugs.mageia.org/show_bug.cgi?id=34342 - https://mariadb.com/docs/release-notes/community-server/11.4/11.4.7 - https://mariadb.com/docs/release-notes/community-server/11.4/11.4.6 - https://ubuntu.com/security/notices/USN-7548-1 - https://www.cve.org/CVERecord?id=CVE-2023-52969 - https://www.cve.org/CVERecord?id=CVE-2023-52970 - https://www.cve.org/CVERecord?id=CVE-2023-52971 - https://www.cve.org/CVERecord?id=CVE-2025-30693 - https://www.cve.org/CVERecord?id=CVE-2025-30722 SRPMS: - 9/core/mariadb-11.4.7-1.mga9 . The recent MariaDB enhancements within Mageia tackle a range of security flaws, bolstering system robustness and protecting data accuracy for its community.. MariaDB Security, Mageia Update, DOS Prevention, Crash Protection. . LinuxSecurity.com Team
Vulnerabilities was discovered in MariaDB, a SQL database server compatible with MySQL. CVE-2025-30693 . From: Otto Kekäläinen To:
An update that solves one vulnerability can now be installed.. # Security update for mariadb Announcement ID: SUSE-SU-2025:01716-1 Release Date: 2025-05-27T12:44:15Z Rating: moderate References: * bsc#1243356 Cross-References: * CVE-2025-21490 CVSS scores: * CVE-2025-21490 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-21490 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2025-21490 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H Affected Products: * Galera for Ericsson 15 SP6 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for mariadb fixes the following issues: Update to version 10.11.11. * CVE-2025-21490: vulnerability allows high privileged attacker with network access to cause hangs and frequent crashes on affected servers (bsc#1243356). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1716=1 openSUSE-SLE-15.6-2025-1716=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1716=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2025-1716=1 * Galera for Ericsson 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-ERICSSON-2025-1716=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * mariadb-rpm-macros-10.11.11-150600.4.10.1 * libmariadbd19-debuginfo-10.11.11-150600.4.10.1 *mariadb-debugsource-10.11.11-150600.4.10.1 * mariadb-galera-10.11.11-150600.4.10.1 * mariadb-client-debuginfo-10.11.11-150600.4.10.1 * mariadb-test-10.11.11-150600.4.10.1 * mariadb-client-10.11.11-150600.4.10.1 * mariadb-debuginfo-10.11.11-150600.4.10.1 * mariadb-10.11.11-150600.4.10.1 * mariadb-bench-debuginfo-10.11.11-150600.4.10.1 * mariadb-test-debuginfo-10.11.11-150600.4.10.1 * libmariadbd19-10.11.11-150600.4.10.1 * libmariadbd-devel-10.11.11-150600.4.10.1 * mariadb-tools-10.11.11-150600.4.10.1 * mariadb-bench-10.11.11-150600.4.10.1 * mariadb-tools-debuginfo-10.11.11-150600.4.10.1 * openSUSE Leap 15.6 (noarch) * mariadb-errormessages-10.11.11-150600.4.10.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * mariadb-debuginfo-10.11.11-150600.4.10.1 * mariadb-debugsource-10.11.11-150600.4.10.1 * mariadb-galera-10.11.11-150600.4.10.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libmariadbd19-debuginfo-10.11.11-150600.4.10.1 * mariadb-debugsource-10.11.11-150600.4.10.1 * mariadb-client-debuginfo-10.11.11-150600.4.10.1 * mariadb-client-10.11.11-150600.4.10.1 * mariadb-debuginfo-10.11.11-150600.4.10.1 * mariadb-10.11.11-150600.4.10.1 * libmariadbd19-10.11.11-150600.4.10.1 * mariadb-tools-10.11.11-150600.4.10.1 * libmariadbd-devel-10.11.11-150600.4.10.1 * mariadb-tools-debuginfo-10.11.11-150600.4.10.1 * Server Applications Module 15-SP6 (noarch) * mariadb-errormessages-10.11.11-150600.4.10.1 * Galera for Ericsson 15 SP6 (x86_64) * mariadb-debuginfo-10.11.11-150600.4.10.1 * mariadb-debugsource-10.11.11-150600.4.10.1 * mariadb-galera-10.11.11-150600.4.10.1 ## References: * https://www.suse.com/security/cve/CVE-2025-21490.html * https://bugzilla.suse.com/show_bug.cgi?id=1243356 . The latest mariadb update resolves a significant vulnerability in openSUSE, bolstering both security and system reliability with the newly released patch.. openSUSESecurity Update, MariaDB Patch, Network Vulnerability Fix. . LinuxSecurity.com Team
* bsc#1243356 Cross-References: * CVE-2025-21490 . # Security update for mariadb Announcement ID: SUSE-SU-2025:01716-1 Release Date: 2025-05-27T12:44:15Z Rating: moderate References: * bsc#1243356 Cross-References: * CVE-2025-21490 CVSS scores: * CVE-2025-21490 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-21490 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2025-21490 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H Affected Products: * Galera for Ericsson 15 SP6 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for mariadb fixes the following issues: Update to version 10.11.11. * CVE-2025-21490: vulnerability allows high privileged attacker with network access to cause hangs and frequent crashes on affected servers (bsc#1243356). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1716=1 openSUSE-SLE-15.6-2025-1716=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1716=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2025-1716=1 * Galera for Ericsson 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-ERICSSON-2025-1716=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * mariadb-rpm-macros-10.11.11-150600.4.10.1 * libmariadbd19-debuginfo-10.11.11-150600.4.10.1 *mariadb-debugsource-10.11.11-150600.4.10.1 * mariadb-galera-10.11.11-150600.4.10.1 * mariadb-client-debuginfo-10.11.11-150600.4.10.1 * mariadb-test-10.11.11-150600.4.10.1 * mariadb-client-10.11.11-150600.4.10.1 * mariadb-debuginfo-10.11.11-150600.4.10.1 * mariadb-10.11.11-150600.4.10.1 * mariadb-bench-debuginfo-10.11.11-150600.4.10.1 * mariadb-test-debuginfo-10.11.11-150600.4.10.1 * libmariadbd19-10.11.11-150600.4.10.1 * libmariadbd-devel-10.11.11-150600.4.10.1 * mariadb-tools-10.11.11-150600.4.10.1 * mariadb-bench-10.11.11-150600.4.10.1 * mariadb-tools-debuginfo-10.11.11-150600.4.10.1 * openSUSE Leap 15.6 (noarch) * mariadb-errormessages-10.11.11-150600.4.10.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * mariadb-debuginfo-10.11.11-150600.4.10.1 * mariadb-debugsource-10.11.11-150600.4.10.1 * mariadb-galera-10.11.11-150600.4.10.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libmariadbd19-debuginfo-10.11.11-150600.4.10.1 * mariadb-debugsource-10.11.11-150600.4.10.1 * mariadb-client-debuginfo-10.11.11-150600.4.10.1 * mariadb-client-10.11.11-150600.4.10.1 * mariadb-debuginfo-10.11.11-150600.4.10.1 * mariadb-10.11.11-150600.4.10.1 * libmariadbd19-10.11.11-150600.4.10.1 * mariadb-tools-10.11.11-150600.4.10.1 * libmariadbd-devel-10.11.11-150600.4.10.1 * mariadb-tools-debuginfo-10.11.11-150600.4.10.1 * Server Applications Module 15-SP6 (noarch) * mariadb-errormessages-10.11.11-150600.4.10.1 * Galera for Ericsson 15 SP6 (x86_64) * mariadb-debuginfo-10.11.11-150600.4.10.1 * mariadb-debugsource-10.11.11-150600.4.10.1 * mariadb-galera-10.11.11-150600.4.10.1 ## References: * https://www.suse.com/security/cve/CVE-2025-21490.html * https://bugzilla.suse.com/show_bug.cgi?id=1243356 . Security update for mariadb released by SUSE addresses a network attack threat with a moderate severity rating.. mariadb security, SUSE update, network attack fix,server protection. . LinuxSecurity.com Team
Several security issues were fixed in MariaDB.. ========================================================================== Ubuntu Security Notice USN-7519-1 May 20, 2025 mariadb-10.6 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in MariaDB. Software Description: - mariadb-10.6: MariaDB database Details: Several security issues were discovered in MariaDB and this update includes a new upstream MariaDB version to fix these issues. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS mariadb-server 1:10.6.22-0ubuntu0.22.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart MariaDB to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7519-1 CVE-2023-52969, CVE-2023-52970, CVE-2025-30693, CVE-2025-30722 Package Information: https://launchpad.net/ubuntu/+source/mariadb-10.6/1:10.6.22-0ubuntu0.22.04.1 . A series of vulnerabilities addressed with the latest MariaDB update on Ubuntu 22.04 LTS, enhancing both performance and protection.. MariaDB Update, Ubuntu Security Notice, Database Fix, MariaDB Vulnerability, System Security Upgrade. . Severity: Important. LinuxSecurity.com Team
New mariadb packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] mariadb (SSA:2025-127-01) New mariadb packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/mariadb-10.5.29-i586-1_slack15.0.txz: Upgraded. This update fixes bugs and several security issues. For more information, see: https://www.cve.org/CVERecord?id=CVE-2025-30722 https://www.cve.org/CVERecord?id=CVE-2025-30693 https://www.cve.org/CVERecord?id=CVE-2023-52970 https://www.cve.org/CVERecord?id=CVE-2023-52969 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mariadb-10.5.29-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/mariadb-10.5.29-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/ap/mariadb-11.4.6-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ap/mariadb-11.4.6-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: 3ac0ae5edb7063ca8feedb0ecdb0a88d mariadb-10.5.29-i586-1_slack15.0.txz Slackware x86_64 15.0 package: e535f783af1749341ed222a10522af4b mariadb-10.5.29-x86_64-1_slack15.0.txz Slackware -current package: 6792ba5ff1c117ee4970db1eb4ed088a ap/mariadb-11.4.6-i686-1.txz Slackware x86_64 -currentpackage: 54eaf8733363566bf8de5b24e4ec9db3 ap/mariadb-11.4.6-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg mariadb-10.5.29-i586-1_slack15.0.txz Then, restart the database server: # sh /etc/rc.d/rc.mysqld restart +-----+ . Latest PostgreSQL distributions for Slackware address significant vulnerabilities. Keep your environment protected by applying the most recent patches.. mariadb packages, Slackware update, security fixes, database security. . Severity: Critical. LinuxSecurity.com Team
A security issue was fixed in MariaDB.. ========================================================================== Ubuntu Security Notice USN-7376-2 March 31, 2025 mariadb vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: A security issue was fixed in MariaDB. Software Description: - mariadb: MariaDB database - mariadb-10.6: MariaDB database Details: USN-7376-1 fixed vulnerabilities in MariaDB. This update provides the corresponding updates for Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. Original advisory details: A security issue was discovered in MariaDB and this update includes a new upstream MariaDB version to fix the issue. In addition to security fixes, the updated packages contain bug and regression fixes, new features, and possibly incompatible changes. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS mariadb-server 1:10.11.11-0ubuntu0.24.04.2 Ubuntu 22.04 LTS mariadb-server 1:10.6.21-0ubuntu0.22.04.2 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart MariaDB to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7376-2 https://ubuntu.com/security/notices/USN-7376-1 CVE-2025-21490 Package Information: https://launchpad.net/ubuntu/+source/mariadb/1:10.11.11-0ubuntu0.24.04.2 https://launchpad.net/ubuntu/+source/mariadb-10.6/1:10.6.21-0ubuntu0.22.04.2 . A security issue in MariaDB was addressed with updates for Ubuntu 22.04 LTS and 24.04 LTS in security advisory USN-7376-2.. security, mariadb, =============================================================. . Severity: Important. LinuxSecurity.com Team
A security issue was fixed in MariaDB.. ========================================================================== Ubuntu Security Notice USN-7376-1 March 27, 2025 mariadb vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 Summary: A security issue was fixed in MariaDB. Software Description: - mariadb: MariaDB database Details: A security issue was discovered in MariaDB and this update includes a new upstream MariaDB version to fix the issue. In addition to security fixes, the updated packages contain bug and regression fixes, new features, and possibly incompatible changes. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 mariadb-server 1:11.4.5-0ubuntu0.24.10.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart MariaDB to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7376-1 CVE-2025-21490 Package Information: https://launchpad.net/ubuntu/+source/mariadb/1:11.4.5-0ubuntu0.24.10.1 . Ubuntu's latest advisory updates resolve critical MariaDB security issue. Essential for risk mitigation and system integrity.. security, mariadb, =============================================================. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.