PT-2026-26661 · Mariadb · Server
Codeas
·
Published
2026-03-20
·
Updated
2026-03-20
·
CVE-2026-32710
CVSS v3.1
8.5
High
| AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON SCHEMA VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Server