PT-2026-29985 · Mariadb · Mariadb Server

·

CVE-2026-35549

·

Published

2026-04-03

·

Updated

2026-06-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MariaDB Server versions prior to 11.4.10 MariaDB Server versions 11.5.0 through 11.8.5 MariaDB Server versions prior to 12.2.2
Description MariaDB Server is susceptible to a crash when using the caching sha2 password authentication plugin with certain user accounts. This occurs because the sha256 crypt r function utilizes alloca, and a large packet can trigger a server crash.
Recommendations Update MariaDB Server to version 11.4.10 or later. Update MariaDB Server to version 11.8.6 or later. Update MariaDB Server to version 12.2.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MARIADB-2026-35549
BIT-MARIADB-MIN-2026-35549
BIT-MYSQL-CLIENT-2026-35549
CVE-2026-35549
OPENSUSE-SU-2026:10897-1
OPENSUSE-SU-2026:20933-1
SUSE-SU-2026:22095-1
SUSE-SU-2026:2330-1

Affected Products

Mariadb Server