Buffer Overflow in MariaDB Server's qc_info Plugin
CVE-2026-107816
6.4MEDIUM
What is CVE-2026-107816?
The MariaDB Server's qc_info plugin has a vulnerability that arises from incorrect handling of queries containing embedded null bytes. When such a query is processed and cached, accessing information_schema.query_cache_info can lead to unintended memory disclosure or server crashes due to reading data past the allocated buffer limits. This issue has been addressed in later versions, urging users to upgrade to maintain system integrity and security.
Affected Version(s)
server >= 10.6.1, < 10.6.28 < 10.6.1, 10.6.28
server >= 10.11.1, < 10.11.19 < 10.11.1, 10.11.19
server >= 11.4.1, < 11.4.13 < 11.4.1, 11.4.13
