Buffer Overflow in MariaDB Server's qc_info Plugin
CVE-2026-107816

6.4MEDIUM

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107816?

The MariaDB Server's qc_info plugin has a vulnerability that arises from incorrect handling of queries containing embedded null bytes. When such a query is processed and cached, accessing information_schema.query_cache_info can lead to unintended memory disclosure or server crashes due to reading data past the allocated buffer limits. This issue has been addressed in later versions, urging users to upgrade to maintain system integrity and security.

Affected Version(s)

server >= 10.6.1, < 10.6.28 < 10.6.1, 10.6.28

server >= 10.11.1, < 10.11.19 < 10.11.1, 10.11.19

server >= 11.4.1, < 11.4.13 < 11.4.1, 11.4.13

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.