Out-of-Bounds Read and Write Vulnerability in MariaDB Server by MariaDB Corporation
CVE-2026-107821

8HIGH

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107821?

MariaDB Server versions from 10.6.1 to 13.0.2 exhibit a significant vulnerability due to insufficient validation of FRM metadata while handling binary FRM files. This oversight could allow an attacker, with access to a crafted FRM file, to manipulate the database, leading to potential out-of-bounds reads or writes that may crash the server or result in unauthorized code execution. Users are advised to upgrade to patched versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2 to mitigate this risk.

Affected Version(s)

server >= 10.6.1, < 10.6.28 < 10.6.1, 10.6.28

server >= 10.11.1, < 10.11.19 < 10.11.1, 10.11.19

server >= 11.4.1, < 11.4.13 < 11.4.1, 11.4.13

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.