Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mariadb
Mariadb server |
|
| Vendors & Products |
Mariadb
Mariadb server |
Fri, 09 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the CONNECT engine's DOS table type used an incorrect boundary check that permitted a one-byte null write beyond a stack buffer at an attacker-controlled offset. An authenticated user able to use the CONNECT engine could cause a crash and potentially remote code execution. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. | |
| Title | MariaDB: one byte OOB write in DOS tables of the CONNECT engine | |
| Weaknesses | CWE-787 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T16:05:49.046Z
Reserved: 2026-10-08T21:23:59.822Z
Link: CVE-2026-107815
No data.
Status : Awaiting Analysis
Published: 2026-10-09T17:16:45.970
Modified: 2026-10-09T17:41:29.727
Link: CVE-2026-107815
No data.
OpenCVE Enrichment
Updated: 2026-10-09T17:30:08Z
-
CWE-787
Out-of-bounds Write