[ALSA-2026:0136] Important: mariadb10.11 security update
Type:
security
Severity:
important
Release date:
2026-01-12
Description:
MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities. Security Fix(es): * mysql: High Privilege Denial of Service Vulnerability in MySQL Server (CVE-2025-21490) * mariadb: MariaDB Server Crash Due to Empty Backtrace Log (CVE-2023-52969) * mariadb: MariaDB Server Crash (CVE-2023-52971) * mariadb: MariaDB Server Crash via Item_direct_view_ref (CVE-2023-52970) * mysql: mysqldump unspecified vulnerability (CPU Apr 2025) (CVE-2025-30722) * mysql: InnoDB unspecified vulnerability (CPU Apr 2025) (CVE-2025-30693) * mariadb: MariaDB: mariadb-dump utility vulnerable to remote code execution via improper path validation (CVE-2025-13699) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch mariadb-common-10.11.15-1.el10_1.noarch.rpm 153fe9f1c23236efb58a1e7983dea6a0eb9aede1d0002cd78d5c211536e0389a
noarch mariadb-errmsg-10.11.15-1.el10_1.noarch.rpm d28b3121d08b7ce6d511e8704415c0874db79cb7efbf67eb85e565cec6a23c71
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.