Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: mariadb

Found 1 matching suggestions

View:
Compact
Detailed
Published
Permalink CVE-2026-35549
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
updated 1 day, 18 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package libmysqlclient
  • @LeSuisse removed package mariadb-galera
  • @LeSuisse removed package mariadb-embedded
  • @LeSuisse removed package libmysqlclient_3_1
  • @LeSuisse removed package libmysqlclient_3_2
  • @LeSuisse removed package libmysqlclient_3_3
  • @LeSuisse removed package mariadb-connector-c
  • @LeSuisse removed package ocamlPackages.mariadb
  • @LeSuisse removed package mariadb-connector-java
  • @LeSuisse removed package mariadb-connector-c_3_1
  • @LeSuisse removed package mariadb-connector-c_3_2
  • @LeSuisse removed package mariadb-connector-c_3_3
  • @LeSuisse removed package perlPackages.DBDMariaDB
  • @LeSuisse removed package unixODBCDrivers.mariadb
  • @LeSuisse removed package unixodbcDrivers.mariadb
  • @LeSuisse removed package perl5Packages.DBDMariaDB
  • @LeSuisse removed package python312Packages.mariadb
  • @LeSuisse removed package python313Packages.mariadb
  • @LeSuisse removed package python314Packages.mariadb
  • @LeSuisse removed package perl538Packages.DBDMariaDB
  • @LeSuisse removed package perl540Packages.DBDMariaDB
  • @LeSuisse removed package ocamlPackages_latest.mariadb
  • @LeSuisse removed package ocamlPackages.caqti-driver-mariadb
  • @LeSuisse removed package ocamlPackages_latest.caqti-driver-mariadb
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x …

An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.

Affected products

MariaDB
  • <12.2.2
  • <11.4.10
  • <11.8.6

Matching in nixpkgs

Ignored packages (24)

pkgs.libmysqlclient

Client library that can be used to connect to MySQL or MariaDB

pkgs.mariadb-connector-java

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases

Package maintainers