Impact
MariaDB RPM packages created the mysql service account with the database data directory as its home directory. A database user who has the FILE privilege can write shell startup files such as .bash_profile into the account’s $HOME directory. When an administrator opens a login shell for the mysql account, these files are executed, allowing the attacker to run arbitrary code with the privileges of the mysql system user. The vulnerability therefore permits an attacker who can create or modify database files to execute code in the context of the mysql service account, potentially compromising database security and confidentiality.
Affected Systems
The issue affects MariaDB Server versions 10.6.1 through 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2 when installed via RPM packages on distributions that allow the mysql account to inherit the database data directory as $HOME. Debian packages are not affected because they assign /nonexistent as the account home. All affected releases are listed in the advisory and the vulnerability is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.4, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is a local attacker who already has a database user with FILE privileges; such a user can write to the mysql system account’s $HOME. Exploitation requires the attacker to control database files and to trigger a login shell for the mysql user, which is common for administrators. Given the high CVSS score and the fact that the flaw allows arbitrary code execution in a privileged account, the risk to impacted deployments is significant.
OpenCVE Enrichment