Impact
The vulnerability arises from insufficient validation of counts, offsets, lengths, and field boundaries in FRM metadata files when a table is opened. An attacker who can place a crafted FRM file in the MySQL data directory may trigger out-of-bounds reads or writes. This can cause the server to crash or, in worst‑case scenarios, allow the attacker to execute arbitrary code. The weakness aligns with CWE‑1285.
Affected Systems
MariaDB server versions 10.6.1 through 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2 are affected. Affected product is MariaDB:server; updates starting with 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2 contain the fix.
Risk and Exploitability
This issue carries a CVSS score of 8, indicating high severity. EPSS is not available, so current exploitation probability cannot be quantified, but the lack of KEV listing suggests no active public exploits yet. The likely attack vector requires an attacker to write a malicious FRM file to the database’s data directory—typically possible only with file‑system access or through a separate vulnerability that allows such writes. Once the server loads the bad FRM, it may read or write outside designated bounds, leading to denial of service or potentially remote code execution if an out‑of‑bounds write overwrites executable memory.
OpenCVE Enrichment