Description
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB insufficiently validated counts, offsets, lengths, and field boundaries in FRM metadata while opening binary FRM files. An attacker able to place a crafted FRM file in the data directory could trigger out-of-bounds reads or writes, crash the server, or potentially execute code. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.
Published: 2026-10-09
Score: 8 High
EPSS: n/a
KEV: No
Impact: Potential Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from insufficient validation of counts, offsets, lengths, and field boundaries in FRM metadata files when a table is opened. An attacker who can place a crafted FRM file in the MySQL data directory may trigger out-of-bounds reads or writes. This can cause the server to crash or, in worst‑case scenarios, allow the attacker to execute arbitrary code. The weakness aligns with CWE‑1285.

Affected Systems

MariaDB server versions 10.6.1 through 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2 are affected. Affected product is MariaDB:server; updates starting with 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2 contain the fix.

Risk and Exploitability

This issue carries a CVSS score of 8, indicating high severity. EPSS is not available, so current exploitation probability cannot be quantified, but the lack of KEV listing suggests no active public exploits yet. The likely attack vector requires an attacker to write a malicious FRM file to the database’s data directory—typically possible only with file‑system access or through a separate vulnerability that allows such writes. Once the server loads the bad FRM, it may read or write outside designated bounds, leading to denial of service or potentially remote code execution if an out‑of‑bounds write overwrites executable memory.

Generated by OpenCVE AI on October 9, 2026 at 18:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MariaDB to a patched version: for affected releases, upgrade to 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, or 13.0.2 or later.
  • If immediate upgrade is not possible, ensure that the database data directory is writable only by the dedicated MariaDB user and has no world‑write permissions; restrict access so that untrusted users cannot create or modify FRM files.
  • Monitor the data directory for unexpected file changes and review MySQL logs for repeated crashes or abnormal behavior that may indicate an exploited FRM file.

Generated by OpenCVE AI on October 9, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB insufficiently validated counts, offsets, lengths, and field boundaries in FRM metadata while opening binary FRM files. An attacker able to place a crafted FRM file in the data directory could trigger out-of-bounds reads or writes, crash the server, or potentially execute code. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.
Title MariaDB: insufficient validation of binary frm data when opening a table
Weaknesses CWE-1285
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T17:42:29.482Z

Reserved: 2026-10-08T21:23:59.823Z

Link: CVE-2026-107821

cve-icon Vulnrichment

Updated: 2026-10-09T17:42:14.921Z

cve-icon NVD

Status : Received

Published: 2026-10-09T18:17:03.860

Modified: 2026-10-09T18:17:03.860

Link: CVE-2026-107821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T18:30:11Z

Weaknesses
  • CWE-1285

    Improper Validation of Specified Index, Position, or Offset in Input