PatchSiren cyber security CVE debrief
CVE-2026-107816 MariaDB CVE debrief
The MariaDB server's `qc_info` plugin can be confused by a query containing embedded null bytes, potentially disclosing adjacent memory or crashing the server. This issue affects versions from 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. The vulnerability is due to improper handling of queries with embedded null bytes, which can lead to out-of-bounds reads. Defenders should prioritize verifying and upgrading to fixed versions to prevent potential information disclosure or server crashes.
- Vendor
- MariaDB
- Product
- server
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for MariaDB server deployments, particularly those using affected versions, should assess exposure and prioritize verification and upgrades to fixed versions.
Why it matters
Defenders should prioritize verifying and upgrading to fixed versions, as this issue can lead to potential information disclosure or server crashes in MariaDB server deployments.
- Potential information disclosure due to out-of-bounds reads.
- Potential server crashes due to out-of-bounds reads.
- Verification of affected versions and upgrades to fixed versions is necessary.
- Monitoring database queries for potential anomalies is recommended.
Technical summary
The `qc_info` plugin in MariaDB server can be confused by a query containing embedded null bytes, potentially disclosing adjacent memory or crashing the server. This issue affects versions from 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. The vulnerability is due to improper handling of queries with embedded null bytes, which can lead to out-of-bounds reads. Defenders should prioritize verifying and upgrading to fixed versions to prevent potential information disclosure or server crashes. The vulnerability can be mitigated by reviewing and monitoring database queries for potential anomalies and implementing compensating controls.
Defensive priority
Defenders should prioritize verifying and upgrading to fixed versions, as this issue can lead to potential information disclosure or server crashes.
Recommended defensive actions
- Verify and upgrade to fixed versions (10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2) to prevent potential information disclosure or server crashes.
- Review and monitor database queries for potential anomalies.
- Implement compensating controls, such as query logging and monitoring, to detect potential exploitation attempts.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is no information on known exploitation or victims. The vulnerability is confirmed to exist in the specified versions, and defenders should verify the presence of affected versions in their deployments. The CVE Program record and NVD detail page provide additional context on the vulnerability. There are no known reports of exploitation, but defenders should still prioritize verification and upgrades.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107816 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107816
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107816 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107816
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
MariaDB: `qc_info` plugin can do OOB reads if query contains \0
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107816.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/security/advisories/GHSA-wfqg-88r5-55f6
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/commit/0931994096b84ecc9ffc8eb3517c7e09e6e8631e
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-11.4.13
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-11.8.9
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/MariaDB/server/releases/tag/mariadb-12.3.3
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.