PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107816 MariaDB CVE debrief

The MariaDB server's `qc_info` plugin can be confused by a query containing embedded null bytes, potentially disclosing adjacent memory or crashing the server. This issue affects versions from 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. The vulnerability is due to improper handling of queries with embedded null bytes, which can lead to out-of-bounds reads. Defenders should prioritize verifying and upgrading to fixed versions to prevent potential information disclosure or server crashes.

Vendor
MariaDB
Product
server
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Defenders responsible for MariaDB server deployments, particularly those using affected versions, should assess exposure and prioritize verification and upgrades to fixed versions.

Why it matters

Defenders should prioritize verifying and upgrading to fixed versions, as this issue can lead to potential information disclosure or server crashes in MariaDB server deployments.

  • Potential information disclosure due to out-of-bounds reads.
  • Potential server crashes due to out-of-bounds reads.
  • Verification of affected versions and upgrades to fixed versions is necessary.
  • Monitoring database queries for potential anomalies is recommended.

Technical summary

The `qc_info` plugin in MariaDB server can be confused by a query containing embedded null bytes, potentially disclosing adjacent memory or crashing the server. This issue affects versions from 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. The vulnerability is due to improper handling of queries with embedded null bytes, which can lead to out-of-bounds reads. Defenders should prioritize verifying and upgrading to fixed versions to prevent potential information disclosure or server crashes. The vulnerability can be mitigated by reviewing and monitoring database queries for potential anomalies and implementing compensating controls.

Defensive priority

Defenders should prioritize verifying and upgrading to fixed versions, as this issue can lead to potential information disclosure or server crashes.

Recommended defensive actions

  • Verify and upgrade to fixed versions (10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2) to prevent potential information disclosure or server crashes.
  • Review and monitor database queries for potential anomalies.
  • Implement compensating controls, such as query logging and monitoring, to detect potential exploitation attempts.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is no information on known exploitation or victims. The vulnerability is confirmed to exist in the specified versions, and defenders should verify the presence of affected versions in their deployments. The CVE Program record and NVD detail page provide additional context on the vulnerability. There are no known reports of exploitation, but defenders should still prioritize verification and upgrades.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107816 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107816

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107816 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107816

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • MariaDB: `qc_info` plugin can do OOB reads if query contains \0

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107816.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/security/advisories/GHSA-wfqg-88r5-55f6

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/commit/0931994096b84ecc9ffc8eb3517c7e09e6e8631e

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-11.4.13

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-11.8.9

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MariaDB/server/releases/tag/mariadb-12.3.3

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.