Bug 2494795 - CVE-2026-44169 mariadb11.8: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check [fedora-all]
Summary: CVE-2026-44169 mariadb11.8: MariaDB server: Information disclosure of stored ...
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: mariadb11.8
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Michal Schorm
QA Contact:
URL:
Whiteboard: {"flaws": ["cbaceffd-3a41-41de-aea8-5...
Depends On:
Blocks: CVE-2026-44169
TreeView+ depends on / blocked
 
Reported: 2026-06-30 08:15 UTC by Praise Ogwuche
Modified: 2026-06-30 10:58 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-06-30 10:58:37 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Praise Ogwuche 2026-06-30 08:15:23 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.

Comment 1 Michal Schorm 2026-06-30 10:58:37 UTC
Fixed in the version currently available in Fedora Rawhide


Note You need to log in before you can comment on or make changes to this bug.