Bug 2494797 - CVE-2026-44169 mariadb10.11: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check [fedora-all]
Summary: CVE-2026-44169 mariadb10.11: MariaDB server: Information disclosure of stored...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: mariadb10.11
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Michal Schorm
QA Contact:
URL:
Whiteboard: {"flaws": ["cbaceffd-3a41-41de-aea8-5...
Depends On:
Blocks: CVE-2026-44169
TreeView+ depends on / blocked
 
Reported: 2026-06-30 08:16 UTC by Praise Ogwuche
Modified: 2026-06-30 11:00 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-06-30 11:00:02 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Praise Ogwuche 2026-06-30 08:16:32 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.

Comment 1 Michal Schorm 2026-06-30 11:00:02 UTC
Not applicable to 10.11 version:
https://github.com/MariaDB/server/security/advisories/GHSA-22xq-vq3f-87x2


Note You need to log in before you can comment on or make changes to this bug.