CVE-2026-35549

Name
CVE-2026-35549
Description
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://jira.mariadb.org/browse/MDEV-38365

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* mariadb >= None < 11.4.10
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* mariadb >= 11.5.0 < 11.8.6
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* mariadb >= 12.0.0 < 12.2.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
mariadb edge-main 11.8.5-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 11.8.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 11.4.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 11.4.8-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 11.4.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 11.4.7-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 11.4.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 11.4.5-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 11.4.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 11.4.4-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 11.4.4-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.11.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.11.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.6.12-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.6.12-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.6.11-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.6.10-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.6.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.6.8-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.6.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.6.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.6.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.5.11-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.5.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb edge-main 10.5.8-r0 None possibly vulnerable
mariadb edge-main 10.5.6-r0 None possibly vulnerable
mariadb edge-main 10.4.13-r0 None possibly vulnerable
mariadb edge-main 10.4.12-r0 None possibly vulnerable
mariadb edge-main 10.4.10-r0 None possibly vulnerable
mariadb edge-main 10.4.7-r0 None possibly vulnerable
mariadb edge-main 10.3.15-r0 None possibly vulnerable
mariadb edge-main 10.3.13-r0 None possibly vulnerable
mariadb edge-main 10.3.11-r0 None possibly vulnerable
mariadb edge-main 10.2.15-r0 None possibly vulnerable
mariadb edge-main 10.1.22-r0 None possibly vulnerable
mariadb edge-main 10.1.21-r0 None possibly vulnerable
mariadb 3.23-main 11.4.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.22-main 11.4.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.22-main 11.4.5-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.22-main 11.4.5-r0 None possibly vulnerable
mariadb 3.22-main 10.11.8-r0 None possibly vulnerable
mariadb 3.22-main 10.11.6-r0 None possibly vulnerable
mariadb 3.22-main 10.6.9-r0 None possibly vulnerable
mariadb 3.22-main 10.6.8-r0 None possibly vulnerable
mariadb 3.22-main 10.6.7-r0 None possibly vulnerable
mariadb 3.22-main 10.6.4-r0 None possibly vulnerable
mariadb 3.22-main 10.5.11-r0 None possibly vulnerable
mariadb 3.22-main 10.5.9-r0 None possibly vulnerable
mariadb 3.22-main 10.5.8-r0 None possibly vulnerable
mariadb 3.22-main 10.5.6-r0 None possibly vulnerable
mariadb 3.22-main 10.4.13-r0 None possibly vulnerable
mariadb 3.22-main 10.4.12-r0 None possibly vulnerable
mariadb 3.22-main 10.4.10-r0 None possibly vulnerable
mariadb 3.22-main 10.4.7-r0 None possibly vulnerable
mariadb 3.22-main 10.3.15-r0 None possibly vulnerable
mariadb 3.22-main 10.3.13-r0 None possibly vulnerable
mariadb 3.22-main 10.3.11-r0 None possibly vulnerable
mariadb 3.22-main 10.2.15-r0 None possibly vulnerable
mariadb 3.22-main 10.1.22-r0 None possibly vulnerable
mariadb 3.22-main 10.1.21-r0 None possibly vulnerable
mariadb 3.21-main 11.4.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.21-main 11.4.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.21-main 11.4.4-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.21-main 10.11.8-r0 None possibly vulnerable
mariadb 3.21-main 10.11.6-r0 None possibly vulnerable
mariadb 3.21-main 10.6.9-r0 None possibly vulnerable
mariadb 3.21-main 10.6.8-r0 None possibly vulnerable
mariadb 3.21-main 10.6.7-r0 None possibly vulnerable
mariadb 3.21-main 10.6.4-r0 None possibly vulnerable
mariadb 3.21-main 10.5.11-r0 None possibly vulnerable
mariadb 3.21-main 10.5.9-r0 None possibly vulnerable
mariadb 3.21-main 10.5.8-r0 None possibly vulnerable
mariadb 3.21-main 10.5.6-r0 None possibly vulnerable
mariadb 3.21-main 10.4.13-r0 None possibly vulnerable
mariadb 3.21-main 10.4.12-r0 None possibly vulnerable
mariadb 3.21-main 10.4.10-r0 None possibly vulnerable
mariadb 3.21-main 10.4.7-r0 None possibly vulnerable
mariadb 3.21-main 10.3.15-r0 None possibly vulnerable
mariadb 3.21-main 10.3.13-r0 None possibly vulnerable
mariadb 3.21-main 10.3.11-r0 None possibly vulnerable
mariadb 3.21-main 10.2.15-r0 None possibly vulnerable
mariadb 3.21-main 10.1.22-r0 None possibly vulnerable
mariadb 3.21-main 10.1.21-r0 None possibly vulnerable
mariadb 3.20-main 10.11.18-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.20-main 10.11.17-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.20-main 10.11.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.20-main 10.11.14-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.20-main 10.11.11-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.20-main 10.11.10-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.20-main 10.11.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.20-main 10.11.6-r0 None possibly vulnerable
mariadb 3.20-main 10.6.9-r0 None possibly vulnerable
mariadb 3.20-main 10.6.8-r0 None possibly vulnerable
mariadb 3.20-main 10.6.7-r0 None possibly vulnerable
mariadb 3.20-main 10.6.4-r0 None possibly vulnerable
mariadb 3.20-main 10.5.11-r0 None possibly vulnerable
mariadb 3.20-main 10.5.9-r0 None possibly vulnerable
mariadb 3.20-main 10.5.8-r0 None possibly vulnerable
mariadb 3.20-main 10.5.6-r0 None possibly vulnerable
mariadb 3.20-main 10.4.13-r0 None possibly vulnerable
mariadb 3.20-main 10.4.12-r0 None possibly vulnerable
mariadb 3.20-main 10.4.10-r0 None possibly vulnerable
mariadb 3.20-main 10.4.7-r0 None possibly vulnerable
mariadb 3.20-main 10.3.15-r0 None possibly vulnerable
mariadb 3.20-main 10.3.13-r0 None possibly vulnerable
mariadb 3.20-main 10.3.11-r0 None possibly vulnerable
mariadb 3.20-main 10.2.15-r0 None possibly vulnerable
mariadb 3.20-main 10.1.22-r0 None possibly vulnerable
mariadb 3.20-main 10.1.21-r0 None possibly vulnerable
mariadb 3.19-main 10.11.14-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.19-main 10.11.11-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.19-main 10.11.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.19-main 10.6.9-r0 None possibly vulnerable
mariadb 3.19-main 10.6.8-r0 None possibly vulnerable
mariadb 3.19-main 10.6.7-r0 None possibly vulnerable
mariadb 3.19-main 10.6.4-r0 None possibly vulnerable
mariadb 3.19-main 10.5.11-r0 None possibly vulnerable
mariadb 3.19-main 10.5.9-r0 None possibly vulnerable
mariadb 3.19-main 10.5.8-r0 None possibly vulnerable
mariadb 3.19-main 10.5.6-r0 None possibly vulnerable
mariadb 3.19-main 10.4.13-r0 None possibly vulnerable
mariadb 3.19-main 10.4.12-r0 None possibly vulnerable
mariadb 3.19-main 10.4.10-r0 None possibly vulnerable
mariadb 3.19-main 10.4.7-r0 None possibly vulnerable
mariadb 3.19-main 10.3.15-r0 None possibly vulnerable
mariadb 3.19-main 10.3.13-r0 None possibly vulnerable
mariadb 3.19-main 10.3.11-r0 None possibly vulnerable
mariadb 3.19-main 10.2.15-r0 None possibly vulnerable
mariadb 3.19-main 10.1.22-r0 None possibly vulnerable
mariadb 3.19-main 10.1.21-r0 None possibly vulnerable