Heap-based buffer overflow in MariaDB - CVE-2026-32710
Published: April 28, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in the JSON_SCHEMA_VALID() function when processing crafted input. A remote user can send specially crafted input to execute arbitrary code.
Successful code execution requires tight control over memory layout and is generally only attainable in a lab environment.
Affected software
mariadb-debugsource
mariadb-debuginfo
mariadb-galera
libmariadbd-devel
mariadb-client
mariadb
libmariadbd19
mariadb-client-debuginfo
mariadb-tools
mariadb-tools-debuginfo
libmariadbd19-debuginfo
mariadb-errormessages
Galera for Ericsson 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Server Applications Module
SUSE Package Hub 15
How to mitigate CVE-2026-32710
mariadb-debugsource - update to 11.8.6-150700.3.12.1
mariadb-debuginfo - update to 11.8.6-150700.3.12.1
mariadb-galera - update to 11.8.6-150700.3.12.1
libmariadbd-devel - update to 11.8.6-150700.3.12.1
mariadb-client - update to 11.8.6-150700.3.12.1
mariadb - update to 11.8.6-150700.3.12.1
libmariadbd19 - update to 11.8.6-150700.3.12.1
mariadb-client-debuginfo - update to 11.8.6-150700.3.12.1
mariadb-tools - update to 11.8.6-150700.3.12.1
mariadb-tools-debuginfo - update to 11.8.6-150700.3.12.1
libmariadbd19-debuginfo - update to 11.8.6-150700.3.12.1
mariadb-errormessages - update to 11.8.6-150700.3.12.1