DEBIAN-CVE-2026-21968

Source
https://security-tracker.debian.org/tracker/CVE-2026-21968
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-21968.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-21968
Upstream
Published
2026-01-20T22:15:59.853Z
Modified
2026-03-14T12:01:07.371922Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

References

Affected packages

Debian:12 / mariadb

Package

Name
mariadb
Purl
pkg:deb/debian/mariadb?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:10.*
1:10.11.3-1
1:10.11.3-2~exp1
1:10.11.4-1~deb12u1
1:10.11.4-1
1:10.11.5-1
1:10.11.5-2
1:10.11.5-3
1:10.11.6-0+deb12u1
1:10.11.6-1
1:10.11.6-2
1:10.11.6-2.1~exp1
1:10.11.7-1
1:10.11.7-2
1:10.11.7-3
1:10.11.7-4
1:10.11.8-1
1:10.11.9-0+deb12u1
1:10.11.11-0+deb12u1
1:10.11.13-0+deb12u1
1:10.11.14-0+deb12u1
1:10.11.14-0+deb12u2
1:11.*
1:11.4.2-1
1:11.4.2-2
1:11.4.2-3
1:11.4.2-4
1:11.4.3-1
1:11.4.4-1
1:11.4.4-2
1:11.4.4-3
1:11.4.5-1
1:11.4.5-2~exp1
1:11.8.1-1
1:11.8.1-2
1:11.8.1-3
1:11.8.1-4
1:11.8.1-5
1:11.8.2-1
1:11.8.3-1
1:11.8.5-1
1:11.8.5-2
1:11.8.5-3~exp1
1:11.8.5-3~exp2
1:11.8.5-3~exp3
1:11.8.5-3
1:11.8.5-4
1:11.8.6-1
1:11.8.6-2
1:11.8.6-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-21968.json"

Debian:13 / mariadb

Package

Name
mariadb
Purl
pkg:deb/debian/mariadb?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.8.6-0+deb13u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-21968.json"

Debian:14 / mariadb

Package

Name
mariadb
Purl
pkg:deb/debian/mariadb?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:11.8.5-1

Affected versions

1:11.*
1:11.8.2-1
1:11.8.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-21968.json"