Vulnerabilities

MariaDB on Linux: which version fixes what

MariaDB began as a fork of MySQL and still inherits a good deal of its code, so a MySQL advisory frequently applies to MariaDB too, arriving later and under a different package name.

SecAI tracks 106 distinct CVEs affecting MariaDB across the 6 distributions below, of which 44 have no fixed package version on at least one of them. Each row names the package version that fixes it on that release.

What it is, and why it is on your server

MariaDB is the default database on Debian and on Rocky and AlmaLinux, and the one most hosting panels install. Ubuntu stamps the branch into the source package name, so it is mariadb-10.6 on 22.04 and mariadb on 24.04.

Why its advisories behave the way they do

  • Shared ancestry means shared bugs. When Oracle publishes a server flaw in code that predates the fork, MariaDB usually needs the same fix, and the two projects do not ship on the same day.
  • It is what a panel installs. cPanel, Plesk and DirectAdmin overwhelmingly deploy MariaDB, which makes it the database actually running on most shared-hosting servers.
  • Major versions are supported for years and then abruptly are not. A server sitting on a branch past its end-of-life date stops receiving fixes without anything appearing to change.

Check what you are actually running

The version that matters is the package version, not the upstream one. Distributions backport security fixes without changing the number before the dash, so a release that looks years old is frequently fully patched, and the revision after the dash is the only part that tells you.

Debian and Ubuntu
dpkg-query -W -f='${Package} ${Version}\n' mariadb-server mariadb-client 2>/dev/null
Rocky Linux and AlmaLinux
rpm -q mariadb-server mariadb

Fixed versions, per distribution

Each distribution patches on its own schedule and under its own version scheme, so the same CVE has a different answer on each of them. These come from the distributions’ own advisory data, asked per release. Where a release has no fixed version, that is what the advisory says, not a gap in the data.

Ubuntu 22.04 LTSsource package: mariadb-10.6

CVEPublishedFixed in package version
CVE-2026-469362026-07-21no fixed version released
CVE-2026-470122026-07-21no fixed version released
CVE-2026-470232026-07-21no fixed version released
CVE-2026-470522026-07-21no fixed version released
CVE-2026-470642026-07-21no fixed version released
CVE-2026-601452026-07-21no fixed version released
CVE-2026-601632026-07-21no fixed version released
CVE-2026-601772026-07-21no fixed version released
CVE-2026-601782026-07-21no fixed version released
CVE-2026-601822026-07-21no fixed version released
CVE-2026-601832026-07-21no fixed version released
CVE-2026-601842026-07-21no fixed version released
CVE-2026-601852026-07-21no fixed version released
CVE-2026-601862026-07-21no fixed version released
CVE-2026-601872026-07-21no fixed version released
CVE-2026-601882026-07-21no fixed version released
CVE-2026-601892026-07-21no fixed version released
CVE-2026-601902026-07-21no fixed version released
CVE-2026-601912026-07-21no fixed version released
CVE-2026-603152026-07-21no fixed version released
CVE-2026-603162026-07-21no fixed version released
CVE-2026-603312026-07-21no fixed version released
CVE-2026-603322026-07-21no fixed version released
CVE-2026-605852026-07-21no fixed version released
CVE-2026-607472026-07-21no fixed version released

Showing the 25 most recent of 95 that apply to Ubuntu 22.04 LTS, 44 of which have no fixed version released.

Ubuntu 24.04 LTSsource package: mariadb

CVEPublishedFixed in package version
CVE-2026-469362026-07-21no fixed version released
CVE-2026-470122026-07-21no fixed version released
CVE-2026-470232026-07-21no fixed version released
CVE-2026-470522026-07-21no fixed version released
CVE-2026-470642026-07-21no fixed version released
CVE-2026-601452026-07-21no fixed version released
CVE-2026-601632026-07-21no fixed version released
CVE-2026-601772026-07-21no fixed version released
CVE-2026-601782026-07-21no fixed version released
CVE-2026-601822026-07-21no fixed version released
CVE-2026-601832026-07-21no fixed version released
CVE-2026-601842026-07-21no fixed version released
CVE-2026-601852026-07-21no fixed version released
CVE-2026-601862026-07-21no fixed version released
CVE-2026-601872026-07-21no fixed version released
CVE-2026-601882026-07-21no fixed version released
CVE-2026-601892026-07-21no fixed version released
CVE-2026-601902026-07-21no fixed version released
CVE-2026-601912026-07-21no fixed version released
CVE-2026-603152026-07-21no fixed version released
CVE-2026-603162026-07-21no fixed version released
CVE-2026-603312026-07-21no fixed version released
CVE-2026-603322026-07-21no fixed version released
CVE-2026-605852026-07-21no fixed version released
CVE-2026-607472026-07-21no fixed version released

Showing the 25 most recent of 51 that apply to Ubuntu 24.04 LTS, 44 of which have no fixed version released.

Debian 12 (bookworm)source package: mariadb

CVEPublishedFixed in package version
CVE-2026-470232026-07-21no fixed version released
CVE-2026-601842026-07-21no fixed version released
CVE-2026-603312026-07-21no fixed version released
CVE-2026-605852026-07-21no fixed version released
CVE-2026-607472026-07-21no fixed version released
CVE-2026-610812026-07-21no fixed version released
CVE-2026-441682026-06-121:10.11.18-0+deb12u1
CVE-2026-441692026-06-12no fixed version released
CVE-2026-441712026-06-121:10.11.18-0+deb12u1
CVE-2026-441722026-06-121:10.11.18-0+deb12u1
CVE-2026-441732026-06-121:10.11.18-0+deb12u1
CVE-2026-481632026-06-121:10.11.18-0+deb12u1
CVE-2026-481652026-06-121:10.11.18-0+deb12u1
CVE-2026-492612026-06-111:10.11.18-0+deb12u1
CVE-2026-343032026-04-211:10.11.18-0+deb12u1
CVE-2026-34942026-03-031:10.11.18-0+deb12u1
CVE-2026-219682026-01-201:10.11.18-0+deb12u1
CVE-2025-136992025-12-231:10.11.18-0+deb12u1
CVE-2025-306932025-04-151:10.11.13-0+deb12u1
CVE-2025-307222025-04-151:10.11.13-0+deb12u1
CVE-2023-529692025-03-081:10.11.13-0+deb12u1
CVE-2023-529702025-03-081:10.11.13-0+deb12u1
CVE-2023-529712025-03-081:10.11.13-0+deb12u1
CVE-2025-214902025-01-211:10.11.11-0+deb12u1
CVE-2024-210962024-04-161:10.11.11-0+deb12u1

Showing the 25 most recent of 27 that apply to Debian 12 (bookworm), 7 of which have no fixed version released.

Debian 13 (trixie)source package: mariadb

CVEPublishedFixed in package version
CVE-2026-470232026-07-21no fixed version released
CVE-2026-601842026-07-21no fixed version released
CVE-2026-603312026-07-21no fixed version released
CVE-2026-605852026-07-21no fixed version released
CVE-2026-607472026-07-21no fixed version released
CVE-2026-610812026-07-21no fixed version released
CVE-2026-441682026-06-12no fixed version released
CVE-2026-441692026-06-12no fixed version released
CVE-2026-441712026-06-12no fixed version released
CVE-2026-441722026-06-12no fixed version released
CVE-2026-441732026-06-12no fixed version released
CVE-2026-481632026-06-12no fixed version released
CVE-2026-481652026-06-12no fixed version released
CVE-2026-492612026-06-11no fixed version released
CVE-2026-343032026-04-211:11.8.6-0+deb13u1
CVE-2026-355492026-04-031:11.8.6-0+deb13u1
CVE-2026-327102026-03-201:11.8.6-0+deb13u1
CVE-2026-34942026-03-031:11.8.6-0+deb13u1
CVE-2026-219682026-01-2011.8.6-0+deb13u1
CVE-2025-136992025-12-2311.8.6-0+deb13u1
CVE-2025-306932025-04-151:11.8.2-1
CVE-2025-307222025-04-151:11.8.2-1
CVE-2023-529692025-03-081:11.8.2-1
CVE-2023-529702025-03-081:11.8.2-1
CVE-2023-529712025-03-081:11.8.2-1

Showing the 25 most recent of 29 that apply to Debian 13 (trixie), 14 of which have no fixed version released.

Rocky Linux 9source package: mariadb

CVEPublishedFixed in package version
CVE-2026-441682026-07-053:11.8.8-1.module+el9.8.0+40229+87be66a2
CVE-2026-441692026-07-053:11.8.8-1.module+el9.8.0+40229+87be66a2
CVE-2026-441702026-07-053:11.8.8-1.module+el9.8.0+40229+87be66a2
CVE-2026-441712026-07-053:11.8.8-1.module+el9.8.0+40229+87be66a2
CVE-2026-441722026-07-053:11.8.8-1.module+el9.8.0+40229+87be66a2
CVE-2026-441732026-07-053:11.8.8-1.module+el9.8.0+40229+87be66a2
CVE-2026-481632026-07-053:11.8.8-1.module+el9.8.0+40229+87be66a2
CVE-2026-481652026-07-053:11.8.8-1.module+el9.8.0+40229+87be66a2
CVE-2026-492612026-07-053:11.8.8-1.module+el9.8.0+40229+87be66a2
CVE-2026-327102026-05-283:11.8.6-2.module+el9.8.0+40192+484cc2de
CVE-2023-529692026-01-093:10.11.15-1.module+el9.7.0+40065+b33d0971
CVE-2023-529702026-01-093:10.11.15-1.module+el9.7.0+40065+b33d0971
CVE-2023-529712026-01-093:10.11.15-1.module+el9.7.0+40065+b33d0971
CVE-2025-136992026-01-093:10.11.15-1.module+el9.7.0+40065+b33d0971
CVE-2025-214902026-01-093:10.11.15-1.module+el9.7.0+40065+b33d0971
CVE-2025-306932026-01-093:10.11.15-1.module+el9.7.0+40065+b33d0971
CVE-2025-307222026-01-093:10.11.15-1.module+el9.7.0+40065+b33d0971
CVE-2024-210962025-03-173:10.11.10-1.module+el9.5.0+30364+a2cca97c
CVE-2021-466592022-08-093:10.5.16-2.el9_0
CVE-2021-466612022-08-093:10.5.16-2.el9_0
CVE-2021-466632022-08-093:10.5.16-2.el9_0
CVE-2021-466642022-08-093:10.5.16-2.el9_0
CVE-2021-466652022-08-093:10.5.16-2.el9_0
CVE-2021-466682022-08-093:10.5.16-2.el9_0
CVE-2021-466692022-08-093:10.5.16-2.el9_0

Showing the 25 most recent of 55 that apply to Rocky Linux 9.

AlmaLinux 9source package: mariadb

CVEPublishedFixed in package version
CVE-2026-492612026-06-303:11.8.8-1.module_el9.8.0+274+ad8c02e7
CVE-2023-529692026-01-073:10.11.15-1.module_el9.7.0+199+a988ea01
CVE-2023-529702026-01-073:10.11.15-1.module_el9.7.0+199+a988ea01
CVE-2023-529712026-01-073:10.11.15-1.module_el9.7.0+199+a988ea01
CVE-2025-136992026-01-073:10.11.15-1.module_el9.7.0+199+a988ea01
CVE-2025-214902026-01-073:10.11.15-1.module_el9.7.0+199+a988ea01
CVE-2025-306932026-01-073:10.11.15-1.module_el9.7.0+199+a988ea01
CVE-2025-307222026-01-073:10.11.15-1.module_el9.7.0+199+a988ea01
CVE-2024-210962025-02-043:10.11.10-1.module_el9.5.0+135+c9657a87
CVE-2023-220842025-02-043:10.5.27-1.el9_5
CVE-2022-320812023-10-123:10.5.22-1.el9_2.alma.1
CVE-2022-320822023-10-123:10.5.22-1.el9_2.alma.1
CVE-2022-320842023-10-123:10.5.22-1.el9_2.alma.1
CVE-2022-320892023-10-123:10.5.22-1.el9_2.alma.1
CVE-2022-320912023-10-123:10.5.22-1.el9_2.alma.1
CVE-2022-387912023-10-123:10.5.22-1.el9_2.alma.1
CVE-2022-470152023-10-123:10.5.22-1.el9_2.alma.1
CVE-2023-51572023-10-123:10.5.22-1.el9_2.alma.1
CVE-2021-466592022-08-093:10.5.16-2.el9_0
CVE-2021-466612022-08-093:10.5.16-2.el9_0
CVE-2021-466632022-08-093:10.5.16-2.el9_0
CVE-2021-466642022-08-093:10.5.16-2.el9_0
CVE-2021-466652022-08-093:10.5.16-2.el9_0
CVE-2021-466682022-08-093:10.5.16-2.el9_0
CVE-2021-466692022-08-093:10.5.16-2.el9_0

Showing the 25 most recent of 54 that apply to AlmaLinux 9.

Advisory data last refreshed 26 September 2026. It is re-read daily.

What this page does not tell you

It does not tell you whether your server is affected. A CVE applying to a package is not the same as a CVE applying to your installation: the fix may already be backported into what you are running, the vulnerable module may not be loaded, or the service may not be reachable from anywhere that matters. Answering that needs the versions on your machine, not a list.

It also carries no count of how many servers are affected. SecAI monitors a small fleet, and a percentage drawn from it would be arithmetic on a sample too small to mean anything. When that changes, the number will appear here and the page will say when it started.

Read next

Find out which of these you are running

One read-only command, no account, no agent. It reads the installed package versions on your server and tells you which advisories actually apply to them, MariaDB included. It changes nothing.