MariaDB server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 취약점
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.
영향 제품·버전
제품 MariaDB server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8
영향 버전 MariaDB server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 >= >= 10.6.1, < 10.6.27, >= >= 10.11.1, < 10.11.18, >= >= 11.4.1, < 11.4.12, >= >= 11.8.1, < 11.8.8, >= = 12.3.1, >= 10.6.1 < 10.6.27, >= 10.11.1 < 10.11.18, >= 11.4.1 < 11.4.12, >= 11.8.1 < 11.8.8, 12.3.1
수정 버전 MariaDB server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 10.6.27, 10.11.18, 11.4.12, 11.8.8
MariaDB server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8의 현재 전체 버전이 공식 영향 범위(MariaDB server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 >= >= 10.6.1, < 10.6.27, >= >= 10.11.1, < 10.11.18, >= >= 11.4.1, < 11.4.12, >= >= 11.8.1, < 11.8.8, >= = 12.3.1, >= 10.6.1 < 10.6.27, >= 10.11.1 < 10.11.18, >= 11.4.1 < 11.4.12, >= 11.8.1 < 11.8.8, 12.3.1)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
저장소 Security Advisory 원문에서 CVE 번호가 CVE-2026-49261와 일치하는지 먼저 확인하고, 일치할 때만 수정 버전 값(10.6.27, 10.11.18, 11.4.12, 11.8.8)을 조치 기준으로 사용합니다.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 MariaDB server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 10.6.27, 10.11.18, 11.4.12, 11.8.8 기준을 충족하는지 확인합니다. 이어서 명령어·코드 인젝션 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.