Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-27766

Published: October 20, 2024Last modified: June 17, 2025

Description

An issue in MYSQL MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function.

Severity score breakdown

ParameterValue
Base score5.7
Attack VectorPHYSICAL
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Notes

According to https://ubuntu.com/security/CVE-2024-27766 this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSmariadbWill not fix (10.6.12-r0)
StreammariadbWill not fix (10.11.4-r0)

References

ON THIS PAGE