[USN-7376-2] MariaDB vulnerability

Eduardo Barretto eduardo.barretto at canonical.com
Mon Mar 31 13:57:15 UTC 2025


==========================================================================
Ubuntu Security Notice USN-7376-2
March 31, 2025

mariadb vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

A security issue was fixed in MariaDB.

Software Description:
- mariadb: MariaDB database
- mariadb-10.6: MariaDB database

Details:

USN-7376-1 fixed vulnerabilities in MariaDB. This update provides the
corresponding updates for Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.

Original advisory details:

 A security issue was discovered in MariaDB and this update includes
 a new upstream MariaDB version to fix the issue.

 In addition to security fixes, the updated packages contain bug and
 regression fixes, new features, and possibly incompatible changes.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
  mariadb-server                  1:10.11.11-0ubuntu0.24.04.2

Ubuntu 22.04 LTS
  mariadb-server                  1:10.6.21-0ubuntu0.22.04.2

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart MariaDB to
make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-7376-2
  https://ubuntu.com/security/notices/USN-7376-1
  CVE-2025-21490

Package Information:
  https://launchpad.net/ubuntu/+source/mariadb/1:10.11.11-0ubuntu0.24.04.2
  https://launchpad.net/ubuntu/+source/mariadb-10.6/1:10.6.21-0ubuntu0.22.04.2

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20250331/650af4e2/attachment.sig>


More information about the ubuntu-security-announce mailing list