[RHSA-2016:0534] mariadb security and bug fix update

Severity Moderate
Affected Packages 44
CVEs 27

MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL.

The following packages have been upgraded to a newer upstream version: MariaDB (5.5.47). Refer to the MariaDB Release Notes listed in the References section for a complete list of changes.

Security Fix(es):

  • It was found that the MariaDB client library did not properly check host names against server identities noted in the X.509 certificates when establishing secure connections using TLS/SSL. A man-in-the-middle attacker could possibly use this flaw to impersonate a server to a client. (CVE-2016-2047)

  • This update fixes several vulnerabilities in the MariaDB database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section. (CVE-2015-4792, CVE-2015-4802, CVE-2015-4815, CVE-2015-4816, CVE-2015-4819, CVE-2015-4826, CVE-2015-4830, CVE-2015-4836, CVE-2015-4858, CVE-2015-4861, CVE-2015-4870, CVE-2015-4879, CVE-2015-4913, CVE-2016-0505, CVE-2016-0546, CVE-2016-0596, CVE-2016-0597, CVE-2016-0598, CVE-2016-0600, CVE-2016-0606, CVE-2016-0608, CVE-2016-0609, CVE-2016-0616)

Bug Fix(es):

  • When more than one INSERT operation was executed concurrently on a non-empty InnoDB table with an AUTO_INCREMENT column defined as a primary key immediately after starting MariaDB, a race condition could occur. As a consequence, one of the concurrent INSERT operations failed with a "Duplicate key" error message. A patch has been applied to prevent the race condition. Now, each row inserted as a result of the concurrent INSERT operations receives a unique primary key, and the operations no longer fail in this scenario. (BZ#1303946)
Package Affected Version
pkg:rpm/redhat/mariadb?arch=x86_64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb?arch=s390x&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb?arch=ppc64le&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb?arch=ppc64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-test?arch=x86_64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-test?arch=s390x&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-test?arch=ppc64le&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-test?arch=ppc64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-server?arch=x86_64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-server?arch=s390x&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-server?arch=ppc64le&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-server?arch=ppc64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-libs?arch=x86_64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-libs?arch=s390x&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-libs?arch=s390&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-libs?arch=ppc64le&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-libs?arch=ppc64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-libs?arch=ppc&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-libs?arch=i686&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded?arch=x86_64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded?arch=s390x&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded?arch=s390&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded?arch=ppc64le&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded?arch=ppc64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded?arch=ppc&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded?arch=i686&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded-devel?arch=x86_64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded-devel?arch=s390x&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded-devel?arch=s390&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded-devel?arch=ppc64le&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded-devel?arch=ppc64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded-devel?arch=ppc&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-embedded-devel?arch=i686&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-devel?arch=x86_64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-devel?arch=s390x&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-devel?arch=s390&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-devel?arch=ppc64le&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-devel?arch=ppc64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-devel?arch=ppc&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-devel?arch=i686&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-bench?arch=x86_64&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-bench?arch=s390x&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-bench?arch=ppc64le&distro=redhat-7.2 < 5.5.47-1.el7_2
pkg:rpm/redhat/mariadb-bench?arch=ppc64&distro=redhat-7.2 < 5.5.47-1.el7_2
Source # ID Name URL
Bugzilla 1274752 https://bugzilla.redhat.com/1274752
Bugzilla 1274756 https://bugzilla.redhat.com/1274756
Bugzilla 1274759 https://bugzilla.redhat.com/1274759
Bugzilla 1274761 https://bugzilla.redhat.com/1274761
Bugzilla 1274764 https://bugzilla.redhat.com/1274764
Bugzilla 1274766 https://bugzilla.redhat.com/1274766
Bugzilla 1274767 https://bugzilla.redhat.com/1274767
Bugzilla 1274771 https://bugzilla.redhat.com/1274771
Bugzilla 1274773 https://bugzilla.redhat.com/1274773
Bugzilla 1274776 https://bugzilla.redhat.com/1274776
Bugzilla 1274781 https://bugzilla.redhat.com/1274781
Bugzilla 1274783 https://bugzilla.redhat.com/1274783
Bugzilla 1274794 https://bugzilla.redhat.com/1274794
Bugzilla 1301492 https://bugzilla.redhat.com/1301492
Bugzilla 1301493 https://bugzilla.redhat.com/1301493
Bugzilla 1301496 https://bugzilla.redhat.com/1301496
Bugzilla 1301497 https://bugzilla.redhat.com/1301497
Bugzilla 1301498 https://bugzilla.redhat.com/1301498
Bugzilla 1301501 https://bugzilla.redhat.com/1301501
Bugzilla 1301504 https://bugzilla.redhat.com/1301504
Bugzilla 1301506 https://bugzilla.redhat.com/1301506
Bugzilla 1301507 https://bugzilla.redhat.com/1301507
Bugzilla 1301510 https://bugzilla.redhat.com/1301510
Bugzilla 1301874 https://bugzilla.redhat.com/1301874
Bugzilla 1329243 https://bugzilla.redhat.com/1329243
Bugzilla 1329254 https://bugzilla.redhat.com/1329254
Bugzilla 1358203 https://bugzilla.redhat.com/1358203
RHSA RHSA-2016:0534 https://access.redhat.com/errata/RHSA-2016:0534
CVE CVE-2015-4792 https://access.redhat.com/security/cve/CVE-2015-4792
CVE CVE-2015-4802 https://access.redhat.com/security/cve/CVE-2015-4802
CVE CVE-2015-4815 https://access.redhat.com/security/cve/CVE-2015-4815
CVE CVE-2015-4816 https://access.redhat.com/security/cve/CVE-2015-4816
CVE CVE-2015-4819 https://access.redhat.com/security/cve/CVE-2015-4819
CVE CVE-2015-4826 https://access.redhat.com/security/cve/CVE-2015-4826
CVE CVE-2015-4830 https://access.redhat.com/security/cve/CVE-2015-4830
CVE CVE-2015-4836 https://access.redhat.com/security/cve/CVE-2015-4836
CVE CVE-2015-4858 https://access.redhat.com/security/cve/CVE-2015-4858
CVE CVE-2015-4861 https://access.redhat.com/security/cve/CVE-2015-4861
CVE CVE-2015-4870 https://access.redhat.com/security/cve/CVE-2015-4870
CVE CVE-2015-4879 https://access.redhat.com/security/cve/CVE-2015-4879
CVE CVE-2015-4913 https://access.redhat.com/security/cve/CVE-2015-4913
CVE CVE-2016-0505 https://access.redhat.com/security/cve/CVE-2016-0505
CVE CVE-2016-0546 https://access.redhat.com/security/cve/CVE-2016-0546
CVE CVE-2016-0596 https://access.redhat.com/security/cve/CVE-2016-0596
CVE CVE-2016-0597 https://access.redhat.com/security/cve/CVE-2016-0597
CVE CVE-2016-0598 https://access.redhat.com/security/cve/CVE-2016-0598
CVE CVE-2016-0600 https://access.redhat.com/security/cve/CVE-2016-0600
CVE CVE-2016-0606 https://access.redhat.com/security/cve/CVE-2016-0606
CVE CVE-2016-0608 https://access.redhat.com/security/cve/CVE-2016-0608
CVE CVE-2016-0609 https://access.redhat.com/security/cve/CVE-2016-0609
CVE CVE-2016-0616 https://access.redhat.com/security/cve/CVE-2016-0616
CVE CVE-2016-0642 https://access.redhat.com/security/cve/CVE-2016-0642
CVE CVE-2016-0651 https://access.redhat.com/security/cve/CVE-2016-0651
CVE CVE-2016-2047 https://access.redhat.com/security/cve/CVE-2016-2047
CVE CVE-2016-3471 https://access.redhat.com/security/cve/CVE-2016-3471
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/mariadb?arch=x86_64&distro=redhat-7.2 redhat mariadb < 5.5.47-1.el7_2 redhat-7.2 x86_64
Affected pkg:rpm/redhat/mariadb?arch=s390x&distro=redhat-7.2 redhat mariadb < 5.5.47-1.el7_2 redhat-7.2 s390x
Affected pkg:rpm/redhat/mariadb?arch=ppc64le&distro=redhat-7.2 redhat mariadb < 5.5.47-1.el7_2 redhat-7.2 ppc64le
Affected pkg:rpm/redhat/mariadb?arch=ppc64&distro=redhat-7.2 redhat mariadb < 5.5.47-1.el7_2 redhat-7.2 ppc64
Affected pkg:rpm/redhat/mariadb-test?arch=x86_64&distro=redhat-7.2 redhat mariadb-test < 5.5.47-1.el7_2 redhat-7.2 x86_64
Affected pkg:rpm/redhat/mariadb-test?arch=s390x&distro=redhat-7.2 redhat mariadb-test < 5.5.47-1.el7_2 redhat-7.2 s390x
Affected pkg:rpm/redhat/mariadb-test?arch=ppc64le&distro=redhat-7.2 redhat mariadb-test < 5.5.47-1.el7_2 redhat-7.2 ppc64le
Affected pkg:rpm/redhat/mariadb-test?arch=ppc64&distro=redhat-7.2 redhat mariadb-test < 5.5.47-1.el7_2 redhat-7.2 ppc64
Affected pkg:rpm/redhat/mariadb-server?arch=x86_64&distro=redhat-7.2 redhat mariadb-server < 5.5.47-1.el7_2 redhat-7.2 x86_64
Affected pkg:rpm/redhat/mariadb-server?arch=s390x&distro=redhat-7.2 redhat mariadb-server < 5.5.47-1.el7_2 redhat-7.2 s390x
Affected pkg:rpm/redhat/mariadb-server?arch=ppc64le&distro=redhat-7.2 redhat mariadb-server < 5.5.47-1.el7_2 redhat-7.2 ppc64le
Affected pkg:rpm/redhat/mariadb-server?arch=ppc64&distro=redhat-7.2 redhat mariadb-server < 5.5.47-1.el7_2 redhat-7.2 ppc64
Affected pkg:rpm/redhat/mariadb-libs?arch=x86_64&distro=redhat-7.2 redhat mariadb-libs < 5.5.47-1.el7_2 redhat-7.2 x86_64
Affected pkg:rpm/redhat/mariadb-libs?arch=s390x&distro=redhat-7.2 redhat mariadb-libs < 5.5.47-1.el7_2 redhat-7.2 s390x
Affected pkg:rpm/redhat/mariadb-libs?arch=s390&distro=redhat-7.2 redhat mariadb-libs < 5.5.47-1.el7_2 redhat-7.2 s390
Affected pkg:rpm/redhat/mariadb-libs?arch=ppc64le&distro=redhat-7.2 redhat mariadb-libs < 5.5.47-1.el7_2 redhat-7.2 ppc64le
Affected pkg:rpm/redhat/mariadb-libs?arch=ppc64&distro=redhat-7.2 redhat mariadb-libs < 5.5.47-1.el7_2 redhat-7.2 ppc64
Affected pkg:rpm/redhat/mariadb-libs?arch=ppc&distro=redhat-7.2 redhat mariadb-libs < 5.5.47-1.el7_2 redhat-7.2 ppc
Affected pkg:rpm/redhat/mariadb-libs?arch=i686&distro=redhat-7.2 redhat mariadb-libs < 5.5.47-1.el7_2 redhat-7.2 i686
Affected pkg:rpm/redhat/mariadb-embedded?arch=x86_64&distro=redhat-7.2 redhat mariadb-embedded < 5.5.47-1.el7_2 redhat-7.2 x86_64
Affected pkg:rpm/redhat/mariadb-embedded?arch=s390x&distro=redhat-7.2 redhat mariadb-embedded < 5.5.47-1.el7_2 redhat-7.2 s390x
Affected pkg:rpm/redhat/mariadb-embedded?arch=s390&distro=redhat-7.2 redhat mariadb-embedded < 5.5.47-1.el7_2 redhat-7.2 s390
Affected pkg:rpm/redhat/mariadb-embedded?arch=ppc64le&distro=redhat-7.2 redhat mariadb-embedded < 5.5.47-1.el7_2 redhat-7.2 ppc64le
Affected pkg:rpm/redhat/mariadb-embedded?arch=ppc64&distro=redhat-7.2 redhat mariadb-embedded < 5.5.47-1.el7_2 redhat-7.2 ppc64
Affected pkg:rpm/redhat/mariadb-embedded?arch=ppc&distro=redhat-7.2 redhat mariadb-embedded < 5.5.47-1.el7_2 redhat-7.2 ppc
Affected pkg:rpm/redhat/mariadb-embedded?arch=i686&distro=redhat-7.2 redhat mariadb-embedded < 5.5.47-1.el7_2 redhat-7.2 i686
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=x86_64&distro=redhat-7.2 redhat mariadb-embedded-devel < 5.5.47-1.el7_2 redhat-7.2 x86_64
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=s390x&distro=redhat-7.2 redhat mariadb-embedded-devel < 5.5.47-1.el7_2 redhat-7.2 s390x
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=s390&distro=redhat-7.2 redhat mariadb-embedded-devel < 5.5.47-1.el7_2 redhat-7.2 s390
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=ppc64le&distro=redhat-7.2 redhat mariadb-embedded-devel < 5.5.47-1.el7_2 redhat-7.2 ppc64le
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=ppc64&distro=redhat-7.2 redhat mariadb-embedded-devel < 5.5.47-1.el7_2 redhat-7.2 ppc64
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=ppc&distro=redhat-7.2 redhat mariadb-embedded-devel < 5.5.47-1.el7_2 redhat-7.2 ppc
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=i686&distro=redhat-7.2 redhat mariadb-embedded-devel < 5.5.47-1.el7_2 redhat-7.2 i686
Affected pkg:rpm/redhat/mariadb-devel?arch=x86_64&distro=redhat-7.2 redhat mariadb-devel < 5.5.47-1.el7_2 redhat-7.2 x86_64
Affected pkg:rpm/redhat/mariadb-devel?arch=s390x&distro=redhat-7.2 redhat mariadb-devel < 5.5.47-1.el7_2 redhat-7.2 s390x
Affected pkg:rpm/redhat/mariadb-devel?arch=s390&distro=redhat-7.2 redhat mariadb-devel < 5.5.47-1.el7_2 redhat-7.2 s390
Affected pkg:rpm/redhat/mariadb-devel?arch=ppc64le&distro=redhat-7.2 redhat mariadb-devel < 5.5.47-1.el7_2 redhat-7.2 ppc64le
Affected pkg:rpm/redhat/mariadb-devel?arch=ppc64&distro=redhat-7.2 redhat mariadb-devel < 5.5.47-1.el7_2 redhat-7.2 ppc64
Affected pkg:rpm/redhat/mariadb-devel?arch=ppc&distro=redhat-7.2 redhat mariadb-devel < 5.5.47-1.el7_2 redhat-7.2 ppc
Affected pkg:rpm/redhat/mariadb-devel?arch=i686&distro=redhat-7.2 redhat mariadb-devel < 5.5.47-1.el7_2 redhat-7.2 i686
Affected pkg:rpm/redhat/mariadb-bench?arch=x86_64&distro=redhat-7.2 redhat mariadb-bench < 5.5.47-1.el7_2 redhat-7.2 x86_64
Affected pkg:rpm/redhat/mariadb-bench?arch=s390x&distro=redhat-7.2 redhat mariadb-bench < 5.5.47-1.el7_2 redhat-7.2 s390x
Affected pkg:rpm/redhat/mariadb-bench?arch=ppc64le&distro=redhat-7.2 redhat mariadb-bench < 5.5.47-1.el7_2 redhat-7.2 ppc64le
Affected pkg:rpm/redhat/mariadb-bench?arch=ppc64&distro=redhat-7.2 redhat mariadb-bench < 5.5.47-1.el7_2 redhat-7.2 ppc64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...