Dark C0d3rs

Full Version: HackerOne Disclosed Reports - 2026-10-07
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Logo
Medium
resolved

MariaDB HandlerSocket Improper Request Field-Count Validation Causes Server Crash


Bug reported by XlabAITeam was disclosed at October 7, 2026, 8:03 pm   |   Uncontrolled Resource Consumption

A vulnerability was discovered in MariaDB Server's optional HandlerSocket plugin that allowed improper validation of request field-count parameters. When processing exec requests, the plugin allocated stack memory based on a client-supplied field count before validating whether the count was reasonable. An attacker could send requests with abnormally large field counts to cause the MariaDB process to crash, resulting in database service denial of service. The vulnerability affected deployments with HandlerSocket enabled, and could be exploited by unauthenticated attackers if no authentication secret was configured.


Logo
Medium
resolved

MariaDB Low-Privilege User Can Exhaust Memory Through a Formatting Function and Crash the Service


Bug reported by XlabAITeam was disclosed at October 7, 2026, 8:01 pm   |   Uncontrolled Resource Consumption

A low-privilege database user was able to exhaust memory on a MariaDB server through the SFORMAT() function by specifying an extremely large width parameter. The function attempted to allocate nearly 2 GB of memory before generating the return value. Multiple concurrent requests caused the database process to be terminated by the system's out-of-memory mechanism, resulting in service unavailability. The vulnerability required only basic database login privileges and the ability to execute standard SELECT queries. No administrative access, table privileges, or user interaction was necessary to exploit this denial-of-service condition.


Logo
High
resolved

DROP PACKAGE leaves PACKAGE BODY grant in mysql.procs_priv causing privilege escalation


Bug reported by jeb was disclosed at October 7, 2026, 7:57 pm   |   Improper Access Control - Generic

A privilege escalation vulnerability was discovered in package management functionality. When a package was dropped, the associated grant in the privilege table for the package body was not removed, while the package object itself was deleted from the system catalog. If a new package with the same name was subsequently created, the orphaned grant allowed previous users to execute the new package without explicit authorization, running with the new definer's privileges. The vulnerability also propagated through role-based access control to all role members. The issue was specific to package drops, as other similar drop operations correctly cleaned up their respective privilege rows.


Logo
Medium
resolved

Pre-authentication `size_t` integer underflow → out-of-bounds read / server crash in MariaDB `caching_sha2_password` (auth_mysql_sha2) via an RSA-OAEP


Bug reported by vnth4nhnt was disclosed at October 7, 2026, 7:54 pm   |   Integer Underflow

A pre-authentication integer underflow vulnerability was discovered in the caching_sha2_password authentication plugin. When a client sent an RSA-OAEP encrypted empty message over plaintext TCP, the decrypted length was not validated before being used in a subtraction operation. This caused a size_t integer underflow that resulted in an out-of-bounds read in the SHA-256 hashing routine. The vulnerability allowed an unauthenticated attacker to crash the database server without requiring valid credentials.


Logo
High
resolved

Missing FILE-privilege enforcement in CONNECT file UDFs allows server-side file read and write


Bug reported by Duong Tran was disclosed at October 7, 2026, 7:53 pm   |   Improper Access Control - Generic

A privilege enforcement vulnerability was discovered in file user-defined functions (UDFs) of a database engine. The file UDFs failed to enforce FILE privilege requirements and secure file path restrictions that were already implemented in the file-backed table handler. This allowed users with only SELECT privileges to read arbitrary files accessible to the database process and write files outside the configured secure directory. The vulnerability affected multiple file-related UDFs and was reproducible on multiple versions of the database software. The issue resulted from file UDFs not performing the same access control checks that were already in place for equivalent table operations.


Logo
Critical
resolved

Low-privilege RCE in MariaDB: SYS_REFCURSOR cursor-array use-after-free chained with an ST_Area heap over-read


Bug reported by Rick de Jager was disclosed at October 7, 2026, 7:47 pm   |   Use After Free

A critical remote code execution vulnerability was discovered in MariaDB Server 13.0.2. The vulnerability chained two memory-safety bugs to allow an authenticated low-privilege user to execute arbitrary operating system commands as the database process user without requiring FILE, SUPER, or administrative privileges.

The first bug was a use-after-free condition in the system reference cursor array implementation. When the cursor array expanded, the backing buffer was reallocated, but open cursors retained raw pointers to the freed memory. Subsequent fetch operations dereferenced these dangling pointers, resulting in a virtual function call through an attacker-controlled vtable.

The second bug was an out-of-bounds heap read in the ST_Area geospatial function. A missing bounds check in the multipolygon area calculation allowed reading past the geometry buffer when processing a crafted multipolygon with a declared polygon count exceeding the actual polygons present. This enabled an in-process memory disclosure oracle.

The exploit chain combined these bugs to leak heap and code addresses for defeating address space layout randomization and position-independent execution, then used the use-after-free to gain elevated database privileges and execute arbitrary commands. The complete end-to-end exploit was demonstrated against the released Docker image.


Logo
High
resolved

Heap Use-After-Free in Materialized_cursor::open via SYS_REFCURSOR Array Reallocation


Bug reported by Akhil Koul was disclosed at October 7, 2026, 7:46 pm   |   Use After Free

A heap-use-after-free vulnerability was identified in the cursor handling mechanism of the database server. The vulnerability existed in the cursor opening function where array reallocation during nested cursor operations caused dangling pointer references. When a cursor's SELECT statement invoked a function that opened additional cursors, the underlying memory buffer was reallocated, invalidating previously stored pointer addresses. These stale pointers were subsequently used for virtual method calls and memory writes, resulting in potential code execution and heap corruption. The issue affected authenticated users with function creation privileges and was distinct from a previously addressed related bug that had removed a stored member variable but had not corrected the parameter passing at the call site.