openSUSE-SU-2026:21409-1: important: Security update for mariadb-connector-c

[email protected] Fri, 24 Jul 2026 17:52:47 +0200 (CEST)
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for mariadb-connector-c
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21409-1
Rating: important
References:

  * bsc#1266438



Cross-References:

  * CVE-2026-44172



CVSS scores:

  * CVE-2026-44172 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for mariadb-connector-c fixes the following issue:

- CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438).

Changes for mariadb-connector-c:

- Update to release 3.4.9.

- Update to release 3.4.8:

 * Fix compilation with GCC 15
 * CONC-762: always set is_null and length in the bind
 structure to avoid msan errors
 * CONC-763: add MySQL collation ID 309 (utf8mb4_0900_bin)
 * CONC-764: fix build of ma_context.c on Android (X18 is a
 platform-reserved register)
 * CONC-766: disable clang -Wcast-function-type-strict for
 makecontext


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1319=1

Package List:

- openSUSE Leap 16.0:

  libmariadb-devel-3.4.9-160000.1.1
  libmariadb3-3.4.9-160000.1.1
  libmariadb_plugins-3.4.9-160000.1.1
  libmariadbprivate-3.4.9-160000.1.1

References:

  * https://www.suse.com/security/cve/CVE-2026-44172.html