Red Hat Product Errata RHSA-2026:43505 - Security Advisory Issued: 2026-07-22 Updated: 2026-07-22 RHSA-2026:43505 - Security Advisory Overview Updated Packages Synopsis Important: mariadb-connector-c security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for mariadb-connector-c is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The MariaDB Native Client library (C driver) is used to connect applications developed in C/C++ to MariaDB and MySQL databases. Security Fix(es): mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() (CVE-2026-44172) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2488459 - CVE-2026-44172 mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() CVEs CVE-2026-44172 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM mariadb-connector-c-3.4.4-2.el10_2.src.rpm SHA-256: d86e7907924a27097d6b000f71ed9d8f64fc86c185d16028bf9ba06da9d58401 x86_64 mariadb-connector-c-3.4.4-2.el10_2.x86_64.rpm SHA-256: 0b51a7121da82491ab6e5ddf08ec4481d5c445c0fcdb37d61520f6d869a768b3 mariadb-connector-c-config-3.4.4-2.el10_2.noarch.rpm SHA-256: 8b52a17f04485b8ac60f9fc875b48aa6f41ef34906c1bda5000aa0cd6ef4fd21 mariadb-connector-c-debuginfo-3.4.4-2.el10_2.x86_64.rpm SHA-256: 6c7604254fa3601b71f9172dcbd0facd6a6bdf40b79f8c9a56a70d87cd26ff85 mariadb-connector-c-debuginfo-3.4.4-2.el10_2.x86_64.rpm SHA-256: 6c7604254fa3601b71f9172dcbd0facd6a6bdf40b79f8c9a56a70d87cd26ff85 mariadb-connector-c-debugsource-3.4.4-2.el10_2.x86_64.rpm SHA-256: 04247bb1798189b3c06517f4cbf740d358a200a6bc86b99cc3409474ef709a59 mariadb-connector-c-debugsource-3.4.4-2.el10_2.x86_64.rpm SHA-256: 04247bb1798189b3c06517f4cbf740d358a200a6bc86b99cc3409474ef709a59 mariadb-connector-c-devel-3.4.4-2.el10_2.x86_64.rpm SHA-256: 4f4693556e1d1e91d0b00a97bd285d979516d0c6dc04282406cb2dc502430322 mariadb-connector-c-devel-debuginfo-3.4.4-2.el10_2.x86_64.rpm SHA-256: cc9229e094cf1606c770b47d63bdb8f6df334b0f9939b36a408f2068af29291e mariadb-connector-c-devel-debuginfo-3.4.4-2.el10_2.x86_64.rpm SHA-256: cc9229e094cf1606c770b47d63bdb8f6df334b0f9939b36a408f2068af29291e mariadb-connector-c-test-debuginfo-3.4.4-2.el10_2.x86_64.rpm SHA-256: 95e55d19d4899251ce2e6d1c3d518a346e4c1b5c0bb0a9107b45503c44c5c4e1 mariadb-connector-c-test-debuginfo-3.4.4-2.el10_2.x86_64.rpm SHA-256: 95e55d19d4899251ce2e6d1c3d518a346e4c1b5c0bb0a9107b45503c44c5c4e1 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM mariadb-connector-c-3.4.4-2.el10_2.src.rpm SHA-256: d86e7907924a27097d6b000f71ed9d8f64fc86c185d16028bf9ba06da9d58401 x86_64 mariadb-connector-c-3.4.4-2.el10_2.x86_64.rpm SHA-256: 0b51a7121da82491ab6e5ddf08ec4481d5c445c0fcdb37d61520f6d869a768b3 mariadb-connector-c-config-3.4.4-2.el10_2.noarch.rpm SHA-256: 8b52a17f04485b8ac60f9fc875b48aa6f41ef34906c1bda5000aa0cd6ef4fd21 mariadb-connector-c-debuginfo-3.4.4-2.el10_2.x86_64.rpm SHA-256: 6c7604254fa3601b71f9172dcbd0facd6a6bdf40b79f8c9a56a70d87cd26ff85 mariadb-connector-c-debuginfo-3.4.4-2.el10_2.x86_64.rpm SHA-256: 6c7604254fa3601b71f9172dcbd0facd6a6bdf40b79f8c9a56a70d87cd26ff85 mariadb-connector-c-debugsource-3.4.4-2.el10_2.x86_64.rpm SHA-256: 04247bb1798189b3c06517f4cbf740d358a200a6bc86b99cc3409474ef709a59 mariadb-connector-c-debugsource-3.4.4-2.el10_2.x86_64.rpm SHA-256: 04247bb1798189b3c06517f4cbf740d358a200a6bc86b99cc3409474ef709a59 mariadb-connector-c-devel-3.4.4-2.el10_2.x86_64.rpm SHA-256: 4f4693556e1d1e91d0b00a97bd285d979516d0c6dc04282406cb2dc502430322 mariadb-connector-c-devel-debuginfo-3.4.4-2.el10_2.x86_64.rpm SHA-256: cc9229e094cf1606c770b47d63bdb8f6df334b0f9939b36a408f2068af29291e mariadb-connector-c-devel-debuginfo-3.4.4-2.el10_2.x86_64.rpm SHA-256: cc9229e094cf1606c770b47d63bdb8f6df334b0f9939b36a408f2068af29291e mariadb-connector-c-test-debuginfo-3.4.4-2.el10_2.x86_64.rpm SHA-256: 95e55d19d4899251ce2e6d1c3d518a346e4c1b5c0bb0a9107b45503c44c5c4e1 mariadb-connector-c-test-debuginfo-3.4.4-2.el10_2.x86_64.rpm SHA-256: 95e55d19d4899251ce2e6d1c3d518a346e4c1b5c0bb0a9107b45503c44c5c4e1 Red Hat Enterprise Linux for IBM z Systems 10 SRPM mariadb-connector-c-3.4.4-2.el10_2.src.rpm SHA-256: d86e7907924a27097d6b000f71ed9d8f64fc86c185d16028bf9ba06da9d58401 s390x mariadb-connector-c-3.4.4-2.el10_2.s390x.rpm SHA-256: 68c067b1eab37a223f156bfba95bef920cba84f22f0eaaff5c69b22abd7e374d mariadb-connector-c-config-3.4.4-2.el10_2.noarch.rpm SHA-256: 8b52a17f04485b8ac60f9fc875b48aa6f41ef34906c1bda5000aa0cd6ef4fd21 mariadb-connector-c-debuginfo-3.4.4-2.el10_2.s390x.rpm SHA-256: 2310a70b9f27e53db311ca888c7536524406a8b0aae73ba06405a376ce033f02 mariadb-connector-c-debuginfo-3.4.4-2.el10_2.s390x.rpm SHA-256: 2310a70b9f27e53db311ca888c7536524406a8b0aae73ba06405a376ce033f02 mariadb-connector-c-debugsource-3.4.4-2.el10_2.s390x.rpm SHA-256: 9b930deaf2e17299c8e1eaf60ffa784ea165fa93e86f9872717c56b4baa0b5a7 mariadb-connector-c-debugsource-3.4.4-2.el10_2.s390x.rpm SHA-256: 9b930deaf2e17299c8e1eaf60ffa784ea165fa93e86f9872717c56b4baa0b5a7 mariadb-connector-c-devel-3.4.4-2.el10_2.s390x.rpm SHA-256: 1686920c21edd7e3f1460e6168c47e6f485755f374745329db59ee88f71257d0 mariadb-connector-c-devel-debuginfo-3.4.4-2.el10_2.s390x.rpm SHA-256: 2979d71a4c754d13dced76789609b43286fb07c346268642b37d27c17f3910fe mariadb-connector-c-devel-debuginfo-3.4.4-2.el10_2.s390x.rpm SHA-256: 2979d71a4c754d13dced76789609b43286fb07c346268642b37d27c17f3910fe mariadb-connector-c-test-debuginfo-3.4.4-2.el10_2.s390x.rpm SHA-256: dff32fbfeb3801686649ca050cfa58ff3b7f112f6d9ecd5c57c11454abb751cb mariadb-connector-c-test-debuginfo-3.4.4-2.el10_2.s390x.rpm SHA-256: dff32fbfeb3801686649ca050cfa58ff3b7f112f6d9ecd5c57c11454abb751cb Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM mariadb-connector-c-3.4.4-2.el10_2.src.rpm SHA-256: d86e7907924a27097d6b000f71ed9d8f64fc86c185d16028bf9ba06da9d58401 s390x mariadb-connector-c-3.4.4-2.el10_2.s390x.rpm SHA-256: 68c067b1eab37a223f156bfba95bef920cba84f22f0eaaff5c69b22abd7e374d mariadb-connector-c-config-3.4.4-2.el10_2.noarch.rpm SHA-256: 8b52a17f04485b8ac60f9fc875b48aa6f41ef34906c1bda5000aa0cd6ef4fd21 mariadb-connector-c-debuginfo-3.4.4-2.el10_2.s390x.rpm SHA-256: 2310a70b9f27e53db311ca888c7536524406a8b0aae73ba06405a376ce033f02 mariadb-connector-c-debuginfo-3.4.4-2.el10_2.s390x.rpm SHA-256: 2310a70b9f27e53db311ca888c7536524406a8b0aae73ba06405a376ce033f02 mariadb-connector-c-debugsource-3.4.4-2.el10_2.s390x.rpm SHA-256: 9b930deaf2e17299c8e1eaf60ffa784ea165fa93e86f9872717c56b4baa0b5a7 mariadb-connector-c-debugsource-3.4.4-2.el10_2.s390x.rpm SHA-256: 9b930deaf2e17299c8e1eaf60ffa784ea165fa93e86f9872717c56b4baa0b5a7 mariadb-connector-c-devel-3.4.4-2.el10_2.s390x.rpm SHA-256: 1686920c21edd7e3f1460e6168c47e6f485755f374745329db59ee88f71257d0 mariadb-connector-c-devel-debuginfo-3.4.4-2.el10_2.s390x.rpm SHA-256: 2979d71a4c754d13dced76789609b43286fb07c346268642b37d27c17f3910fe mariadb-connector-c-devel-debuginfo-3.4.4-2.el10_2.s390x.rpm SHA-256: 2979d71a4c754d13dced76789609b43286fb07c346268642b37d27c17f3910fe mariadb-connector-c-test-debuginfo-3.4.4-2.el10_2.s390x.rpm SHA-256: dff32fbfeb3801686649ca050cfa58ff3b7f112f6d9ecd5c57c11454abb751cb mariadb-connector-c-test-debuginfo-3.4.4-2.el10_2.s390x.rpm SHA-256: dff32fbfeb3801686649ca050cfa58ff3b7f112f6d9ecd5c57c11454abb751cb Red Hat Enterprise Linux for Power, little endian 10
A critical SQL injection vulnerability (CVE-2026-44172, CVSS 9.1) exists in the MariaDB Connector/C library due to improper handling of the big5 character set within the `mysql_real_escape_string()` function, allowing attackers to inject arbitrary SQL. The vulnerability affects mariadb-connector-c versions 3.3.18 and 3.4.8, as well as Red Hat Enterprise Linux 10.0. The advisory provides a security update rated Important; administrators should apply the referenced Red Hat patch for their specific platform.