Red Hat Product Errata RHSA-2026:47772 - Security Advisory Issued: 2026-07-29 Updated: 2026-07-29 RHSA-2026:47772 - Security Advisory Overview Updated Packages Synopsis Important: mariadb-connector-c security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for mariadb-connector-c is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The MariaDB Native Client library (C driver) is used to connect applications developed in C/C++ to MariaDB and MySQL databases. Security Fix(es): mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() (CVE-2026-44172) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.0 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.0 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2488459 - CVE-2026-44172 mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() CVEs CVE-2026-44172 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM mariadb-connector-c-3.4.4-1.el10_0.1.src.rpm SHA-256: 4360e2963d7d2689fbabee0dc858cc5d5609d2909b18f8d33648724bbaca485e x86_64 mariadb-connector-c-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: fb8d5101bef9f72cb58b4a0bbf5433868b25c06b4b847c08dc0821c8478550af mariadb-connector-c-config-3.4.4-1.el10_0.1.noarch.rpm SHA-256: 691fdacd643f0a77637dc1df26309dfd24fa3ad97e16c2f483fb8680c08eb871 mariadb-connector-c-debuginfo-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: e6744ff4d5f79f2b76280856a2f7a99e4e27980c0b8ef3cfc4a222a1064dca34 mariadb-connector-c-debuginfo-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: e6744ff4d5f79f2b76280856a2f7a99e4e27980c0b8ef3cfc4a222a1064dca34 mariadb-connector-c-debugsource-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: 9c3d3a5cc8aaee8b77a45665c61293abd752fa90f0884b3479aa8d0e3c9557bf mariadb-connector-c-debugsource-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: 9c3d3a5cc8aaee8b77a45665c61293abd752fa90f0884b3479aa8d0e3c9557bf mariadb-connector-c-devel-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: 17945670fde96df45e8ab8ea6ac8ce73ca347573d1f8fc5b8718ee5c4a623b53 mariadb-connector-c-devel-debuginfo-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: 13c8f7656a861e359a50cf56268d87253ac54b03ae4f8664c0d26982b1440fd1 mariadb-connector-c-devel-debuginfo-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: 13c8f7656a861e359a50cf56268d87253ac54b03ae4f8664c0d26982b1440fd1 mariadb-connector-c-test-debuginfo-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: ee97cddddefc83f191c92b27474a495a67a8e3611ab83cdd5de0dd3d3fe774f7 mariadb-connector-c-test-debuginfo-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: ee97cddddefc83f191c92b27474a495a67a8e3611ab83cdd5de0dd3d3fe774f7 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM mariadb-connector-c-3.4.4-1.el10_0.1.src.rpm SHA-256: 4360e2963d7d2689fbabee0dc858cc5d5609d2909b18f8d33648724bbaca485e s390x mariadb-connector-c-3.4.4-1.el10_0.1.s390x.rpm SHA-256: 2c95cebb7dabd8e7f448f6856a352fee1cfdb69f2ea3132d575a69460f221132 mariadb-connector-c-config-3.4.4-1.el10_0.1.noarch.rpm SHA-256: 691fdacd643f0a77637dc1df26309dfd24fa3ad97e16c2f483fb8680c08eb871 mariadb-connector-c-debuginfo-3.4.4-1.el10_0.1.s390x.rpm SHA-256: 244d240fa03dfcc81f374e6ac59d242ad0d582b48f3cc1fd65f75188a9b26432 mariadb-connector-c-debuginfo-3.4.4-1.el10_0.1.s390x.rpm SHA-256: 244d240fa03dfcc81f374e6ac59d242ad0d582b48f3cc1fd65f75188a9b26432 mariadb-connector-c-debugsource-3.4.4-1.el10_0.1.s390x.rpm SHA-256: 4dbb1af37cc66f246792cf7c4263ce6feafd36211be855c539ed31ae95e7a270 mariadb-connector-c-debugsource-3.4.4-1.el10_0.1.s390x.rpm SHA-256: 4dbb1af37cc66f246792cf7c4263ce6feafd36211be855c539ed31ae95e7a270 mariadb-connector-c-devel-3.4.4-1.el10_0.1.s390x.rpm SHA-256: cfa6898118246ac264296ac6edeb31a01873a6fd4b4080d077269f15ec1de976 mariadb-connector-c-devel-debuginfo-3.4.4-1.el10_0.1.s390x.rpm SHA-256: 7415ced1119021d233216a0c3829672e9e6b1a7f3ce1e4ab001340f280bbebfb mariadb-connector-c-devel-debuginfo-3.4.4-1.el10_0.1.s390x.rpm SHA-256: 7415ced1119021d233216a0c3829672e9e6b1a7f3ce1e4ab001340f280bbebfb mariadb-connector-c-test-debuginfo-3.4.4-1.el10_0.1.s390x.rpm SHA-256: a08bf6bd151c59b5f05e187b082c716da1da7f78b14e1c755571bca9a39fcade mariadb-connector-c-test-debuginfo-3.4.4-1.el10_0.1.s390x.rpm SHA-256: a08bf6bd151c59b5f05e187b082c716da1da7f78b14e1c755571bca9a39fcade Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM mariadb-connector-c-3.4.4-1.el10_0.1.src.rpm SHA-256: 4360e2963d7d2689fbabee0dc858cc5d5609d2909b18f8d33648724bbaca485e ppc64le mariadb-connector-c-3.4.4-1.el10_0.1.ppc64le.rpm SHA-256: 1bafc064e9c55d0427de68845b9427617aa8bb6720ac9763ed6dda769ea89339 mariadb-connector-c-config-3.4.4-1.el10_0.1.noarch.rpm SHA-256: 691fdacd643f0a77637dc1df26309dfd24fa3ad97e16c2f483fb8680c08eb871 mariadb-connector-c-debuginfo-3.4.4-1.el10_0.1.ppc64le.rpm SHA-256: 4d3c3711273f1812e44c8e40a356ebde0ecdc1b87dca528511347768f5479558 mariadb-connector-c-debuginfo-3.4.4-1.el10_0.1.ppc64le.rpm SHA-256: 4d3c3711273f1812e44c8e40a356ebde0ecdc1b87dca528511347768f5479558 mariadb-connector-c-debugsource-3.4.4-1.el10_0.1.ppc64le.rpm SHA-256: 74974ecad4021d130846f4a4fca7e9f1de2e106b63c38d80e24c8cf803fc4a91 mariadb-connector-c-debugsource-3.4.4-1.el10_0.1.ppc64le.rpm SHA-256: 74974ecad4021d130846f4a4fca7e9f1de2e106b63c38d80e24c8cf803fc4a91 mariadb-connector-c-devel-3.4.4-1.el10_0.1.ppc64le.rpm SHA-256: f2dcd6ea000f44ffcd5f20bc434f23339538516185721a9c9943702e4bfc9639 mariadb-connector-c-devel-debuginfo-3.4.4-1.el10_0.1.ppc64le.rpm SHA-256: 1145f3738b7fb4054123f6da4e99954081432741652cc80b479b064c22638e97 mariadb-connector-c-devel-debuginfo-3.4.4-1.el10_0.1.ppc64le.rpm SHA-256: 1145f3738b7fb4054123f6da4e99954081432741652cc80b479b064c22638e97 mariadb-connector-c-test-debuginfo-3.4.4-1.el10_0.1.ppc64le.rpm SHA-256: 24113d39b645d6adfafc68abf4c68ba114d04649998d5412e1d0405c0dca9d0d mariadb-connector-c-test-debuginfo-3.4.4-1.el10_0.1.ppc64le.rpm SHA-256: 24113d39b645d6adfafc68abf4c68ba114d04649998d5412e1d0405c0dca9d0d Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM mariadb-connector-c-3.4.4-1.el10_0.1.src.rpm SHA-256: 4360e2963d7d2689fbabee0dc858cc5d5609d2909b18f8d33648724bbaca485e aarch64 mariadb-connector-c-3.4.4-1.el10_0.1.aarch64.rpm SHA-256: 8d9e2c7498518841b1246f7d37bcc8a3d0a83a80f7b5dc4891ef582dfaa676ca mariadb-connector-c-config-3.4.4-1.el10_0.1.noarch.rpm SHA-256: 691fdacd643f0a77637dc1df26309dfd24fa3ad97e16c2f483fb8680c08eb871 mariadb-connector-c-debuginfo-3.4.4-1.el10_0.1.aarch64.rpm SHA-256: f9ecc3553c9a73979168176121c5bf54a900978f6cfd5d6c1c7e868df7e4d329 mariadb-connector-c-debuginfo-3.4.4-1.el10_0.1.aarch64.rpm SHA-256: f9ecc3553c9a73979168176121c5bf54a900978f6cfd5d6c1c7e868df7e4d329 mariadb-connector-c-debugsource-3.4.4-1.el10_0.1.aarch64.rpm SHA-256: 6b47db52b6cc9beb9fcb361101d3e2cf22942c9b8ad82f27bda67c64ae78817c mariadb-connector-c-debugsource-3.4.4-1.el10_0.1.aarch64.rpm SHA-256: 6b47db52b6cc9beb9fcb361101d3e2cf22942c9b8ad82f27bda67c64ae78817c mariadb-connector-c-devel-3.4.4-1.el10_0.1.aarch64.rpm SHA-256: 1fd69abf89e70bd14871aaa75d0e603a4acdade8227aab75216d03c2e0d97de5 mariadb-connector-c-devel-debuginfo-3.4.4-1.el10_0.1.aarch64.rpm SHA-256: 1c935c8a273e32c579f16b5cdbe671ae9b3dccbe0abea76fa052d8ba8c8214c8 mariadb-connector-c-devel-debuginfo-3.4.4-1.el10_0.1.aarch64.rpm SHA-256: 1c935c8a273e32c579f16b5cdbe671ae9b3dccbe0abea76fa052d8ba8c8214c8 mariadb-connector-c-test-debuginfo-3.4.4-1.el10_0.1.aarch64.rpm SHA-256: 88b9591323987f6659cab585bad891c99d7587fc9e827208848273aea47c7239 mariadb-connector-c-test-debuginfo-3.4.4-1.el10_0.1.aarch64.rpm SHA-256: 88b9591323987f6659cab585bad891c99d7587fc9e827208848273aea47c7239 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.0 SRPM x86_64 mariadb-connector-c-debuginfo-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: e6744ff4d5f79f2b76280856a2f7a99e4e27980c0b8ef3cfc4a222a1064dca34 mariadb-connector-c-debugsource-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: 9c3d3a5cc8aaee8b77a45665c61293abd752fa90f0884b3479aa8d0e3c9557bf mariadb-connector-c-devel-debuginfo-3.4.4-1.el10_0.1.x86_64.rpm SHA-256: 13c8f7656a861e359a50cf56268d87253ac54b03ae4f8664c0d26982b1440fd1 mariadb-connector-c-doc-3.4.4-1.el10_0.1.noarch.rpm SHA-256: 835716a656b9a5726d4e7cb183
An SQL injection vulnerability (CVE-2026-44172, CVSS 9.1 CRITICAL) exists in the MariaDB C Connector due to improper handling of the big5 character set within the `mysql_real_escape_string()` function. The vulnerability affects mariadb-connector-c versions 3.3.18 and 3.4.8, as well as Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat has released a patched version, mariadb-connector-c-3.4.4-1.el10_0.1, which should be applied immediately.