- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Otto Kekäläinen
- Date:
- 2026-07-16 09:29:01 UTC
- Severity:
- normal
- Tags:
Changelog:
mariadb (1:11.8.8-0+deb13u1) trixie; urgency=medium
* New upstream version 11.8.8 with critical fix for regression in 11.8.7 as
noted at https://mariadb.com/docs/release-notes/community-server/11.8/11.8.8
and for the following security issues:
- CVE-2026-48165
- CVE-2026-48163
* Previous upstream version 11.8.7 included fixes for several defects as noted
at https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7 as
well the following security issues:
- CVE-2026-44173
- CVE-2026-44172
- CVE-2026-44171
- CVE-2026-44170
- CVE-2026-44169
- CVE-2026-44168
* New upstream version included fixes for these Debian tracked issues:
- MDEV-38698 Upgrade did not fix charset and collation for mysql.user,
leading to "Illegal mix of collations" errors on upgrades or when trying
to restore backups (Closes: #1104533, #1126850, #1137221)
- MDEV-39479 Mroonga hangs on invalid index flag (Closes: #1110683)
- MDEV-38811 Crash in information_schema.table_constraints when running in
'skip-grant-tables' mode (Closes: #1127431, affected Akonadi)
* Update configuration traces to match changes in system variables
- new variable 'innodb-buffer-pool-in-core-dump' (default: FALSE)
- new default value 0->8796093022208 in 'innodb-buffer-pool-size-max'
* Salsa CI: Disable the uscan job as it is incompatible with MariaDB
Final debdiff can be posed only once MR at
https://salsa.debian.org/mariadb-team/mariadb-server/-/merge_requests/163
is finalized and approved.
package release.debian.org tags 1140853 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: mariadb Version: 11.8.8-0+deb13u1 Explanation: new upstream stable release; fix code execution issues [CVE-2026-44168 CVE-2026-48163 CVE-2026-48165]; fix authorization bypass [CVE-2026-44169]; fix shell interpolation vulnerability [CVE-2026-44170]; fix path traversal issue [CVE-2026-44171]; fix SQL injection issue [CVE-2026-44172]; fix incomplete privilege check issue [CVE-2026-44173]; fix "Illegal mix of collations" error; fix "Mroonga hangs on invalid index flag"; fix crash in information_schema.table_constraints
package release.debian.org tags 1140853 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: mariadb Version: 11.8.8-0+deb13u1 Explanation: new upstream stable release; fix code execution issues [CVE-2026-44168 CVE-2026-48163 CVE-2026-48165]; fix authorization bypass [CVE-2026-44169]; fix shell interpolation vulnerability [CVE-2026-44170]; fix path traversal issue [CVE-2026-44171]; fix SQL injection issue [CVE-2026-44172]; fix incomplete privilege check issue [CVE-2026-44173]; fix "Illegal mix of collations" error; fix "Mroonga hangs on invalid index flag"; fix crash in information_schema.table_constraints
Santiago is very fast at reporting FTBFS regressions, and the filing fits with being caused by the upload of 1:11.8.8-1 to unstable. I can reproduce in trixie that libdbd-mariadb-perl builds with 1:11.8.6-0+deb13u1 from stable but does FTBFS with 1:11.8.8-0+deb13u1 from pu. In both unstable and stable the autopkgtest shows the same failures and blames mariadb 11.8.8 (but only neutral due to flaky): https://ci.debian.net/packages/libd/libdbd-mariadb-perl/testing/amd64/ https://ci.debian.net/packages/libd/libdbd-mariadb-perl/stable/amd64/ While building locally there was always a stray mysqld process left after the build (only with 11.8.8), this is also seen in reproducible: https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/libdbd-mariadb-perl.html W: Stray processes left from build: ... CGroup: /system.slice/system-pbuilder.slice/system-pbuilder-build.slice/system-pbuilder-build-libdbd\x2dmariadb\x2dperl_1.22\x2d1.slice/system-pbuilder-build-libdbd\x2dmariadb\x2dperl_1.22\x2d1-2487514.slice `-run-p2505164-i40247590.scope `-2509485 /usr/sbin/mysqld --no-defaults --user=pbuilder1 --socket=/build/reproducible-path/libdbd-mariadb-perl-1.22/t/testdb/mysql.sock --datadir=/build/reproducible-path/libdbd-mariadb-perl-1.22/t/testdb --pid-file=/build/reproducible-path/libdbd-mariadb-perl-1.22/t/testdb/mysql.pid --explicit_defaults_for_timestamp --skip-networking The most urgent question is whether this is a MariaDB regression that should result in excluding 1:11.8.8-0+deb13u1 from the point release. cu Adrian
On 08 juil. 2026 12:36, Adrian Bunk <bunk@debian.org> wrote: [...] Bad idea to have 11.8.8 to stable. This version is broken, even if MyhTV isn't in debian : https://forum.mythtv.org/viewtopic.php?p=31030 https://www.deb-multimedia.org/lurker/message/20260707.153854.696f4834.en.html Christian
Hi Gregor, I noticed you pushed a commit to https://salsa.debian.org/perl-team/modules/packages/libdbd-mariadb-perl/-/commits/master two weeks ago and saw that the post-build tests started to fail. Did you investigate the failures? Do you see what is the root cause to these failing? not ok 140 - NoChopBlanks: c_text should not have blanks chopped not ok 141 - NoChopBlanks: c_tinytext should not have blanks chopped not ok 142 - NoChopBlanks: c_mediumtext should not have blanks chopped not ok 143 - NoChopBlanks: c_longtext should not have blanks chopped not ok 144 - NoChopBlanks: b_blob should not have blanks chopped not ok 145 - NoChopBlanks: b_tinyblob should not have blanks chopped not ok 146 - NoChopBlanks: b_mediumblob should not have blanks chopped not ok 147 - NoChopBlanks: b_longblob should not have blanks chopped ... not ok 11 ... Test Summary Report ------------------- t/50chopblanks.t (Wstat: 2048 (exited 8) Tests: 180 Failed: 8) Failed tests: 140-147 Non-zero exit status: 8 t/rt118977-zerofill.t (Wstat: 256 (exited 1) Tests: 12 Failed: 1) Failed test: 11 Non-zero exit status: 1 Files=94, Tests=4136, 54 wallclock secs ( 0.77 usr 0.19 sys + 9.22 cusr 1.91 csys = 12.09 CPU) Result: FAIL Failed 2/94 test programs. 9/4136 subtests failed. Clearly this is related to some change in libmariadb3 from 11.8.8 but we would need find out some more details to be able to poinpoint what change it was, or at least have enough data to file a bug upstream. I was wondering if you were already aware of something as you saw the build failure some weeks ago.
Hi! I added the new test failures to d/changelog. And then I looked around a bit but didn't find anything, sorry … Cheers, gregor
mariadb 1:11.8.8-0+deb13u1 will be skipped for 13.6 and remain in proposed-updates for fixes to join it in 13.7.