{"id":"openSUSE-SU-2026:21409-1","summary":"Security update for mariadb-connector-c","details":"This update for mariadb-connector-c fixes the following issue:\n\n- CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438).\n\nChanges for mariadb-connector-c:\n\n- Update to release 3.4.9.\n\n- Update to release 3.4.8:\n\n * Fix compilation with GCC 15\n * CONC-762: always set is_null and length in the bind\n structure to avoid msan errors\n * CONC-763: add MySQL collation ID 309 (utf8mb4_0900_bin)\n * CONC-764: fix build of ma_context.c on Android (X18 is a\n platform-reserved register)\n * CONC-766: disable clang -Wcast-function-type-strict for\n makecontext\n","modified":"2026-07-24T18:24:23.616985119Z","published":"2026-07-22T08:23:18Z","related":["CVE-2026-44172"],"upstream":["CVE-2026-44172"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266438"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44172"}],"affected":[{"package":{"name":"mariadb-connector-c","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/mariadb-connector-c&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.9-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libmariadb_plugins":"3.4.9-160000.1.1","libmariadbprivate":"3.4.9-160000.1.1","libmariadb-devel":"3.4.9-160000.1.1","libmariadb3":"3.4.9-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21409-1.json"}}],"schema_version":"1.7.5"}