-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 02 Jun 2026 00:02:02 +0000 Source: mariadb Architecture: source Version: 1:11.8.8-1 Distribution: unstable Urgency: medium Maintainer: Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org> Changed-By: Otto Kekäläinen <otto@debian.org> Closes: 1104533 1109404 1110683 1126850 1137221 1138309 Changes: mariadb (1:11.8.8-1) unstable; urgency=medium . [ Otto Kekäläinen ] * New upstream version 11.8.8 with critical fix for regression in 11.8.7 as noted at https://mariadb.com/docs/release-notes/community-server/11.8/11.8.8 and for the following security issues: - CVE-2026-48165 - CVE-2026-48163 * Previous upstream version 11.8.7 included fixes for several defects as noted at https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7 as well the following security issues: - CVE-2026-44173 - CVE-2026-44172 - CVE-2026-44171 - CVE-2026-44170 - CVE-2026-44169 - CVE-2026-44168 * Also cherry-pick the following upstream debian/ changes: - MDEV-38587 slow_query_log missing from debian conf - MDEV-39031 remove Docs/README-wsrep - MDEV-34902 debian-start erroneously reports issues - MDEV-32745 Add a simple MySQL to MariaDB upgrade helper (Debian part) * Update configuration traces to match changes in system variables - new variable 'innodb-buffer-pool-in-core-dump' (default: FALSE) - new default value 0->8796093022208 in 'innodb-buffer-pool-size-max' * New upstream version included fixes for these Debian tracked issues: - MDEV-38698 Upgrade did not fix charset and collation for mysql.user, leading to "Illegal mix of collations" errors on upgrades or when trying to restore backups (Closes: #1104533, #1126850, #1137221) - MDEV-39479 Mroonga hangs on invalid index flag (Closes: #1110683) * Drop patches included upstream and refresh metadata for easier tracking * Use upstream patch from MariaDB 13.0 to use the invoking Unix user's login name instead of 'root' when running mytop (Closes: #1109404) * Re-add patch to fix build failures on x32 * Add patch to update TLS test regexes for OpenSSL 4.0 * Add upstream patch to fix "invalid iv length" with OpenSSL 4.0 (Closes: #1138309, LP: #2154856) * Remove override for deprecated Lintian tag 'exit-in-shared-library' * Salsa CI: Disable new uscan test that is not suitable for MariaDB * Include new upstream test file pam_mariadb_mtr.so * Clean away obsolete Lintian overrides * Extend spelling patch to fix new typos introduced in 11.8.7/8 * Bump Debian Policy version to 4.7.4 . [ Luca Boccassi ] * Use dh-sequence-installsysusers instead of manual dependency * d/mariadb-server.postinst: sd-sysusers is idempotent Checksums-Sha1: bc6007e753c1a06a5ed6b3dacd3ce859e85e8a6b 5637 mariadb_11.8.8-1.dsc 3d2ae312418e2f40dd14e51eefd4d7751c4c5f25 119402982 mariadb_11.8.8.orig.tar.gz 2837ef2bd5121662c891e7b1970f40042cf933b1 833 mariadb_11.8.8.orig.tar.gz.asc 64913c7a342be5e0ee12bb95226d00d57efbabd7 303436 mariadb_11.8.8-1.debian.tar.xz 9be30070e9c83f766788a3869a1ebf1119f51c9c 13794 mariadb_11.8.8-1_source.buildinfo Checksums-Sha256: 92d2ce77abb8a895977299ef878969749b88c22cf8f53b1661a31188f7514aa4 5637 mariadb_11.8.8-1.dsc bd023a4959faf012db7f0ebfc0d276729e67e5443df193163f98d80fdfc524c9 119402982 mariadb_11.8.8.orig.tar.gz 12601a392e99fc15abd5c03abe3b5217d50e8a8578fc93fd3a6cd871552e6065 833 mariadb_11.8.8.orig.tar.gz.asc 01fff8e0ce19920d371f11a2eb623e3a72952ea415602186816621ddf3c48fb8 303436 mariadb_11.8.8-1.debian.tar.xz 0384f337cc2e46c423df9e650f0313c0f119e3b65145ed92cfc52ef7d258dda8 13794 mariadb_11.8.8-1_source.buildinfo Files: fef480e5cf3a9f5c726e8837627d1096 5637 database optional mariadb_11.8.8-1.dsc 2d28267407373d2771127eec3416b043 119402982 database optional mariadb_11.8.8.orig.tar.gz a1ba25c9186dc62e45542dc79d79bc4f 833 database optional mariadb_11.8.8.orig.tar.gz.asc 575d5b1489c3cf664a5f0d3b037ed036 303436 database optional mariadb_11.8.8-1.debian.tar.xz 99d883e700a7deb219046df18ee7b905 13794 database optional mariadb_11.8.8-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmbRSsR88dMO0U+RvvthEn87o2ogFAmoj2VEACgkQvthEn87o 2oiCXg//RZwGvnptKxT2bGFWmtu83Pc/yFRiArXlY2cQLz/e//3VgWa86h29Jtnb X0fY9jUzg3Rpc1ndL4xsXZ2qNhg8wuQV8DkRtkLie0JJ8cYWr7wIZSS1kA2x+3UH 0+uHvprgTtWNk9V8jmMNGMqbjF2dmES17/duOo+6DgtvWPkhV+8ieRFzIO6ZIYzg ZFrIMzvvi5vsPrxRbEJ2CDanviMvkq9gYK8h3VUnij1qECOK3FBluK1OByIILBSA hHEY7jTUzJs6PKFdvgkEYKS3RleGrAFJFLFKHShZhqp30ozpyMJhclkCERYAA6Z3 wiDJbnyVtQMZXFJwoBAMTT1+GbNFKrzogJZyexqgW82hsqO+klvD+z+/L8OmKF7o lpoHglwTah1xdwJQz56tNETis+AXhpGqUPwmaQhcLJpZK/+p4aRJcFVZszFnGqKy V6fw9fcMAaoasN7l8RdPGIcnh3PKatepVBK3CCJ2zu0JG9I2Jww5xRp8XcoDPgXw KYAi5IllPgu60m7av10b5YO3DADpjQeAt0RwiaPTI8Y/tJKgTsVxV9lVEAdxsh3J 9mts43v1ZP/mdtMgiWazdCfq9xJai1RoQ255cczVieRovoj62gHMgQUpPOGLOoPr P1pqvFDcoopYEt1pF8U6E5d+PoIFhIb2QrL3u8JED1/kbJkh4RM= =dy0q -----END PGP SIGNATURE-----