Debian Package Tracker
Register | Log in
Subscribe

mariadb-connector-java

Java database driver for MariaDB and MySQL

Choose email to subscribe with

general
  • source: mariadb-connector-java (main)
  • version: 3.5.10-1
  • maintainer: Debian Java Maintainers (archive) (DMD)
  • uploaders: Emmanuel Bourg [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.7.2-1
  • oldstable: 2.7.6-1
  • stable: 2.7.6-1
  • testing: 2.7.6-1
  • unstable: 3.5.10-1
versioned links
  • 2.7.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.7.6-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.5.10-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libmariadb-java (1 bugs: 0, 1, 0, 0)
action needed
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-61700: MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, ClientMessage.readPacket processes a server-initiated LOCAL INFILE protocol packet 0xfb without enforcing allowLocalInfile=false. When an application sends a LOAD DATA LOCAL INFILE COM_QUERY, a rogue or man-in-the-middle server can echo the same filename and cause the connector to transmit that file despite the disabled option. The server cannot redirect the request to an arbitrary path and can receive only the exact file already selected by the application, so exploitation requires an application that actively loads sensitive data over an untrusted connection. This issue is fixed in versions 2.7.14, 3.3.5, 3.4.3, and 3.5.9.
Created: 2026-09-26 Last update: 2026-09-28 00:00
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-61700: MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, ClientMessage.readPacket processes a server-initiated LOCAL INFILE protocol packet 0xfb without enforcing allowLocalInfile=false. When an application sends a LOAD DATA LOCAL INFILE COM_QUERY, a rogue or man-in-the-middle server can echo the same filename and cause the connector to transmit that file despite the disabled option. The server cannot redirect the request to an arbitrary path and can receive only the exact file already selected by the application, so exploitation requires an application that actively loads sensitive data over an untrusted connection. This issue is fixed in versions 2.7.14, 3.3.5, 3.4.3, and 3.5.9.
Created: 2026-09-26 Last update: 2026-09-28 00:00
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-61700: (needs triaging) MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, ClientMessage.readPacket processes a server-initiated LOCAL INFILE protocol packet 0xfb without enforcing allowLocalInfile=false. When an application sends a LOAD DATA LOCAL INFILE COM_QUERY, a rogue or man-in-the-middle server can echo the same filename and cause the connector to transmit that file despite the disabled option. The server cannot redirect the request to an arbitrary path and can receive only the exact file already selected by the application, so exploitation requires an application that actively loads sensitive data over an untrusted connection. This issue is fixed in versions 2.7.14, 3.3.5, 3.4.3, and 3.5.9.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-09-26 Last update: 2026-09-28 00:00
testing migrations
  • excuses:
    • Migration status for mariadb-connector-java (2.7.6-1 to 3.5.10-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for jaydebeapi/1.2.3-2: amd64: No tests, superficial or marked flaky ♻ (reference ♻), arm64: No tests, superficial or marked flaky ♻ (reference ♻), armhf: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻ (reference ♻), ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), riscv64: No tests, superficial or marked flaky ♻ (reference ♻), s390x: Test triggered
    • ∙ ∙ Autopkgtest for osmosis/0.49.2-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Too young, only 2 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/m/mariadb-connector-java.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-09-27] Accepted mariadb-connector-java 3.5.10-1 (source) into unstable (Emmanuel Bourg)
  • [2026-09-26] Accepted mariadb-connector-java 2.7.15-1 (source) into unstable (Emmanuel Bourg)
  • [2022-09-07] mariadb-connector-java 2.7.6-1 MIGRATED to testing (Debian testing watch)
  • [2022-09-04] Accepted mariadb-connector-java 2.7.6-1 (source) into unstable (tony mancill)
  • [2022-06-20] mariadb-connector-java 2.7.5-1 MIGRATED to testing (Debian testing watch)
  • [2022-06-15] Accepted mariadb-connector-java 2.7.5-1 (source) into unstable (tony mancill)
  • [2021-09-22] mariadb-connector-java 2.7.4-1 MIGRATED to testing (Debian testing watch)
  • [2021-09-17] Accepted mariadb-connector-java 2.7.4-1 (source) into unstable (Emmanuel Bourg)
  • [2021-03-11] mariadb-connector-java 2.7.2-1 MIGRATED to testing (Debian testing watch)
  • [2021-02-28] Accepted mariadb-connector-java 2.7.2-1 (source) into unstable (Emmanuel Bourg)
  • [2021-01-23] mariadb-connector-java 2.7.1-1 MIGRATED to testing (Debian testing watch)
  • [2021-01-18] Accepted mariadb-connector-java 2.7.1-1 (source) into unstable (Emmanuel Bourg)
  • [2020-09-16] mariadb-connector-java 2.6.2-1 MIGRATED to testing (Debian testing watch)
  • [2020-09-10] Accepted mariadb-connector-java 2.6.2-1 (source) into unstable (Emmanuel Bourg)
  • [2020-01-31] mariadb-connector-java 2.5.3-1 MIGRATED to testing (Debian testing watch)
  • [2020-01-26] Accepted mariadb-connector-java 2.5.3-1 (source) into unstable (Emmanuel Bourg)
  • [2019-07-20] mariadb-connector-java 2.4.2-1 MIGRATED to testing (Debian testing watch)
  • [2019-07-15] Accepted mariadb-connector-java 2.4.2-1 (source) into unstable (Emmanuel Bourg)
  • [2018-09-26] mariadb-connector-java 2.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2018-09-20] Accepted mariadb-connector-java 2.3.0-1 (source) into unstable (Emmanuel Bourg)
  • [2018-08-18] mariadb-connector-java 2.2.5-1 MIGRATED to testing (Debian testing watch)
  • [2018-08-13] Accepted mariadb-connector-java 2.2.5-1 (source all) into unstable, unstable (Emmanuel Bourg)
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.7.6-1build1
  • 1 bug

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing