vulnerability

Amazon Linux 2023: CVE-2025-13699: Medium priority package update for mariadb1011

Severity
6
CVSS
(AV:L/AC:H/Au:N/C:C/I:C/A:C)
Published
Nov 27, 2025
Added
Jan 12, 2026
Modified
Jan 12, 2026

Description

A flaw was found in MariaDB. This vulnerability allows remote attackers to execute arbitrary code on affected installations via improper validation of a user-supplied path prior to using it in file operations in the mariadb-dump utility, requiring user interaction.

Solutions

amazon-linux-2023-upgrade-mariadb1011amazon-linux-2023-upgrade-mariadb1011-backupamazon-linux-2023-upgrade-mariadb1011-backup-debuginfoamazon-linux-2023-upgrade-mariadb1011-client-utilsamazon-linux-2023-upgrade-mariadb1011-commonamazon-linux-2023-upgrade-mariadb1011-connect-engineamazon-linux-2023-upgrade-mariadb1011-connect-engine-debuginfoamazon-linux-2023-upgrade-mariadb1011-cracklib-password-checkamazon-linux-2023-upgrade-mariadb1011-cracklib-password-check-debuginfoamazon-linux-2023-upgrade-mariadb1011-debuginfoamazon-linux-2023-upgrade-mariadb1011-debugsourceamazon-linux-2023-upgrade-mariadb1011-develamazon-linux-2023-upgrade-mariadb1011-errmsgamazon-linux-2023-upgrade-mariadb1011-gssapi-serveramazon-linux-2023-upgrade-mariadb1011-gssapi-server-debuginfoamazon-linux-2023-upgrade-mariadb1011-oqgraph-engineamazon-linux-2023-upgrade-mariadb1011-oqgraph-engine-debuginfoamazon-linux-2023-upgrade-mariadb1011-pamamazon-linux-2023-upgrade-mariadb1011-pam-debuginfoamazon-linux-2023-upgrade-mariadb1011-rocksdb-engineamazon-linux-2023-upgrade-mariadb1011-rocksdb-engine-debuginfoamazon-linux-2023-upgrade-mariadb1011-serveramazon-linux-2023-upgrade-mariadb1011-server-debuginfoamazon-linux-2023-upgrade-mariadb1011-server-utilsamazon-linux-2023-upgrade-mariadb1011-server-utils-debuginfoamazon-linux-2023-upgrade-mariadb1011-sphinx-engineamazon-linux-2023-upgrade-mariadb1011-sphinx-engine-debuginfoamazon-linux-2023-upgrade-mariadb1011-testamazon-linux-2023-upgrade-mariadb1011-test-debuginfo
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.