Bug 33989 - MariadDB: new version 10.11.11
Summary: MariadDB: new version 10.11.11
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-02-05 20:06 CET by Marc Krämer
Modified: 2025-02-09 01:20 CET (History)
6 users (show)

See Also:
Source RPM: mariadb
CVE: CVE-2025-21490
Status comment:


Attachments

Marc Krämer 2025-02-05 20:06:54 CET

CVE: (none) => CVE-2025-21490

Comment 1 Marc Krämer 2025-02-05 20:22:27 CET
This is a usual bug fix release which fixes some memory leaks and crash fixes.


References:
https://mariadb.com/kb/en/mariadb-10-11-11-release-notes/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490
========================

Updated packages in core/updates_testing:
========================
mariadb-extra-debuginfo-10.11.11-1.mga9
mariadb-s3-engine-10.11.11-1.mga9
mariadb-s3-engine-debuginfo-10.11.11-1.mga9
mariadb-connect-10.11.11-1.mga9
mariadb-feedback-debuginfo-10.11.11-1.mga9
mariadb-spider-10.11.11-1.mga9
mariadb-bench-debuginfo-10.11.11-1.mga9
mariadb-spider-debuginfo-10.11.11-1.mga9
mariadb-connect-debuginfo-10.11.11-1.mga9
mariadb-sphinx-debuginfo-10.11.11-1.mga9
lib64mariadb3-debuginfo-10.11.11-1.mga9
mariadb-10.11.11-1.mga9
mariadb-obsolete-debuginfo-10.11.11-1.mga9
mariadb-sequence-debuginfo-10.11.11-1.mga9
lib64mariadb3-10.11.11-1.mga9
mariadb-common-core-10.11.11-1.mga9
mariadb-extra-10.11.11-1.mga9
mariadb-sphinx-10.11.11-1.mga9
mariadb-sequence-10.11.11-1.mga9
mariadb-pam-10.11.11-1.mga9
mariadb-obsolete-10.11.11-1.mga9
mariadb-feedback-10.11.11-1.mga9
mariadb-pam-debuginfo-10.11.11-1.mga9
lib64mariadb-devel-debuginfo-10.11.11-1.mga9
mysql-MariaDB-10.11.11-1.mga9
lib64mariadb-devel-10.11.11-1.mga9
mariadb-mroonga-debuginfo-10.11.11-1.mga9
mariadb-mroonga-10.11.11-1.mga9
mariadb-client-10.11.11-1.mga9
mariadb-client-debuginfo-10.11.11-1.mga9
lib64mariadbd19-10.11.11-1.mga9
mariadb-rocks-10.11.11-1.mga9
mariadb-core-10.11.11-1.mga9
lib64mariadb-embedded-devel-10.11.11-1.mga9
mariadb-debuginfo-10.11.11-1.mga9
mariadb-common-10.11.11-1.mga9
mariadb-debugsource-10.11.11-1.mga9
lib64mariadbd19-debuginfo-10.11.11-1.mga9
mariadb-core-debuginfo-10.11.11-1.mga9
mariadb-bench-10.11.11-1.mga9
mariadb-common-debuginfo-10.11.11-1.mga9
mariadb-rocks-debuginfo-10.11.11-1.mga9
lib64mariadb-embedded-devel-debuginfo-10.11.11-1.mga9

SRPM
mariadb-10.11.11-1.mga9.src.rpm

Assignee: mageia => qa-bugs

katnatek 2025-02-06 04:01:38 CET

Keywords: (none) => advisory

PC LX 2025-02-06 10:12:24 CET

CC: (none) => mageia

Morgan Leijström 2025-02-06 20:32:46 CET

CC: (none) => fri
Summary: MaridDB: new version 10.11.11 => MariadDB: new version 10.11.11

Comment 2 Herman Viaene 2025-02-07 13:40:05 CET
MGA9-64 Plasma XWayland on Compaq H000SB
No installatiion issues, omitting all debug stuff.
# systemctl start httpd
# systemctl start mysqld
# systemctl -l status mysqld
● mysqld.service - MySQL database server
     Loaded: loaded (/usr/lib/systemd/system/mysqld.service; disabled; preset: disabled)
     Active: active (running) since Fri 2025-02-07 13:29:53 CET; 15s ago
    Process: 199366 ExecStartPre=/usr/sbin/mysqld-prepare-db-dir (code=exited, status=0/SUCCESS)
   Main PID: 199380 (mysqld)
     Status: "Taking your SQL requests now..."
      Tasks: 22 (limit: 8806)
     Memory: 70.6M
        CPU: 1.123s
     CGroup: /system.slice/mysqld.service
             └─199380 /usr/sbin/mysqld

Feb 07 13:29:36 mach3.hviaene.thuis mysqld[199380]: 2025-02-07 13:29:36 0 [Note] InnoDB: Setting file './ibtmp1' size to 12.000MiB. Physically writing the f>
Feb 07 13:29:36 mach3.hviaene.thuis mysqld[199380]: 2025-02-07 13:29:36 0 [Note] InnoDB: File './ibtmp1' size is now 12.000MiB.
Feb 07 13:29:36 mach3.hviaene.thuis mysqld[199380]: 2025-02-07 13:29:36 0 [Note] InnoDB: log sequence number 63424; transaction id 34
Feb 07 13:29:36 mach3.hviaene.thuis mysqld[199380]: 2025-02-07 13:29:36 0 [Note] InnoDB: Loading buffer pool(s) from /var/lib/mysql/ib_buffer_pool
Feb 07 13:29:36 mach3.hviaene.thuis mysqld[199380]: 2025-02-07 13:29:36 0 [Note] CONNECT: Version 1.07.0002 March 22, 2021
Feb 07 13:29:36 mach3.hviaene.thuis mysqld[199380]: 2025-02-07 13:29:36 0 [Note] InnoDB: Buffer pool(s) load completed at 250207 13:29:36
Feb 07 13:29:36 mach3.hviaene.thuis mysqld[199380]: 250207 13:29:36 server_audit: MariaDB Audit Plugin version 1.4.14 STARTED.
Feb 07 13:29:53 mach3.hviaene.thuis mysqld[199380]: 250207 13:29:36 server_audit: Query cache is enabled with the TABLE events. Some table reads can be veil>
Feb 07 13:29:53 mach3.hviaene.thuis mysqld[199380]: Version: '10.11.11-MariaDB'  socket: '/var/lib/mysql/mysql.sock'  port: 0  Mageia MariaDB Server
Feb 07 13:29:53 mach3.hviaene.thuis systemd[1]: Started mysqld.service.

Then used phpmyadmin to create a new database, create a new table with primary and unique key, char field and a timestam.
Populated with some data, all worked OK.

CC: (none) => herman.viaene

Comment 3 Ulrich Beckmann 2025-02-07 15:59:28 CET
Tested with Kontact/KMail/Akonadi under KDE Plasma amd64.

$ cat ~/.local/share/akonadi/db_data/mysql.err
2025-02-07 11:21:41 0 [Note] Starting MariaDB 10.11.11-MariaDB source revision e69f8cae1a15e15b9e4f5e0f8497e1f17bdc81a4 server_uid yrk/2KwJU3yOnHsoBS5xdxZHWxo= as process 2036
2025-02-07 11:21:42 0 [Warning] option 'innodb-log-buffer-size': unsigned value 1048576 adjusted to 2097152
2025-02-07 11:21:42 0 [Note] InnoDB: Compressed tables use zlib 1.2.13
2025-02-07 11:21:42 0 [Note] InnoDB: Number of transaction pools: 1
2025-02-07 11:21:42 0 [Note] InnoDB: Using crc32 + pclmulqdq instructions
2025-02-07 11:21:42 0 [Note] InnoDB: Using Linux native AIO
2025-02-07 11:21:42 0 [Note] InnoDB: Initializing buffer pool, total size = 128.000MiB, chunk size = 2.000MiB
2025-02-07 11:21:42 0 [Note] InnoDB: Completed initialization of buffer pool
2025-02-07 11:21:42 0 [Note] InnoDB: Buffered log writes (block size=512 bytes)
2025-02-07 11:21:42 0 [Note] InnoDB: End of log at LSN=170970833
2025-02-07 11:21:43 0 [Note] InnoDB: 128 rollback segments are active.
2025-02-07 11:21:43 0 [Note] InnoDB: Setting file './ibtmp1' size to 12.000MiB. Physically writing the file full; Please wait ...
2025-02-07 11:21:43 0 [Note] InnoDB: File './ibtmp1' size is now 12.000MiB.
2025-02-07 11:21:43 0 [Note] InnoDB: log sequence number 170970833; transaction id 70140
2025-02-07 11:21:43 0 [Note] InnoDB: Loading buffer pool(s) from /home/bequimao/.local/share/akonadi/db_data/ib_buffer_pool
2025-02-07 11:21:43 0 [Note] /usr/sbin/mysqld: ready for connections.
Version: '10.11.11-MariaDB'  socket: '/run/user/1000/akonadi/mysql.socket'  port: 0  Mageia MariaDB Server
2025-02-07 11:21:46 0 [Note] InnoDB: Buffer pool(s) load completed at 250207 11:21:46
[bequimao@mga9-tst1 ~]$

Invoked as user
$ akonadictl status, ok
$ akonadictl fsck, ok

$ mysql_upgrade -u akonadi --socket=/run/user/1000/akonadi/mysql.socket, ok

No regression found,

Ulrich

CC: (none) => bequimao.de

Comment 4 PC LX 2025-02-07 23:29:08 CET
Installed and tested for 2 days without issues.

Tested with:
- mysql CLI;
- dbeaver-ce;
- mysql workstation;
- PHP scripts (e.g. wordpress, drupal, roundcubemail, nextcloud, phpmyadmin);
- Qt6 applications using the QSqlMySql plugin driver;
- network access disabled, only using unix socket.
- systemd restricted service for improved security (see override.conf file below).
All OK.



System: Mageia 9, x86_64, Intel(R) Core(TM) i5-4590 CPU @ 3.30GHz.



$ uname -a
Linux marte 6.6.74-server-1.mga9 #1 SMP PREEMPT_DYNAMIC Sat Jan 25 13:01:49 UTC 2025 x86_64 GNU/Linux
$ rpm -qa | grep mariadb | sort
lib64mariadb3-10.11.11-1.mga9
mariadb-10.11.11-1.mga9
mariadb-client-10.11.11-1.mga9
mariadb-common-10.11.11-1.mga9
mariadb-common-core-10.11.11-1.mga9
mariadb-core-10.11.11-1.mga9
mariadb-extra-10.11.11-1.mga9
$ systemctl status mysqld.service 
● mysqld.service - MySQL database server
     Loaded: loaded (/usr/lib/systemd/system/mysqld.service; enabled; preset: disabled)
    Drop-In: /etc/systemd/system/mysqld.service.d
             └─override.conf
     Active: active (running) since Fri 2025-02-07 10:00:13 WET; 12h ago
    Process: 2884701 ExecStartPre=/usr/sbin/mysqld-prepare-db-dir (code=exited, status=0/SUCCESS)
   Main PID: 2884715 (mysqld)
     Status: "Taking your SQL requests now..."
      Tasks: 11 (limit: 19018)
     Memory: 95.5M
        CPU: 28.617s
     CGroup: /system.slice/mysqld.service
             └─2884715 /usr/sbin/mysqld

fev 07 10:00:12 marte systemd[1]: Starting mysqld.service...
fev 07 10:00:12 marte mysqld[2884715]: 2025-02-07 10:00:12 0 [Warning] failed to retrieve the MAC address
fev 07 10:00:13 marte systemd[1]: Started mysqld.service.
$ cat /etc/systemd/system/mysqld.service.d/override.conf
# If "skip-networking" is set in the configuration then "AF_INET AF_INET6"
# should be removed from RestrictAddressFamilies and PrivateNetwork= should
# be set to "yes".

[Service]

PrivateNetwork=yes
PrivateUsers=yes
PrivateTmp=yes
PrivateDevices=yes
DevicePolicy=closed

UMask=0077
NoNewPrivileges=yes
LockPersonality=yes
MemoryDenyWriteExecute=yes
RemoveIPC=yes

RestrictRealtime=yes
RestrictSUIDSGID=yes
RestrictNamespaces=yes
RestrictAddressFamilies=AF_UNIX
#RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6

SystemCallArchitectures=native
SystemCallFilter=@system-service
SystemCallFilter=~ @privileged @resources

ProtectHome=yes
ProtectHostname=yes
ProtectKernelLogs=yes
ProtectClock=yes
ProtectControlGroups=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
ProtectKernelLogs=yes
ProtectSystem=strict

AmbientCapabilities=
CapabilityBoundingSet=

StateDirectory=mysql
RuntimeDirectory=mysqld
LogsDirectory=mysqld
Comment 5 Morgan Leijström 2025-02-08 14:02:30 CET
Clean update of installed packages on my workstation and three half-old laptops running x86_64 Plasma X11, tested incl qt update.
Thinkpad T510, Acer Aspire A717, Asus G75V

And on my i586 Thinkpad T43 lxqt, with all updates in testing.

I have not tested more than it installs cleanly, rebooted and all is well.
Comment 6 katnatek 2025-02-08 22:02:06 CET
Thank you for your test mageians

CC: (none) => andrewsfarm
Whiteboard: (none) => MGA9-64-OK

Comment 7 Thomas Andrews 2025-02-08 22:08:12 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 8 Mageia Robot 2025-02-09 01:20:34 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0047.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.