HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2016-6663

CVSS 7.0v3.0pub. 2016-12-13upd. 2026-05-06

Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.18; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17 allows local users with certain permissions to gain privileges by leveraging use of my_copystat by REPAIR TABLE to repair a MyISAM table.

CVSS Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • MariaDB

    APP
    Mariadb
    10.1.0 – 10.1.18 (excl.)10.0.0 – 10.0.28 (excl.)5.5.20 – 5.5.52 (excl.)
  • Oracle MySQL

    APP
    Oracle
    8.05.5.0 – 5.5.525.6.0 – 5.6.335.7.0 – 5.7.15
  • Percona Server

    APP
    Percona
    5.7 – 5.7.14-8 (excl.)5.6 – 5.6.32-78.1 (excl.)5.5 – 5.5.51-38.2 (excl.)
  • Percona Xtradb Cluster

    APP
    Percona
    5.6 – 5.6.32-25.17 (excl.)5.7 – 5.7.14-26.17 (excl.)5.5 – 5.5.41-37.0 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Race Condition
CWE
References

Related vulnerabilities

CVE-2026-49261CRITICAL10.0PL ✓same product

MariaDB: command injection przez wsrep_notify_cmd w nazwie węzła Galera

CVE-2023-26785CRITICAL9.8PL ✓same product

MariaDB v10.5 — RCE przez UDF w plikach współdzielonych (disputed)

CVE-2020-15180CRITICAL9.0PL ✓same product

Command injection w MariaDB mysql-wsrep via wsrep_sst_method

CVE-2020-26542CRITICAL9.8PL ✓same product

Pominięcie uwierzytelnienia LDAP w Percona Server przez puste hasło

CVE-2020-11656CRITICAL9.8PL ✓same product

Use-after-free w SQLite — błąd implementacji ALTER TABLE