Red Hat Patches MariaDB Connector C Flaw Allowing SQL Injection Through Big5 Character Handling
Red Hat has published security advisory RHSA-2026:75673, an update for the mariadb-connector-c package on Red Hat Enterprise Linux 9, issued and updated on 5 October 2026. The advisory addresses CVE-2026-44172, an SQL injection weakness arising from improper handling of the big5 character set when the mysql_real_escape_string() function is used. Red Hat Product Security has rated the update as Important. The affected component is the MariaDB Native Client library, the C driver that applications written in C and C++ use to connect to MariaDB and MySQL databases, which means the exposure sits in the client layer rather than in a single application. The affected product list is broad and covers Red Hat Enterprise Linux 9 and the 9.8 Extended Update Support, Update Services for SAP Solutions, four-years-of-updates and Extended Life Cycle streams across x86_64, ppc64le, s390x and aarch64, along with the matching CodeReady Linux Builder repositories.
mysql_real_escape_string() is the routine that C and C++ developers call to neutralise user-supplied values before they are concatenated into an SQL statement, so a defect in that function undermines the exact control an application is relying on. According to the advisory, the flaw lies in how the library handles the big5 multibyte character set, a legacy Traditional Chinese encoding in which certain byte sequences can be interpreted differently depending on whether they are read as single bytes or as multibyte characters. Red Hat has not published a step-by-step exploitation chain, a proof-of-concept, or an attacker profile in this errata, and the full severity breakdown and CVSS base score are held on the linked CVE page rather than in the advisory text. What the advisory does state plainly is the outcome: input that an application believes it has escaped can still be treated as SQL syntax, producing an injection condition. The issue is tracked internally as Bugzilla 2488459, and the fixed build is mariadb-connector-c-3.2.6-2.el9_8, shipped as source, runtime, config, devel, test and debuginfo RPMs for every supported architecture.
The strategic weight of this issue comes from where the library sits. A client driver is a shared dependency, so a single flawed package can simultaneously weaken many unrelated applications on the same host, including middleware, reporting tools and in-house C or C++ services that nobody considers a database product. Any of those applications that accepts untrusted input and uses the connector's escaping function while operating against a big5 connection inherits the weakness regardless of how carefully its own code was written, and successful injection in that position can expose stored records, alter data, or extend an attacker's reach into back-end systems. The practical exposure is narrowed by the character set dependency, since environments that never use big5 are far less likely to encounter the condition, but estates running legacy regional applications or inherited database connections with non-default encodings cannot assume that. On current exploitation status, FIRST EPSS places CVE-2026-44172 at a 1.0 percent probability of exploitation in the next 30 days, and neither the advisory nor the authoritative evidence available to us records confirmed exploitation in the wild. Red Hat also notes that its Lightspeed patch analysis can identify systems affected by this advisory, and that more recent versions of the listed packages may already be available.
Attack Surface
Database, Web Application, Server OS
Tactics
Initial Access, Collection, Impact
Techniques
- T1190 – Exploit Public-Facing Application
- T1213 – Data from Information Repositories
- T1565.001 – Stored Data Manipulation
SuperPRO's Threat Countermeasures Procedures
- Update mariadb-connector-c to 3.2.6-2.el9_8 or later on all Red Hat Enterprise Linux 9 hosts, including the 9.8 Extended Update Support, Update Services for SAP Solutions, four-years-of-updates and Extended Life Cycle streams, using dnf update mariadb-connector-c mariadb-connector-c-config.
- Inventory exposure before patching with rpm -q mariadb-connector-c mariadb-connector-c-devel across x86_64, ppc64le, s390x and aarch64 estates, and include CodeReady Linux Builder hosts where mariadb-connector-c-devel-3.2.6-2.el9_8 is installed for build pipelines.
- Rebuild and redeploy any in-house C or C++ binaries that statically link or vendor the MariaDB Native Client library, since replacing the system RPM alone will not remediate applications shipping their own copy of the vulnerable 3.2.6 code.
- Identify database connections negotiating the big5 character set by running SHOW VARIABLES LIKE 'character_set%' and SELECT @@character_set_client, @@character_set_connection, @@character_set_results on each MariaDB and MySQL instance, and by checking for default-character-set=big5 entries in /etc/my.cnf and /etc/my.cnf.d/ client configuration files, prioritising patching for the application servers that return big5, as CVE-2026-44172 depends on big5 handling in mysql_real_escape_string().
- Replace mysql_real_escape_string() based query construction with prepared statements using mysql_stmt_prepare() and mysql_stmt_bind_param() in application code, so that escaping defects in the client driver cannot translate into injectable SQL.
- Use the Red Hat Lightspeed patch analysis feature referenced in RHSA-2026:75673 to enumerate subscribed systems still reporting as affected, and track remediation against Bugzilla 2488459 until all listed architectures are clear.
- Enable and review MariaDB general or audit log output for malformed multibyte sequences and unexpected statement structures such as stacked queries or UNION fragments originating from application service accounts, and alert on those patterns while the patch is being rolled out.