Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-39565

missing filename check in mariadb-backup --decompress

    XMLWordPrintable

Details

    • Can result in unexpected behaviour
    • Q2/2026 Server Development

    Description

      mariadb-backup did not verify that the *.qp files were valid table tables before invoking qpress.
      This allowed filenames with embedded shell metacharacters that normally can never be present within a backup.

      Reported by Sean Nejad.

      Attachments

        Activity

          People

            serg Sergei Golubchik
            serg Sergei Golubchik
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - 0d
                0d
                Remaining:
                Remaining Estimate - 0d
                0d
                Logged:
                Time Spent - 0.25d
                0.25d

                Git Integration

                  Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.