ALAS2023-2025-1331


Amazon Linux 2023 Security Advisory: ALAS2023-2025-1331
Advisory Released Date: 2026-01-07
Advisory Updated Date: 2026-01-07
Severity: Medium

Issue Overview:

A flaw was found in MariaDB. This vulnerability allows remote attackers to execute arbitrary code on affected installations via improper validation of a user-supplied path prior to using it in file operations in the mariadb-dump utility, requiring user interaction. (CVE-2025-13699)


Affected Packages:

mariadb1011


Issue Correction:
Run dnf update mariadb1011 --releasever 2023.10.20260105 or dnf update --advisory ALAS2023-2025-1331 --releasever 2023.10.20260105 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    mariadb1011-gssapi-server-debuginfo-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-cracklib-password-check-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-pam-debuginfo-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-server-utils-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-sphinx-engine-debuginfo-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-server-utils-debuginfo-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-connect-engine-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-gssapi-server-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-oqgraph-engine-debuginfo-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-debuginfo-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-connect-engine-debuginfo-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-errmsg-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-common-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-oqgraph-engine-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-client-utils-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-test-debuginfo-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-cracklib-password-check-debuginfo-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-sphinx-engine-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-backup-debuginfo-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-backup-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-pam-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-server-debuginfo-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-devel-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-server-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-debugsource-10.11.15-1.amzn2023.0.1.aarch64
    mariadb1011-test-10.11.15-1.amzn2023.0.1.aarch64

src:
    mariadb1011-10.11.15-1.amzn2023.0.1.src

x86_64:
    mariadb1011-rocksdb-engine-debuginfo-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-sphinx-engine-debuginfo-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-client-utils-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-server-utils-debuginfo-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-connect-engine-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-test-debuginfo-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-errmsg-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-connect-engine-debuginfo-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-server-debuginfo-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-debuginfo-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-pam-debuginfo-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-backup-debuginfo-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-cracklib-password-check-debuginfo-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-sphinx-engine-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-common-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-oqgraph-engine-debuginfo-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-gssapi-server-debuginfo-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-gssapi-server-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-pam-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-oqgraph-engine-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-debugsource-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-server-utils-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-cracklib-password-check-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-rocksdb-engine-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-devel-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-backup-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-server-10.11.15-1.amzn2023.0.1.x86_64
    mariadb1011-test-10.11.15-1.amzn2023.0.1.x86_64