CVE-2016-6663: MariaDB
High severity, CVSS 7.0. EPSS: 4.3% chance of exploitation in the next 30 days.
Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.18; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17 allows local users with certain permissions to gain privileges by leveraging use of my_copystat by REPAIR TABLE to repair a MyISAM table.
Affected products
- MariaDB MariaDB: from 5.5.20, before 5.5.52 (fixed in 5.5.52); from 10.0.0, before 10.0.28 (fixed in 10.0.28); from 10.1.0, before 10.1.18 (fixed in 10.1.18)
- Oracle MySQL: from 5.5.0, up to and including 5.5.52; from 5.6.0, up to and including 5.6.33; from 5.7.0, up to and including 5.7.15; version 8.0 only
- Percona Percona Server: from 5.5, before 5.5.51-38.2 (fixed in 5.5.51-38.2); from 5.6, before 5.6.32-78.1 (fixed in 5.6.32-78.1); from 5.7, before 5.7.14-8 (fixed in 5.7.14-8)
- Percona Xtradb Cluster: from 5.5, before 5.5.41-37.0 (fixed in 5.5.41-37.0); from 5.6, before 5.6.32-25.17 (fixed in 5.6.32-25.17); from 5.7, before 5.7.14-26.17 (fixed in 5.7.14-26.17)
Published 2016-12-13. Last modified 2026-06-17.