CVE-2016-6664: MariaDB

High severity, CVSS 7.0. EPSS: 3% chance of exploitation in the next 30 days.

mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.

Affected products

  • MariaDB MariaDB: from 5.5.0, before 5.5.54 (fixed in 5.5.54); from 10.0.0, before 10.0.29 (fixed in 10.0.29); from 10.1.0, before 10.1.21 (fixed in 10.1.21)
  • Oracle MySQL: from 5.5.0, up to and including 5.5.51; from 5.6.0, up to and including 5.6.32; from 5.7.0, up to and including 5.7.14
  • Percona Percona Server: from 5.5, before 5.5.51-38.2 (fixed in 5.5.51-38.2); from 5.6, before 5.6.32-78.1 (fixed in 5.6.32-78.1); from 5.7, before 5.7.14-8 (fixed in 5.7.14-8)
  • Percona Xtradb Cluster: from 5.5, before 5.5.41-37.0 (fixed in 5.5.41-37.0); from 5.6, before 5.6.32-25.17 (fixed in 5.6.32-25.17); from 5.7, before 5.7.14-26.17 (fixed in 5.7.14-26.17)

Published 2016-12-13. Last modified 2026-06-17.