vulns.co
/
GKData.io MCP

MEMemory safety and parser contracts · 2 min read

MariaDB JSON normalization exceeded allocated buffer capacity

The organizer awarded Team Xint Code USD 30,000 for this individually identified ZeroDay.cloud 2025 competition entry.

Read the primary source MEMemory safety and parser contractsReviewed 2026-10-02

Root cause

JSON normalization copied variable-length text into an undersized allocation. The fix uses storage management that grows the buffer to fit the value.

Demonstrated impact

An authenticated database user could crash the server. The researcher demonstrated code execution at the event; the vendor-authored CVE record qualifies that outcome as dependent on unusually controlled memory conditions, generally associated with a lab.

Lessons for review

  • Make input length and allocated capacity explicit invariants in normalization code.
  • Prefer capacity-aware storage operations and safe local regression coverage.
  • Separate a controlled demonstration from deployment-wide impact claims.

Award and evidence

USD 30,000Competition Award · Organizer Confirmed

One entry award, excluding the team’s other database entries. The results use $; USD denomination is contextualized by the organizer’s current rules, which concern 2026 rather than an archived 2025 rules snapshot. No conversion or cash-settlement claim is made.

Read the named researcher report, organizer CVE tracker and per-entry award result; cross-checked vendor advisories and CNA records. Currency context is explicitly distinguished from award evidence. No vulnerability testing performed.

  • Vendor CVE wording conditions code execution on tight memory control generally obtainable in a lab; do not infer reliable production-wide compromise.
  • Vendor advisory also lists patched 12.2.2, beyond the two release series emphasized in the research article. The February 4 fix date refers to the reviewed 11.4.10 release.
  • The article shows May 4 without a year; 2026 is inferred from its explicitly dated remediation timeline.
  • Exact award decision and funds-transfer dates are not reported; December 16 is the dated organizer announcement.
  • Current rules establish program US-dollar notation but are not an archived snapshot of the 2025 rules.

Recorded timeline

Published
2026-05-04inferred · Displayed May 4; year inferred from the completed 2026 remediation timeline.
Public Disclosure
2025-12-11explicit · Public competition demonstration. Subsequent CVE/advisory publication and full technical article are separate events.
Reported
2025-12-11explicit · Researcher timeline explicitly dates the report and vendor acknowledgement.
Fixed
2026-02-04explicit · Vendor patch release, not proof of deployment by every customer.
Award Announced
2025-12-16explicit · Dated organizer recap announces the exact entry award; decision and transfer dates remain unknown.

Sources and provenance

  1. CVE-2026-32710: MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE Team Xint Code / ZeroDay.cloud · reviewed 2026-10-02
  2. ZeroDay.cloud 2025 individual competition results Nir Ohfeld / Wiz Research · reviewed 2026-10-02
  3. ZeroDay.cloud vulnerability tracker Wiz / ZeroDay.cloud · reviewed 2026-10-02
  4. ZeroDay.cloud current rules: US-dollar denomination Wiz · reviewed 2026-10-02
  5. MariaDB heap-based buffer overflow in JSON_SCHEMA_VALID MariaDB · reviewed 2026-10-02
  6. CVE-2026-32710 CNA record GitHub CNA, MariaDB advisory / CVE Program · reviewed 2026-10-02
  7. MariaDB 11.4.10 release notes MariaDB · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software