CVE-2016-5617 is a rejected CVE reservation duplicated by CVE-2016-6664 and should not be used independently. The underlying issue was unsafe error-log-file handling in MySQL and MariaDB mysqld_safe. When mysqld_safe operated with elevated privileges, a local mysql operating-system user could abuse error-log creation and symbolic-link handling to cause unsafe file operations. Initial MySQL corrections were incomplete and remained susceptible to races, arbitrary log-path handling, and log writes through symbolic links.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Insecure mysqld_safe error-log-file handling allowing the mysql OS user to escalate privileges to root.
Insecure error-log file handling in MySQL mysqld_safe, addressed in the Red Hat MariaDB 10.1.29 update.
Insecure error-log file handling in mysqld_safe enables local privilege escalation from the mysql OS account to root.
An unspecified vulnerability in the MySQL Server Error Handling component.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.