OSSEVA FOR MARIADB

MariaDB 10.6 is past its community date. Keep it patched.

Community maintenance for MariaDB 10.6 ended on 6 July 2026, and 10.5 a year earlier. OSSeva ships patched, signed builds of the MariaDB Server you already run, supports every current LTS line beside them, and puts MariaDB under the same contract as the rest of your data and messaging stack.

Last reviewed

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why now

10.6 left community maintenance on 6 July 2026

The MariaDB Foundation's maintenance table gives 10.6 a community end-of-life date of 6 July 2026, five years after its GA on 6 July 2021. 10.5 ended on 24 June 2025 and 10.4 on 18 June 2024. Estates still on those lines need an upgrade, a commercial enterprise subscription, or a patched build.

Community LTS windows are getting shorter

Up to 11.4, community LTS binaries were published for five years after GA. From 11.8 the Foundation publishes them for three years, with critical and security fixes available in source form for two more. 11.8 binaries end on 4 June 2028, earlier than 11.4's 29 May 2029. Longer maintenance from the vendor means an enterprise subscription.

Rolling releases move every quarter

Alongside one LTS a year, MariaDB ships rolling releases quarterly, and each is maintained only for a short window: 13.0 from May 2026 to the fourth quarter of 2026. Teams that adopted a rolling release for a feature are on a quarterly upgrade cycle whether they planned for one or not.

MariaDB and MySQL under one contract

MariaDB often runs next to MySQL, PostgreSQL, Redis or Valkey and Kafka, each with its own support arrangement. OSSeva covers all of them with one contract, one renewal date and one escalation path, priced per cluster rather than per core, so adding servers does not reprice the contract.

Versions covered

All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.

VersionStatusActive CVEs
10.4.x(Community EOL, OSSeva patched)ExtendedClean
10.5.x(Community EOL, OSSeva patched)ExtendedClean
10.6.x(Community EOL, OSSeva patched)ExtendedClean
10.11.x(LTS)CurrentClean
11.4.x(LTS)CurrentClean
11.8.x(LTS, three-year community binaries)CurrentClean
12.3.x(Newest LTS, recommended upgrade target)CurrentClean
13.x rolling(Rolling release; supported on Assure and Operate, no patched builds)CurrentClean
Every MariaDB version and end-of-life date →

What you get

Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.

OSSeva Patch

Backported security fixes for MariaDB lines past community end of life.

  • Patched builds for 10.4, 10.5 and 10.6 in step with the quarterly MariaDB release cycle
  • Signed DEB and RPM packages, tarballs and container images
  • Same series, same data directory, same configuration
  • CVE notifications with the fix status for your lines
  • Upgrade planning to 11.8 or 12.3
  • 24/7 managed operations
Get started →
Most popular

OSSeva Assure

Patches plus upgrade planning, configuration review and audit evidence.

  • Everything in Patch
  • Upgrade plan from 10.x to a current LTS, rehearsed with mariadb-upgrade
  • Galera Cluster and replication topology review
  • MySQL-to-MariaDB and MariaDB-to-MySQL compatibility assessment
  • Compliance evidence: SBOMs and CVE remediation records
  • 24/7 managed operations
Get started →

OSSeva Operate

Day-to-day operations for your MariaDB fleet, run by DBAs.

  • Everything in Assure
  • Critical CVEs (CVSS ≥ 9.0) patched within 48 hours and High within 7 days
  • 24/7 Galera, replication and backup monitoring
  • 15-minute P1 incident response SLA
  • Rolling upgrades executed node by node
  • Quarterly capacity and performance reviews
Get started →

All tiers priced per cluster/application — not per core. Contact for pricing →

How it installs

OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.

SQL: identify the series and Galera state on each nodesql
SELECT VERSION();

-- On Galera nodes: cluster size and whether this node is synced
SHOW GLOBAL STATUS WHERE Variable_name IN ('wsrep_cluster_size', 'wsrep_local_state_comment');
Upgrade: run mariadb-upgrade after installing new binariesbash
sudo systemctl stop mariadb
# install the new MariaDB packages, then:
sudo systemctl start mariadb
sudo mariadb-upgrade --verbose

Migrate from MariaDB enterprise subscriptions

Keep your binaries, change your support. OSSeva takes over support for the MariaDB Community Server you run today with no migration, including lines that have left community maintenance, then ships its own patched builds on your schedule. If you rely on enterprise-only builds or tooling, we say so before you sign.

↗

Pricing model

OSSeva for MariaDB is priced per cluster, not per core or per server. Book a discovery call for a quote.

Compliance library

📄SOC 2 compliance evidence package
Request →
📄Sample Audit Narrative
Request →
📄Pen-Test Report Summary
Request →
📄HIPAA Technical Safeguard Matrix
Request →

Frequently asked questions

What is the MariaDB support lifecycle?

The MariaDB Foundation names one long-term release (LTS) each year. From 11.8, community LTS binaries are published for three years after GA, with critical and security fixes in source releases for two more. Releases up to 11.4 get five years of community binaries. Rolling releases ship quarterly and are maintained for a short window. Longer maintenance comes from enterprise subscriptions sold through mariadb.com.

Which MariaDB versions are supported?

As of October 2026, the community LTS lines are 10.11 (to 16 February 2028), 11.4 (to 29 May 2029), 11.8 (to 4 June 2028) and 12.3 (to 12 June 2029). The current rolling release is 13.0, maintained to the fourth quarter of 2026, with 13.1 at release-candidate stage. MariaDB 10.6, 10.5 and 10.4 are past their community end-of-life dates.

When did MariaDB 10.6 reach end of life?

Community maintenance for MariaDB 10.6 ended on 6 July 2026, five years after its GA release on 6 July 2021. The Foundation's table lists enterprise maintenance for 10.6 to 23 August 2028 and the extended option to 23 August 2029, both through mariadb.com.

What is the difference between LTS and rolling releases?

An LTS series receives bug and security fixes for years and gains no new features after GA. A rolling release delivers new features each quarter and is replaced by the next one soon after. Production estates that want stable behaviour usually standardise on an LTS; rolling releases suit teams that need a new feature early and can upgrade every quarter.

Can I move from MySQL to MariaDB?

From MySQL 5.7 and earlier, yes: the Foundation states that mariadb-upgrade can upgrade database files from MySQL releases prior to 8.0. MySQL 8.0 and later use a different data dictionary, so moving from 8.0 to MariaDB is a logical dump and load with compatibility testing. OSSeva Assure includes that assessment.

Can OSSeva support the MariaDB servers we run today without a migration?

Yes. OSSeva takes over support for the community binaries and data you already have. Patched builds stay in the same series, so moving to one is a normal minor update. On a Galera cluster that means one node at a time, waiting for each node to resync before the next.

When is a MariaDB enterprise subscription the better fit?

When you want builds and long-term maintenance from the company that develops MariaDB's enterprise server, or depend on its enterprise-only tooling. OSSeva fits estates that run community MariaDB, often next to MySQL or PostgreSQL, and want one support contract across all of them.

Does OSSeva also support MySQL?

Yes. MySQL 5.7 and 8.0 are covered with patched builds after Oracle's end of life, along with 8.4 and 9.7 LTS, under the same contract as MariaDB.

Ready to get MariaDB patched and supported?

Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.