Oracle MySQL
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*
- <= 8.0.40
- <= 8.4.3
- <= 9.1.0
A denial-of-service vulnerability has been identified in the InnoDB component of Oracle MySQL Server. This issue affects MySQL versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability allows a high-privileged attacker with network access to MySQL Server via multiple protocols to cause a complete server hang or a frequently repeatable crash, leading to a total denial-of-service condition.
Exploitation of this vulnerability can cause a complete denial-of-service condition on the MySQL Server, causing it to hang or crash repeatedly.
For users on Debian 11 bullseye, this vulnerability has been fixed in MariaDB version 1:10.5.28-0+deb11u1. It is recommended to upgrade to this version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.