Oracle MySQL InnoDB Denial-of-Service and Data Manipulation Vulnerability

Vulnerability

A vulnerability has been identified in the MySQL Server component of Oracle MySQL, specifically in versions 8.0.0 through 8.0.41, 8.4.0 through 8.4.4, and 9.0.0 through 9.2.0. This vulnerability allows a high-privileged attacker with network access to MySQL Server to cause a complete denial-of-service by hanging the server or causing a frequently repeatable crash. Additionally, the vulnerability permits unauthorized updates, inserts, or deletions of some data accessible to MySQL Server.

Impact

Exploitation of this vulnerability leads to a complete denial-of-service condition on the MySQL Server, causing it to hang or crash frequently. Furthermore, it allows unauthorized modifications to some of the data accessible by MySQL Server, including updates, inserts, or deletions.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
3.1
exploitability
4.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.