Impact
The vulnerability resides in the Optimizer component of Oracle MySQL Server and allows a high privileged attacker who can reach the server over the network to cause the database to hang or crash repeatedly. This results in complete denial of service, affecting availability while confidentiality and integrity remain untouched. The weakness is a Resource Exhaustion flaw (CWE‑400).
Affected Systems
Oracle MySQL Server versions from 8.0.0 through 8.0.44, 8.4.0 through 8.4.7 and 9.0.0 through 9.5.0 are impacted. Users of these releases should confirm their environment version and plan an upgrade.
Risk and Exploitability
With a CVSS 3.1 base score of 4.9 and an EPSS below 1%, the likelihood of exploitation is judged low, and the vulnerability is not listed in the CISA KEV catalog. The poisoning requires the attacker to have high privileges and network access; once achieved, the effect is a total service disruption. Existing mitigations such as limiting concurrent connections or disabling optimizations could reduce risk, but the most reliable protection comes from applying the official fix.
OpenCVE Enrichment
Ubuntu USN