Impact
The vulnerability resides in Oracle MySQL Server’s InnoDB component. A high‑privileged attacker with network access through any supported protocol can force the server to crash or hang repeatedly, leading to a complete denial of service. The impact is limited to availability; confidentiality and integrity are not affected.
Affected Systems
Oracle MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 are affected. Any deployment of these releases that is exposed to the network is a potential target. The flaw is specific to the InnoDB component within MySQL Server.
Risk and Exploitability
The CVSS base score of 4.9 classifies the flaw as moderate severity. Since the attack vector requires network access and high privileges, the risk is mitigated by proper access controls. No publicly available exploit is listed, EPSS data is unavailable, and the vulnerability is not in the CISA KEV catalog. Nonetheless, the ability to repeatedly crash the service poses a serious operational risk for database infrastructures that cannot tolerate downtime.
OpenCVE Enrichment