Impact
The MySQL Server component GIS is vulnerable to a flaw that lets a network attacker who can assign high privileges within the database cause the server to hang or crash repeatedly. This limits availability without directly affecting confidentiality or integrity, as the flaw does not expose data or alter it. The weakness is tied to access‑control and resource‑exhaustion problems, consistent with the listed CWEs.
Affected Systems
Oracle MySQL Server versions from 9.0.0 through 9.6.0 that include the GIS subsystem are affected. Any deployment that hosts this component remains vulnerable until a version released after 9.6.0 is applied.
Risk and Exploitability
The CVSS 3.1 base score of 4.9 reflects a moderate risk concentrated on availability, with the attack vector being network-based but requiring a high‑privileged user. The EPSS score is below 1 %, and it is not part of CISA KEV, meaning widespread exploitation is unlikely at present. An attacker can bring the server to a hung or crashed state, which will disrupt applications and users that depend on the database.
OpenCVE Enrichment