Impact
The vulnerability resides in the InnoDB component of Oracle MySQL Server. An attacker with high privileges who can reach the server over the network can exploit it to cause the server to hang or crash repeatedly, thereby disabling the database service. The weakness affects availability only, with no impact on confidentiality or integrity, as indicated by the CVSS vector (C:N/I:N/A:H).
Affected Systems
Oracle Corporation MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 are impacted. Systems running these releases are at risk of experiencing frequent service interruptions if the flaw is exploited.
Risk and Exploitability
The CVSS base score of 4.9 signals a moderate severity exploit. EPSS is not reported, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation activity to date. Nonetheless, an attacker with network access can trigger the defect directly via standard MySQL protocols, and the requirement for high privileged access reduces the threat surface but does not eliminate it. The exploit path is straightforward: connect to the server, send malformed or specific InnoDB-related requests that trigger the crash, and cause a denial of service. Maintaining current patches and monitoring for abnormal CPU or memory spikes can mitigate the risk until a fix is applied.
OpenCVE Enrichment