Impact
The vulnerability resides in the InnoDB component of MySQL Server and MySQL Cluster. An attacker with high‑privilege access who can reach the database via standard protocols can trigger a crash or hang, resulting in a complete denial of service. The flaw is a classic denial‑of‑service weakness that disables service availability without compromising confidentiality or integrity.
Affected Systems
Affected products are Oracle MySQL Server and MySQL Cluster. Versions 9.7.0 through 9.7.1 are vulnerable; there is no explicit statement in the CVE that later versions are safe, so risk remains until updated.
Risk and Exploitability
The CVSS v3.1 base score of 4.9 reflects the availability impact and the need for high‑privilege access. The EPSS score is less than 1 %, indicating a low probability of exploitation; the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires network access via MySQL’s native protocols and high‑privilege access, but does not provide persistence or data exfiltration.
OpenCVE Enrichment