Impact
A flaw in the replication component of Oracle MySQL Server and MySQL Cluster allows a high‑privilege attacker who can reach the database over network protocols to cause the server to hang or crash repeatedly. The crashes are complete, resulting in a denial of all database operations. No confidential data is disclosed and integrity is not altered; the sole consequence is the loss of availability.
Affected Systems
Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and Oracle MySQL Cluster versions 8.0.0 through 8.0.47 and their 8.4.x and 9.7.x counterparts are affected.
Risk and Exploitability
The CVSS 3.1 base score of 4.9 reflects moderate severity limited to availability. The EPSS score is below 1%, indicating a low probability of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need network access to the replication subsystem and must be able to initiate or influence replication traffic to trigger the crash; no user interaction is required.
OpenCVE Enrichment