Impact
The vulnerability lies in the InnoDB component of Oracle MySQL Server and MySQL Cluster. An attacker with high privileges who can reach the database over the network through any supported protocol can exploit this flaw to deliberately trigger a hang or repeatable crash of the server. Such an attack results in a denial of service for all users of the affected database instance.
Affected Systems
Affected systems include Oracle MySQL Server and MySQL Cluster. Versions 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 of MySQL Server, as well as 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 of MySQL Cluster are known to be vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 4.9 reflects a moderate severity focused on availability. The EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The described attack vector is a network-based exploit that requires high privileges; therefore, the threat is most acute for exposed database instances that are reachable over the network.
OpenCVE Enrichment