Impact
A flaw in the replication handling of Oracle MySQL Server and MySQL Cluster, categorized as CWE-400 and CWE-770, allows a high‑privileged attacker with network access to trigger a difficult‑to‑exploit crash or hang of the database service. This results in a denial of service that renders the system unavailable, without compromising confidentiality or integrity.
Affected Systems
Oracle MySQL Server and Oracle MySQL Cluster are affected. Versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1 of MySQL Server, and 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 of MySQL Cluster, all run the vulnerable code and are potentially affected.
Risk and Exploitability
The CVSS 3.1 Base Score of 4.4 indicates low severity, with high attack complexity and required privileges. The EPSS score of <1 % suggests a very low exploitation probability, and the vulnerability is not listed in CISA KEV. An attacker must be able to access the MySQL instance over any supported network protocol and possess sufficient privileges to influence replication traffic; once these conditions are met, a crash or hang can be induced that brings the service down until it is restarted.
OpenCVE Enrichment