Impact
A resource exhaustion flaw in the MySQL Group Replication Plugin allows an attacker who has high privileges and network access to trigger a persistent loop or hang that causes the MySQL Server or MySQL Cluster to crash repeatedly. The vulnerability can be exploited to deny services by exhausting server resources, impacting only availability without compromising data confidentiality or integrity.
Affected Systems
Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as MySQL Cluster versions 8.0.0 to 8.0.47, 8.4.0 to 8.4.10, and 9.7.0 to 9.7.1 are affected.
Risk and Exploitability
The CVSS v3.1 base score of 4.4 indicates a moderate severity that focuses solely on availability. The EPSS probability of less than 1 % shows that exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Successful exploitation requires an attacker to have high privileges and network access to the MySQL instance over the supported protocols. If exploited, the attacker can force the server or cluster to hang or crash repeatedly, thereby interrupting service availability.
OpenCVE Enrichment