Impact
The vulnerability resides in the replication component of Oracle MySQL Server and MySQL Cluster and causes high‑privileged attackers with network access to trigger a hang or a repeatable crash of the database engine, resulting in a denial of service. The flaw does not provide a path to compromise confidentiality or integrity; it simply disrupts availability, aligning with CWE‑400 (Resource Exhaustion).
Affected Systems
Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 are impacted.
Risk and Exploitability
The CVSS 3.1 base score of 4.4 signals a medium impact limited to availability, and the EPSS score of less than 1% implies a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires the attacker to have high privileges and network access via one or more supported protocols; the exploit can be delivered over the network to the replication subsystem, leading to a server crash or hang that interrupts database services.
OpenCVE Enrichment