Impact
MySQL Server and MySQL Cluster contain a flaw in the Optimizer that can be triggered by crafted requests sent over any supported database protocol. When an attacker with low privilege sends these requests, the optimizer may hang or crash, preventing legitimate users from accessing the database. The flaw causes a loss of availability while confidentiality and integrity are not affected. The defect is characterized as a resource exhaustion issue (CWE‑400) and an insufficient resources error (CWE‑770).
Affected Systems
Oracle MySQL Server and Oracle MySQL Cluster are impacted in versions 9.7.0 and 9.7.1. All deployments running these releases are vulnerable unless upgraded or patched.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity with a high availability impact. The EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker should be able to exploit this weakness by sending underprivileged traffic over any of the supported network protocols; a successful exploit will induce a crash or hang that consumes server resources and denies continuous service to legitimate users.
OpenCVE Enrichment