Executive brief
A vulnerability exists in Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. A highly privileged attacker could exploit this flaw to cause the database to hang or crash repeatedly, leading to a complete denial of service. While the attack is difficult to execute and requires significant administrative access, it could disrupt business operations and application availability.
Technical details
A vulnerability in the Data Definition Language (DDL) component of Oracle MySQL Server and MySQL Cluster allows for a denial of service (DoS). The flaw is categorized as difficult to exploit and requires the attacker to have high privileges and network access via multiple protocols. Successful exploitation results in a complete loss of availability by causing the server to hang or crash repeatedly. Affected versions include MySQL Server 8.4.0-8.4.10 and 9.7.0-9.7.1, and MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
- Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle