Executive brief
Oracle Database Server includes a network communication component called Net Services that handles connections between clients and the database. An unauthenticated attacker on the network can exploit a flaw in this component to crash or freeze the service, preventing legitimate users from accessing the database and causing operational downtime.
Technical details
This is a denial-of-service vulnerability in the Oracle Net Services component of Oracle Database Server. The flaw is easily exploitable and requires only network access to the Oracle Net port; no authentication or user interaction is required. An attacker can send specially crafted network packets via Oracle Net protocol to trigger a hang or crash of the Net Services process, resulting in complete unavailability. The vulnerability affects versions 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3. Patches from Oracle are expected as part of their regular security updates.
Affected products
- Oracle Database Server 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3
Timeline
- 2026-09-15: disclosed