PT-2025-29644 · Oracle+7 · Mysql 9.0+10

Published

2025-07-15

·

Updated

2025-10-06

·

CVE-2025-50091

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 8.0.0 through 8.0.42 Oracle MySQL versions 8.4.0 through 8.4.5 Oracle MySQL versions 9.0.0 through 9.3.0
Description A vulnerability exists in the Optimizer component of Oracle MySQL Server that allows a high-privileged attacker with network access to cause a denial-of-service (DOS) condition, potentially leading to a hang or frequent crashes of the server.
Recommendations Oracle MySQL versions 8.0.0 through 8.0.42: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Oracle MySQL versions 8.4.0 through 8.4.5: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Oracle MySQL versions 9.0.0 through 9.3.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:15699
ALSA-2025:16046
ALSA-2025:16086
ALSA-2025:16861
AZL-65315
AZL-65465
BDU:2025-08707
CESA-2025_16861
CVE-2025-50091
INFSA-2025_16046
INFSA-2025_16086
INFSA-2025_16861
OESA-2025-2085
RHSA-2025:16861
RHSA-2025_16046
RHSA-2025_16086
RHSA-2025_16861
USN-7691-1
USN-7691-2

Affected Products

Almalinux
Centos
Linuxmint
Mysql 8.0
Mysql 8.4
Mysql 9.0
Mysql Server
Oracle Mysql
Red Hat
Rocky Linux
Ubuntu