PT-2025-29654 · Oracle+7 · Oracle Mysql+7

Yx

·

Published

2025-07-15

·

Updated

2025-10-06

·

CVE-2025-50101

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 8.0.0 through 8.0.42 Oracle MySQL versions 8.4.0 through 8.4.5 Oracle MySQL versions 9.0.0 through 9.3.0
Description A vulnerability exists in the Server: Optimizer component of Oracle MySQL Server. A high-privileged attacker with network access via multiple protocols can compromise the server. Successful exploitation can lead to a denial-of-service (DOS) condition, causing a hang or frequent crashes of the MySQL Server.
Recommendations Update Oracle MySQL to a version later than 8.0.42. Update Oracle MySQL to a version later than 8.4.5. Update Oracle MySQL to a version later than 9.3.0.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALSA-2025:15699
ALSA-2025:16046
ALSA-2025:16086
ALSA-2025:16861
AZL-65312
AZL-65492
BDU:2025-08650
CESA-2025_16861
CVE-2025-50101
INFSA-2025_16046
INFSA-2025_16086
INFSA-2025_16861
OESA-2025-2085
RHSA-2025:16861
RHSA-2025_16046
RHSA-2025_16086
RHSA-2025_16861
USN-7691-1
USN-7691-2

Affected Products

Almalinux
Centos
Linuxmint
Mysql Server
Oracle Mysql
Red Hat
Rocky Linux
Ubuntu