FlawAtlas
Search the atlas
UBUNTU-CVE-2025-21497 Moderate

UBUNTU-CVE-2025-21497

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

Exploit probability Not scored
Published January 21, 2025
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS mysql-5.5

25 explicit affected versions

Ubuntu:16.04:LTS percona-server-5.6

3 explicit affected versions

Ubuntu:16.04:LTS percona-xtradb-cluster-5.6

8 explicit affected versions

Ubuntu:20.04:LTS mysql-8.0

36 explicit affected versions

Ubuntu:22.04:LTS mysql-8.0

20 explicit affected versions

Ubuntu:24.04:LTS mysql-8.0

11 explicit affected versions

Ubuntu:Pro:16.04:LTS mysql-5.7

36 explicit affected versions

Ubuntu:Pro:18.04:LTS mysql-5.7

28 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2025-21497

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

View original source

05 / REFERENCES

Further evidence