CVE-2025-21490: Medium severity Oracle MySQL Server vulnerability
Last updated 31 March 2025
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mariadbto a version that resolves this vulnerability.Fixed in 1:10.11.11-0+deb12u1Fixed in 1:11.8.1-4 - Upgrade
Upgrade
debian/mariadb-10.5to a version that resolves this vulnerability.Fixed in 1:10.5.28-0+deb11u1 - Upgrade
Upgrade
debian/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.42-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.6.21-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.41-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.11.11-1 - Upgrade
Upgrade
Oracle MySQL (MySQL Server) - InnoDBto a version that resolves this vulnerability.Fixed in 8.0.40 - Upgrade
Upgrade
Oracle MySQL (MySQL Server) - InnoDBto a version that resolves this vulnerability.Fixed in 8.4.3 - Upgrade
Upgrade
Oracle MySQL (MySQL Server) - InnoDBto a version that resolves this vulnerability.Fixed in 9.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21490?
CVE-2025-21490 is considered a high severity vulnerability due to its ease of exploitation by high privileged attackers.
How do I fix CVE-2025-21490?
To fix CVE-2025-21490, upgrade to MySQL Server versions 8.0.41-2, 8.4.4 or later, and 9.1.1 or later.
Which MySQL versions are affected by CVE-2025-21490?
Affected MySQL versions include 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior.
What component of MySQL is impacted by CVE-2025-21490?
CVE-2025-21490 impacts the InnoDB component of the MySQL Server product.
Who is primarily affected by CVE-2025-21490?
High privileged attackers with network access are primarily able to exploit CVE-2025-21490.