CVE-2025-21505: Medium severity Oracle MySQL Server vulnerability
Last updated 30 January 2025
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.42-1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21505?
CVE-2025-21505 is classified as an easily exploitable vulnerability that poses a high risk to affected systems.
How do I fix CVE-2025-21505?
To mitigate CVE-2025-21505, upgrade to MySQL Server version 8.0.41-2 or later.
Which versions of MySQL Server are affected by CVE-2025-21505?
CVE-2025-21505 affects MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, as well as 9.1.0 and prior.
Who is impacted by CVE-2025-21505?
High privileged attackers can exploit CVE-2025-21505 to compromise systems running the affected versions of MySQL Server.
What components are involved in CVE-2025-21505?
CVE-2025-21505 involves the MySQL Server product, specifically within the component services.