RHSA-2026:56936: Important: mysql:8.4 security, bug fix, and enhancement update
Important: mysql:8.4 security, bug fix, and enhancement update
Other sources
MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries.Security Fix(es): mysql: Performance Schema unspecified vulnerability (CPU Jul 2026) (CVE-2026-61081) mysql: Optimizer unspecified vulnerability (CPU Jul 2026) (CVE-2026-47064) mysql: Optimizer unspecified vulnerability (CPU Jul 2026) (CVE-2026-47012) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60331) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60190) mysql: Clone Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60177) mysql: Optimizer unspecified vulnerability (CPU Jul 2026) (CVE-2026-60145) mysql: DDL unspecified vulnerability (CPU Jul 2026) (CVE-2026-46936) mysql: Group Replication Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60186) mysql: X Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60315) mysql: Pluggable Auth unspecified vulnerability (CPU Jul 2026) (CVE-2026-61096) mysql: Group Replication Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60163) mysql: InnoDB unspecified vulnerability (CPU Jul 2026) (CVE-2026-47052) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60188) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60184) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60185) mysql: JSON unspecified vulnerability (CPU Jul 2026) (CVE-2026-61109) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60191) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-61094) mysql: Clone Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60178) mysql: Group Replication GCS unspecified vulnerability (CPU Jul 2026) (CVE-2026-60332) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60189) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60747) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-47023) mysql: Clone Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60183) mysql: X Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60316) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60187) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60585) mysql: Clone Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60182) Bug Fix(es) and Enhancement(s): [tracker] Rebase MySQL to 8.4.11 (JIRA:RHEL-188046) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/mecabto a version that resolves this vulnerability.Fixed in 0.996-2.module+el8.10.0+23550+bd321b9a - Upgrade
Upgrade
redhat/mecab-ipadicto a version that resolves this vulnerability.Fixed in 2.7.0.20070801-17.module+el8.10.0+23550+bd321b9a - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mysql-commonto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mysql-errmsgto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mysql-test-datato a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mecab-debuginfoto a version that resolves this vulnerability.Fixed in 0.996-2.module+el8.10.0+23550+bd321b9a - Upgrade
Upgrade
redhat/mecab-debugsourceto a version that resolves this vulnerability.Fixed in 0.996-2.module+el8.10.0+23550+bd321b9a - Upgrade
Upgrade
redhat/mecab-develto a version that resolves this vulnerability.Fixed in 0.996-2.module+el8.10.0+23550+bd321b9a - Upgrade
Upgrade
redhat/mysql-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mysql-debugsourceto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mysql-develto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mysql-devel-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mysql-libsto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mysql-libs-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mysql-serverto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mysql-server-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mysql-testto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mysql-test-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9 - Upgrade
Upgrade
redhat/mecabto a version that resolves this vulnerability.Fixed in 0.996-2.module+el8.10.0+23550+bd321b9a.aa - Upgrade
Upgrade
redhat/mecab-debuginfoto a version that resolves this vulnerability.Fixed in 0.996-2.module+el8.10.0+23550+bd321b9a.aa - Upgrade
Upgrade
redhat/mecab-debugsourceto a version that resolves this vulnerability.Fixed in 0.996-2.module+el8.10.0+23550+bd321b9a.aa - Upgrade
Upgrade
redhat/mecab-develto a version that resolves this vulnerability.Fixed in 0.996-2.module+el8.10.0+23550+bd321b9a.aa - Upgrade
Upgrade
redhat/mecab-ipadicto a version that resolves this vulnerability.Fixed in 2.7.0.20070801-17.module+el8.10.0+23550+bd321b9a.aa - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9.aa - Upgrade
Upgrade
redhat/mysql-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9.aa - Upgrade
Upgrade
redhat/mysql-debugsourceto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9.aa - Upgrade
Upgrade
redhat/mysql-develto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9.aa - Upgrade
Upgrade
redhat/mysql-devel-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9.aa - Upgrade
Upgrade
redhat/mysql-libsto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9.aa - Upgrade
Upgrade
redhat/mysql-libs-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9.aa - Upgrade
Upgrade
redhat/mysql-serverto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9.aa - Upgrade
Upgrade
redhat/mysql-server-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9.aa - Upgrade
Upgrade
redhat/mysql-testto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9.aa - Upgrade
Upgrade
redhat/mysql-test-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el8.10.0+24662+2d989aa9.aa - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Fixed in 8.4.11Patch RHEL-188046 - Compensating control
After updating, validate that the MySQL server daemon (mysqld) and affected components (e.g., Performance Schema, JSON, Optimizer, Replication, Group Replication, InnoDB, DDL, Clone Plugin, Pluggable Auth, X Plugin) are running the updated build with the security fixes for the listed CVEs from the advisory.