RHSA-2026:56973: Important: mysql:8.4 security, bug fix, and enhancement update
MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries.Security Fix(es): mysql: Performance Schema unspecified vulnerability (CPU Jul 2026) (CVE-2026-61081) mysql: Optimizer unspecified vulnerability (CPU Jul 2026) (CVE-2026-47064) mysql: Optimizer unspecified vulnerability (CPU Jul 2026) (CVE-2026-47012) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60331) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60190) mysql: Clone Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60177) mysql: Optimizer unspecified vulnerability (CPU Jul 2026) (CVE-2026-60145) mysql: DDL unspecified vulnerability (CPU Jul 2026) (CVE-2026-46936) mysql: Group Replication Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60186) mysql: X Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60315) mysql: Pluggable Auth unspecified vulnerability (CPU Jul 2026) (CVE-2026-61096) mysql: Group Replication Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60163) mysql: InnoDB unspecified vulnerability (CPU Jul 2026) (CVE-2026-47052) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60188) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60184) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60185) mysql: JSON unspecified vulnerability (CPU Jul 2026) (CVE-2026-61109) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60191) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-61094) mysql: Clone Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60178) mysql: Group Replication GCS unspecified vulnerability (CPU Jul 2026) (CVE-2026-60332) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60189) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60747) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-47023) mysql: Clone Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60183) mysql: X Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60316) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60187) mysql: Replication unspecified vulnerability (CPU Jul 2026) (CVE-2026-60585) mysql: Clone Plugin unspecified vulnerability (CPU Jul 2026) (CVE-2026-60182) Bug Fix(es) and Enhancement(s): [tracker] Rebase MySQL to 8.4.11 (JIRA:RHEL-188045) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/mecabto a version that resolves this vulnerability.Fixed in 0.996-3.module+el9.8.0+24348+9b27f387.4 - Upgrade
Upgrade
redhat/mecab-ipadicto a version that resolves this vulnerability.Fixed in 2.7.0.20070801-24.module+el9.8.0+24348+9b27f387 - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/rapidjsonto a version that resolves this vulnerability.Fixed in 1.1.0-19.module+el9.8.0+24348+9b27f387 - Upgrade
Upgrade
redhat/mysql-commonto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/mysql-errmsgto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/mysql-test-datato a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/rapidjson-docto a version that resolves this vulnerability.Fixed in 1.1.0-19.module+el9.8.0+24348+9b27f387 - Upgrade
Upgrade
redhat/mecab-debuginfoto a version that resolves this vulnerability.Fixed in 0.996-3.module+el9.8.0+24348+9b27f387.4 - Upgrade
Upgrade
redhat/mecab-debugsourceto a version that resolves this vulnerability.Fixed in 0.996-3.module+el9.8.0+24348+9b27f387.4 - Upgrade
Upgrade
redhat/mecab-develto a version that resolves this vulnerability.Fixed in 0.996-3.module+el9.8.0+24348+9b27f387.4 - Upgrade
Upgrade
redhat/mysql-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/mysql-debugsourceto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/mysql-develto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/mysql-devel-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/mysql-libsto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/mysql-libs-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/mysql-serverto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/mysql-server-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/mysql-testto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/mysql-test-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a - Upgrade
Upgrade
redhat/rapidjson-develto a version that resolves this vulnerability.Fixed in 1.1.0-19.module+el9.8.0+24348+9b27f387 - Upgrade
Upgrade
redhat/mecabto a version that resolves this vulnerability.Fixed in 0.996-3.module+el9.8.0+24348+9b27f387.4.aa - Upgrade
Upgrade
redhat/mecab-debuginfoto a version that resolves this vulnerability.Fixed in 0.996-3.module+el9.8.0+24348+9b27f387.4.aa - Upgrade
Upgrade
redhat/mecab-debugsourceto a version that resolves this vulnerability.Fixed in 0.996-3.module+el9.8.0+24348+9b27f387.4.aa - Upgrade
Upgrade
redhat/mecab-develto a version that resolves this vulnerability.Fixed in 0.996-3.module+el9.8.0+24348+9b27f387.4.aa - Upgrade
Upgrade
redhat/mecab-ipadicto a version that resolves this vulnerability.Fixed in 2.7.0.20070801-24.module+el9.8.0+24348+9b27f387.aa - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a.aa - Upgrade
Upgrade
redhat/mysql-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a.aa - Upgrade
Upgrade
redhat/mysql-debugsourceto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a.aa - Upgrade
Upgrade
redhat/mysql-develto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a.aa - Upgrade
Upgrade
redhat/mysql-devel-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a.aa - Upgrade
Upgrade
redhat/mysql-libsto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a.aa - Upgrade
Upgrade
redhat/mysql-libs-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a.aa - Upgrade
Upgrade
redhat/mysql-serverto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a.aa - Upgrade
Upgrade
redhat/mysql-server-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a.aa - Upgrade
Upgrade
redhat/mysql-testto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a.aa - Upgrade
Upgrade
redhat/mysql-test-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.11-1.module+el9.8.0+24663+27effc5a.aa - Upgrade
Upgrade
redhat/rapidjson-develto a version that resolves this vulnerability.Fixed in 1.1.0-19.module+el9.8.0+24348+9b27f387.aa - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Fixed in 8.4.11Patch RHEL-188045 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60177 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60178 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60182 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60183 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-46936 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60332 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60163 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60186 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-47052 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-61109 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-47012 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-47064 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60145 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-61096 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-47023 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60184 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60185 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60187 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60188 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60189 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60190 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60191 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60331 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60585 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60747 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-61094 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60315 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-60316 - Upgrade
Upgrade
mysqlto a version that resolves this vulnerability.Patch CVE-2026-61081
Event History
Frequently Asked Questions
Which package artifacts are listed for review when applying this advisory?
The listed packages are redhat/mysql, redhat/mysql-debuginfo, and redhat/mysql-debugsource, along with redhat/mecab, redhat/mecab-ipadic, redhat/mecab-debuginfo, redhat/mecab-debugsource, and redhat/mecab-devel.
Can exploit prerequisites or exposure through a default configuration be determined from this advisory?
No. The supplied information identifies multiple MySQL components but describes the issues as unspecified and provides no authentication, network exposure, privilege, or configuration prerequisites.
Does the advisory provide package versions or indicators to determine whether a system is already affected?
No. The provided data does not include fixed package versions, vulnerable version ranges, or detection indicators.