Source: mysql-9.7
Version: 9.7.1-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for mysql-9.7.

CVE-2026-46936[0]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: DDL).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4
| (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-47008[1]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: InnoDB).  Supported versions that are affected are
| MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily
| exploitable vulnerability allows high privileged attacker with
| network access via multiple protocols to compromise MySQL Server,
| MySQL Cluster.  Successful attacks of this vulnerability can result
| in unauthorized ability to cause a hang or frequently repeatable
| crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base
| Score 4.9 (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-47012[2]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Optimizer).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4
| (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-47023[3]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Replication).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9
| (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-47052[4]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: InnoDB).  Supported versions that are affected are
| MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9
| (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-47064[5]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Optimizer).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable
| vulnerability allows low privileged attacker with network access via
| multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5
| (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60145[6]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Optimizer).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9
| (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60163[7]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Group Replication Plugin).  Supported
| versions that are affected are MySQL Server: 8.4.0-8.4.10,
| 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and
| 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated
| attacker with logon to the infrastructure where MySQL Server, MySQL
| Cluster executes to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in takeover of
| MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 8.4
| (Confidentiality, Integrity and Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-60174[8]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Optimizer).  Supported versions that are
| affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1.
| Easily exploitable vulnerability allows low privileged attacker with
| network access via multiple protocols to compromise MySQL Server,
| MySQL Cluster.  Successful attacks of this vulnerability can result
| in unauthorized ability to cause a hang or frequently repeatable
| crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base
| Score 6.5 (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60177[9]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Clone Plugin).  Supported versions that
| are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL
| Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to
| exploit vulnerability allows high privileged attacker with network
| access via multiple protocols to compromise MySQL Server, MySQL
| Cluster.  Successful attacks of this vulnerability can result in
| unauthorized ability to cause a hang or frequently repeatable crash
| (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score
| 4.4 (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60178[10]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Clone Plugin).  Supported versions that
| are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL
| Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to
| exploit vulnerability allows high privileged attacker with network
| access via multiple protocols to compromise MySQL Server, MySQL
| Cluster.  Successful attacks of this vulnerability can result in
| takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6
| (Confidentiality, Integrity and Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-60181[11]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Configurator).  Supported versions that
| are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster:
| 9.7.0-9.7.1. Difficult to exploit vulnerability allows low
| privileged attacker with logon to the infrastructure where MySQL
| Server, MySQL Cluster executes to compromise MySQL Server, MySQL
| Cluster.  Successful attacks require human interaction from a person
| other than the attacker. Successful attacks of this vulnerability
| can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base
| Score 6.7 (Confidentiality, Integrity and Availability impacts).
| CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).


CVE-2026-60182[12]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Clone Plugin).  Supported versions that
| are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL
| Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to
| exploit vulnerability allows high privileged attacker with network
| access via multiple protocols to compromise MySQL Server, MySQL
| Cluster.  Successful attacks of this vulnerability can result in
| unauthorized ability to cause a hang or frequently repeatable crash
| (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score
| 4.4 (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60183[13]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Clone Plugin).  Supported versions that
| are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL
| Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to
| exploit vulnerability allows high privileged attacker with logon to
| the infrastructure where MySQL Server, MySQL Cluster executes to
| compromise MySQL Server, MySQL Cluster.  Successful attacks of this
| vulnerability can result in takeover of MySQL Server, MySQL Cluster.
| CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-60184[14]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Replication).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4
| (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60185[15]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Replication).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4
| (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60186[16]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Group Replication Plugin).  Supported
| versions that are affected are MySQL Server: 8.4.0-8.4.10,
| 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and
| 9.7.0-9.7.1. Difficult to exploit vulnerability allows high
| privileged attacker with network access via multiple protocols to
| compromise MySQL Server, MySQL Cluster.  Successful attacks of this
| vulnerability can result in unauthorized ability to cause a hang or
| frequently repeatable crash (complete DOS) of MySQL Server, MySQL
| Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60187[17]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Replication).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4
| (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60188[18]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Replication).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4
| (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60189[19]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Replication).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4
| (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60190[20]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Replication).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a partial denial of service (partial DOS) of MySQL
| Server, MySQL Cluster. CVSS 3.1 Base Score 2.2 (Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).


CVE-2026-60191[21]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Replication).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit
| vulnerability allows high privileged attacker with logon to the
| infrastructure where MySQL Server, MySQL Cluster executes to
| compromise MySQL Server, MySQL Cluster.  Successful attacks of this
| vulnerability can result in unauthorized ability to cause a hang or
| frequently repeatable crash (complete DOS) of MySQL Server, MySQL
| Cluster. CVSS 3.1 Base Score 4.1 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60194[22]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: JSON Duality).  Supported versions that
| are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster:
| 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged
| attacker with network access via multiple protocols to compromise
| MySQL Server, MySQL Cluster.  Successful attacks of this
| vulnerability can result in unauthorized ability to cause a hang or
| frequently repeatable crash (complete DOS) of MySQL Server, MySQL
| Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60195[23]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: JSON Duality).  Supported versions that
| are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster:
| 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged
| attacker with network access via multiple protocols to compromise
| MySQL Server, MySQL Cluster.  Successful attacks of this
| vulnerability can result in unauthorized ability to cause a hang or
| frequently repeatable crash (complete DOS) of MySQL Server, MySQL
| Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60311[24]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Optimizer).  Supported versions that are
| affected are MySQL Server: 9.0.0-9.7.1;  MySQL Cluster: 9.0.0-9.7.1.
| Easily exploitable vulnerability allows low privileged attacker with
| network access via multiple protocols to compromise MySQL Server,
| MySQL Cluster.  Successful attacks of this vulnerability can result
| in unauthorized ability to cause a hang or frequently repeatable
| crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base
| Score 6.5 (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60315[25]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: X Plugin).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable
| vulnerability allows unauthenticated attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster and  unauthorized read access to
| a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1
| Base Score 8.2 (Confidentiality and Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).


CVE-2026-60316[26]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: X Plugin).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in takeover of
| MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2
| (Confidentiality, Integrity and Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-60324[27]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Optimizer).  Supported versions that are
| affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1.
| Easily exploitable vulnerability allows low privileged attacker with
| network access via multiple protocols to compromise MySQL Server,
| MySQL Cluster.  Successful attacks of this vulnerability can result
| in unauthorized ability to cause a hang or frequently repeatable
| crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base
| Score 6.5 (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60331[28]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Replication).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit
| vulnerability allows high privileged attacker with logon to the
| infrastructure where MySQL Server, MySQL Cluster executes to
| compromise MySQL Server, MySQL Cluster.  Successful attacks of this
| vulnerability can result in takeover of MySQL Server, MySQL Cluster.
| CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-60332[29]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Group Replication GCS).  Supported
| versions that are affected are MySQL Server: 8.4.0-8.4.10,
| 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and
| 9.7.0-9.7.1. Difficult to exploit vulnerability allows high
| privileged attacker with logon to the infrastructure where MySQL
| Server, MySQL Cluster executes to compromise MySQL Server, MySQL
| Cluster.  Successful attacks of this vulnerability can result in
| takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4
| (Confidentiality, Integrity and Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-60585[30]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Replication).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in takeover of
| MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6
| (Confidentiality, Integrity and Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-60718[31]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: JSON).  Supported versions that are
| affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1.
| Easily exploitable vulnerability allows low privileged attacker with
| network access via multiple protocols to compromise MySQL Server,
| MySQL Cluster.  Successful attacks of this vulnerability can result
| in unauthorized ability to cause a hang or frequently repeatable
| crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base
| Score 6.5 (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60747[32]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Replication).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable
| vulnerability allows unauthenticated attacker with logon to the
| infrastructure where MySQL Server, MySQL Cluster executes to
| compromise MySQL Server, MySQL Cluster.  Successful attacks of this
| vulnerability can result in unauthorized ability to cause a hang or
| frequently repeatable crash (complete DOS) of MySQL Server, MySQL
| Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-61081[33]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Performance Schema).  Supported versions
| that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL
| Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily
| exploitable vulnerability allows high privileged attacker with
| network access via multiple protocols to compromise MySQL Server,
| MySQL Cluster.  Successful attacks of this vulnerability can result
| in  unauthorized read access to a subset of MySQL Server, MySQL
| Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).


CVE-2026-61093[34]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Optimizer).  Supported versions that are
| affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1.
| Easily exploitable vulnerability allows low privileged attacker with
| network access via multiple protocols to compromise MySQL Server,
| MySQL Cluster.  Successful attacks of this vulnerability can result
| in unauthorized ability to cause a hang or frequently repeatable
| crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base
| Score 6.5 (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-61094[35]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Replication).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable
| vulnerability allows high privileged attacker with network access
| via multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in takeover of
| MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2
| (Confidentiality, Integrity and Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-61096[36]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Pluggable Auth).  Supported versions that
| are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL
| Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to
| exploit vulnerability allows unauthenticated attacker with logon to
| the infrastructure where MySQL Server, MySQL Cluster executes to
| compromise MySQL Server, MySQL Cluster.  Successful attacks of this
| vulnerability can result in  unauthorized update, insert or delete
| access to some of MySQL Server, MySQL Cluster accessible data. CVSS
| 3.1 Base Score 2.9 (Integrity impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).


CVE-2026-61108[37]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: GIS).  Supported versions that are
| affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1.
| Easily exploitable vulnerability allows low privileged attacker with
| network access via multiple protocols to compromise MySQL Server,
| MySQL Cluster.  Successful attacks of this vulnerability can result
| in unauthorized ability to cause a hang or frequently repeatable
| crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base
| Score 6.5 (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-61109[38]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: JSON).  Supported versions that are
| affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster:
| 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable
| vulnerability allows low privileged attacker with network access via
| multiple protocols to compromise MySQL Server, MySQL Cluster.
| Successful attacks of this vulnerability can result in unauthorized
| ability to cause a hang or frequently repeatable crash (complete
| DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5
| (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-61128[39]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Optimizer).  Supported versions that are
| affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1.
| Easily exploitable vulnerability allows high privileged attacker
| with network access via multiple protocols to compromise MySQL
| Server, MySQL Cluster.  Successful attacks of this vulnerability can
| result in unauthorized ability to cause a hang or frequently
| repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS
| 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-61144[40]:
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle
| MySQL (component: Server: Optimizer).  Supported versions that are
| affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1.
| Easily exploitable vulnerability allows high privileged attacker
| with network access via multiple protocols to compromise MySQL
| Server, MySQL Cluster.  Successful attacks of this vulnerability can
| result in unauthorized ability to cause a hang or frequently
| repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS
| 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-46936
    https://www.cve.org/CVERecord?id=CVE-2026-46936
[1] https://security-tracker.debian.org/tracker/CVE-2026-47008
    https://www.cve.org/CVERecord?id=CVE-2026-47008
[2] https://security-tracker.debian.org/tracker/CVE-2026-47012
    https://www.cve.org/CVERecord?id=CVE-2026-47012
[3] https://security-tracker.debian.org/tracker/CVE-2026-47023
    https://www.cve.org/CVERecord?id=CVE-2026-47023
[4] https://security-tracker.debian.org/tracker/CVE-2026-47052
    https://www.cve.org/CVERecord?id=CVE-2026-47052
[5] https://security-tracker.debian.org/tracker/CVE-2026-47064
    https://www.cve.org/CVERecord?id=CVE-2026-47064
[6] https://security-tracker.debian.org/tracker/CVE-2026-60145
    https://www.cve.org/CVERecord?id=CVE-2026-60145
[7] https://security-tracker.debian.org/tracker/CVE-2026-60163
    https://www.cve.org/CVERecord?id=CVE-2026-60163
[8] https://security-tracker.debian.org/tracker/CVE-2026-60174
    https://www.cve.org/CVERecord?id=CVE-2026-60174
[9] https://security-tracker.debian.org/tracker/CVE-2026-60177
    https://www.cve.org/CVERecord?id=CVE-2026-60177
[10] https://security-tracker.debian.org/tracker/CVE-2026-60178
    https://www.cve.org/CVERecord?id=CVE-2026-60178
[11] https://security-tracker.debian.org/tracker/CVE-2026-60181
    https://www.cve.org/CVERecord?id=CVE-2026-60181
[12] https://security-tracker.debian.org/tracker/CVE-2026-60182
    https://www.cve.org/CVERecord?id=CVE-2026-60182
[13] https://security-tracker.debian.org/tracker/CVE-2026-60183
    https://www.cve.org/CVERecord?id=CVE-2026-60183
[14] https://security-tracker.debian.org/tracker/CVE-2026-60184
    https://www.cve.org/CVERecord?id=CVE-2026-60184
[15] https://security-tracker.debian.org/tracker/CVE-2026-60185
    https://www.cve.org/CVERecord?id=CVE-2026-60185
[16] https://security-tracker.debian.org/tracker/CVE-2026-60186
    https://www.cve.org/CVERecord?id=CVE-2026-60186
[17] https://security-tracker.debian.org/tracker/CVE-2026-60187
    https://www.cve.org/CVERecord?id=CVE-2026-60187
[18] https://security-tracker.debian.org/tracker/CVE-2026-60188
    https://www.cve.org/CVERecord?id=CVE-2026-60188
[19] https://security-tracker.debian.org/tracker/CVE-2026-60189
    https://www.cve.org/CVERecord?id=CVE-2026-60189
[20] https://security-tracker.debian.org/tracker/CVE-2026-60190
    https://www.cve.org/CVERecord?id=CVE-2026-60190
[21] https://security-tracker.debian.org/tracker/CVE-2026-60191
    https://www.cve.org/CVERecord?id=CVE-2026-60191
[22] https://security-tracker.debian.org/tracker/CVE-2026-60194
    https://www.cve.org/CVERecord?id=CVE-2026-60194
[23] https://security-tracker.debian.org/tracker/CVE-2026-60195
    https://www.cve.org/CVERecord?id=CVE-2026-60195
[24] https://security-tracker.debian.org/tracker/CVE-2026-60311
    https://www.cve.org/CVERecord?id=CVE-2026-60311
[25] https://security-tracker.debian.org/tracker/CVE-2026-60315
    https://www.cve.org/CVERecord?id=CVE-2026-60315
[26] https://security-tracker.debian.org/tracker/CVE-2026-60316
    https://www.cve.org/CVERecord?id=CVE-2026-60316
[27] https://security-tracker.debian.org/tracker/CVE-2026-60324
    https://www.cve.org/CVERecord?id=CVE-2026-60324
[28] https://security-tracker.debian.org/tracker/CVE-2026-60331
    https://www.cve.org/CVERecord?id=CVE-2026-60331
[29] https://security-tracker.debian.org/tracker/CVE-2026-60332
    https://www.cve.org/CVERecord?id=CVE-2026-60332
[30] https://security-tracker.debian.org/tracker/CVE-2026-60585
    https://www.cve.org/CVERecord?id=CVE-2026-60585
[31] https://security-tracker.debian.org/tracker/CVE-2026-60718
    https://www.cve.org/CVERecord?id=CVE-2026-60718
[32] https://security-tracker.debian.org/tracker/CVE-2026-60747
    https://www.cve.org/CVERecord?id=CVE-2026-60747
[33] https://security-tracker.debian.org/tracker/CVE-2026-61081
    https://www.cve.org/CVERecord?id=CVE-2026-61081
[34] https://security-tracker.debian.org/tracker/CVE-2026-61093
    https://www.cve.org/CVERecord?id=CVE-2026-61093
[35] https://security-tracker.debian.org/tracker/CVE-2026-61094
    https://www.cve.org/CVERecord?id=CVE-2026-61094
[36] https://security-tracker.debian.org/tracker/CVE-2026-61096
    https://www.cve.org/CVERecord?id=CVE-2026-61096
[37] https://security-tracker.debian.org/tracker/CVE-2026-61108
    https://www.cve.org/CVERecord?id=CVE-2026-61108
[38] https://security-tracker.debian.org/tracker/CVE-2026-61109
    https://www.cve.org/CVERecord?id=CVE-2026-61109
[39] https://security-tracker.debian.org/tracker/CVE-2026-61128
    https://www.cve.org/CVERecord?id=CVE-2026-61128
[40] https://security-tracker.debian.org/tracker/CVE-2026-61144
    https://www.cve.org/CVERecord?id=CVE-2026-61144

Regards,
Salvatore


Reply via email to