RHSA-2025:1671HighCVSS 7.5

Red Hat Security Advisory: mysql security update

Published
February 19, 2025
Last Modified
September 11, 2026

🔗 CVE IDs covered (49)

📋 Description

CVE-2024-5535 — openssl: SSL_select_next_proto buffer overread CVE-2024-7264 — curl: libcurl: ASN.1 date parser overread CVE-2024-11053 — curl: curl netrc password leak CVE-2024-21193 — mysql: PS unspecified vulnerability (CPU Oct 2024) CVE-2024-21194 — mysql: InnoDB unspecified vulnerability (CPU Oct 2024) CVE-2024-21196 — mysql: X Plugin unspecified vulnerability (CPU Oct 2024) CVE-2024-21197 — mysql: Information Schema unspecified vulnerability (CPU Oct 2024) CVE-2024-21198 — mysql: DDL unspecified vulnerability (CPU Oct 2024) CVE-2024-21199 — mysql: InnoDB unspecified vulnerability (CPU Oct 2024) CVE-2024-21201 — mysql: Optimizer unspecified vulnerability (CPU Oct 2024) CVE-2024-21203 — mysql: FTS unspecified vulnerability (CPU Oct 2024) CVE-2024-21212 — mysql: Health Monitor unspecified vulnerability (CPU Oct 2024) CVE-2024-21213 — mysql: InnoDB unspecified vulnerability (CPU Oct 2024) CVE-2024-21218 — mysql: InnoDB unspecified vulnerability (CPU Oct 2024) CVE-2024-21219 — mysql: DML unspecified vulnerability (CPU Oct 2024) CVE-2024-21230 — mysql: Optimizer unspecified vulnerability (CPU Oct 2024) CVE-2024-21231 — mysql: Client programs unspecified vulnerability (CPU Oct 2024) CVE-2024-21236 — mysql: InnoDB unspecified vulnerability (CPU Oct 2024) CVE-2024-21237 — mysql: Group Replication GCS unspecified vulnerability (CPU Oct 2024) CVE-2024-21238 — mysql: Thread Pooling unspecified vulnerability (CPU Oct 2024) CVE-2024-21239 — mysql: InnoDB unspecified vulnerability (CPU Oct 2024) CVE-2024-21241 — mysql: Optimizer unspecified vulnerability (CPU Oct 2024) CVE-2024-21247 — mysql: mysqldump unspecified vulnerability (CPU Oct 2024) CVE-2024-37371 — krb5: GSS message token handling CVE-2025-21490 — mysql: mariadb: High Privilege Denial of Service Vulnerability in MySQL Server (CPU Jan 2025) CVE-2025-21491 — mysql: MySQL Server InnoDB Denial of Service and Unauthorized Data Modification Vulnerability CVE-2025-21494 — mysql: MySQL Server: Denial of Service vulnerability CVE-2025-21497 — mysql: MySQL Server (InnoDB): Denial of Service and Data Modification via network access CVE-2025-21500 — mysql: Optimizer unspecified vulnerability (CPU Jan 2025) CVE-2025-21501 — mysql: MySQL Server: Denial of Service vulnerability CVE-2025-21503 — mysql: InnoDB unspecified vulnerability (CPU Jan 2025) CVE-2025-21504 — mysql: MySQL Server: Optimizer Denial of Service Vulnerability CVE-2025-21505 — mysql: Components Services unspecified vulnerability (CPU Jan 2025) CVE-2025-21518 — mysql: Optimizer unspecified vulnerability (CPU Jan 2025) CVE-2025-21519 — mysql: MySQL Server: Denial of Service vulnerability via network access CVE-2025-21520 — mysql: MySQL Server Options Vulnerability CVE-2025-21521 — mysql: MySQL Server: Denial of service in Thread Pooling component CVE-2025-21522 — mysql: Parser unspecified vulnerability (CPU Jan 2025) CVE-2025-21523 — mysql: InnoDB unspecified vulnerability (CPU Jan 2025) CVE-2025-21525 — mysql: MySQL Server: Denial of Service vulnerability via network access by a high privileged attacker CVE-2025-21529 — mysql: MySQL Server: Denial of service vulnerability via network access CVE-2025-21531 — mysql: MySQL Server: Denial of Service (DoS) via network access by a high privileged attacker CVE-2025-21534 — mysql: MySQL Server: Denial of Service vulnerability via network access CVE-2025-21536 — mysql: MySQL Server: Denial of service vulnerability allows high privileged attacker to crash the server via network. CVE-2025-21540 — mysql: MySQL Server: Unauthorized Data Modification and Read Access Vulnerability CVE-2025-21543 — mysql: MySQL Server: Denial of Service via network access CVE-2025-21546 — mysql: Privilege Misuse in MySQL Server Security Component CVE-2025-21555 — mysql: MySQL Server InnoDB Denial of Service and Unauthorized Data Modification Vulnerability CVE-2025-21559 — mysql: MySQL Server InnoDB Denial of Service and Unauthorized Data Modification Vulnerability

🎯 Affected products79

  • Red Hat CodeReady Linux Builder (v. 9)
  • Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-0:8.0.41-2.el9_5.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-0:8.0.41-2.el9_5.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-0:8.0.41-2.el9_5.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-0:8.0.41-2.el9_5.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-0:8.0.41-2.el9_5.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-common-0:8.0.41-2.el9_5.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-common-0:8.0.41-2.el9_5.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-common-0:8.0.41-2.el9_5.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-common-0:8.0.41-2.el9_5.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-debuginfo-0:8.0.41-2.el9_5.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 9)
  • mysql-debuginfo-0:8.0.41-2.el9_5.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-debuginfo-0:8.0.41-2.el9_5.ppc64le as a component of Red Hat CodeReady Linux Builder (v. 9)
  • mysql-debuginfo-0:8.0.41-2.el9_5.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-debuginfo-0:8.0.41-2.el9_5.s390x as a component of Red Hat CodeReady Linux Builder (v. 9)
  • mysql-debuginfo-0:8.0.41-2.el9_5.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-debuginfo-0:8.0.41-2.el9_5.x86_64 as a component of Red Hat CodeReady Linux Builder (v. 9)
  • mysql-debuginfo-0:8.0.41-2.el9_5.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-debugsource-0:8.0.41-2.el9_5.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 9)
  • mysql-debugsource-0:8.0.41-2.el9_5.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-debugsource-0:8.0.41-2.el9_5.ppc64le as a component of Red Hat CodeReady Linux Builder (v. 9)
  • mysql-debugsource-0:8.0.41-2.el9_5.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-debugsource-0:8.0.41-2.el9_5.s390x as a component of Red Hat CodeReady Linux Builder (v. 9)
  • mysql-debugsource-0:8.0.41-2.el9_5.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-debugsource-0:8.0.41-2.el9_5.x86_64 as a component of Red Hat CodeReady Linux Builder (v. 9)
  • mysql-debugsource-0:8.0.41-2.el9_5.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • mysql-devel-0:8.0.41-2.el9_5.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 9)
  • mysql-devel-0:8.0.41-2.el9_5.ppc64le as a component of Red Hat CodeReady Linux Builder (v. 9)
  • mysql-devel-0:8.0.41-2.el9_5.s390x as a component of Red Hat CodeReady Linux Builder (v. 9)
  • +49 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Red Hat build of curl uses OpenSSL, which is not included in the affected list of GnuTLS, Schannel, Secure Transport and mbedTLS. Inspect which TLS backend is in use by running: $ curl --version Check the reference for curl handled by the maintainers which may contain more relevant information around this vulnerability. Workaround: Avoid using the .netrc file together with redirects. Workaround: Restrict network access to the MySQL Server to trusted clients only.

🔗 References (54)