Improper input validation in MySQL Server - CVE-2025-21521
Published: January 21, 2025
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Thread Pooling component in MySQL Server. A remote non-authenticated attacker can exploit this vulnerability to perform a denial of service (DoS) attack.
Affected software
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
mecab
mecab-ipadic
mecab-ipadic-EUCJP
mysql (Red Hat package)
mysql-common
mysql-test
mysql-server
mysql-libs
mysql-errmsg
mysql-devel
mysql
Dell EMC Storage Monitoring and Reporting (SMR)
Storage Resource Manager
How to mitigate CVE-2025-21521
mecab - update to 0.996-2
mecab-ipadic - update to 2.7.0.20070801-17.0.1
mecab-ipadic-EUCJP - update to 2.7.0.20070801-17.0.1
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
mysql (Red Hat package) - addressed in versions 8.0.40-1.el9_2.1, 8.0.40-1.el9_4, 8.0.40-2.el9_0, 8.0.41-2.el9_5
mysql-common - update to 8.0.41-1.0.1
mysql-test - update to 8.0.41-1.0.1
mysql-server - update to 8.0.41-1.0.1
mysql-libs - update to 8.0.41-1.0.1
mysql-errmsg - update to 8.0.41-1.0.1
mysql-devel - update to 8.0.41-1.0.1
mysql - update to 8.0.41-1.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in MySQL Server
- Red Hat Enterprise Linux 9 update for mysql
- Red Hat Enterprise Linux 8 update for the mysql:8.0 module
- Red Hat Enterprise Linux 9 update for mysql
- Red Hat Enterprise Linux 9 update for mysql
- Red Hat Enterprise Linux 8 update for the mysql:8.0 module
- Red Hat Enterprise Linux 8 update for the mysql:8.0 module
- Red Hat Enterprise Linux 9 update for mysql
- Red Hat Enterprise Linux 8 update for the mysql:8.0 module
- Red Hat Enterprise Linux 8 update for the mysql:8.0 module
- Anolis OS update for mysql:8.0 module
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)