Improper input validation in MySQL Server - CVE-2025-21566
Published: January 21, 2025
Vulnerability identifier: #VU103179
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-21566
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Optimizer component in MySQL Server. A remote authenticated user can exploit this vulnerability to perform a denial of service (DoS) attack.
Affected software
MySQL Server
Storage Resource Manager
Dell EMC Storage Monitoring and Reporting (SMR)
Storage Resource Manager
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2025-21566
Install updates from vendor's website.
MySQL Server - update to 9.2.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0