vulnerability

Red Hat: CVE-2025-53040: mysql: Optimizer unspecified vulnerability (CPU Oct 2025) (Multiple Advisories)

Severity
6
CVSS
(AV:N/AC:L/Au:M/C:N/I:N/A:C)
Published
Oct 21, 2025
Added
Dec 11, 2025
Modified
Dec 12, 2025

Description

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

Solutions

redhat-upgrade-mecabredhat-upgrade-mecab-debuginforedhat-upgrade-mecab-debugsourceredhat-upgrade-mecab-develredhat-upgrade-mecab-ipadicredhat-upgrade-mecab-ipadic-eucjpredhat-upgrade-mysqlredhat-upgrade-mysql-commonredhat-upgrade-mysql-debuginforedhat-upgrade-mysql-debugsourceredhat-upgrade-mysql-develredhat-upgrade-mysql-devel-debuginforedhat-upgrade-mysql-errmsgredhat-upgrade-mysql-libsredhat-upgrade-mysql-libs-debuginforedhat-upgrade-mysql-serverredhat-upgrade-mysql-server-debuginforedhat-upgrade-mysql-testredhat-upgrade-mysql-test-dataredhat-upgrade-mysql-test-debuginforedhat-upgrade-mysql8-4redhat-upgrade-mysql8-4-commonredhat-upgrade-mysql8-4-debuginforedhat-upgrade-mysql8-4-debugsourceredhat-upgrade-mysql8-4-develredhat-upgrade-mysql8-4-devel-debuginforedhat-upgrade-mysql8-4-errmsgredhat-upgrade-mysql8-4-libsredhat-upgrade-mysql8-4-libs-debuginforedhat-upgrade-mysql8-4-serverredhat-upgrade-mysql8-4-server-debuginforedhat-upgrade-mysql8-4-testredhat-upgrade-mysql8-4-test-dataredhat-upgrade-mysql8-4-test-debuginforedhat-upgrade-rapidjson-develredhat-upgrade-rapidjson-doc
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.