CVE-2021-2001
published 2021-01-20CVE-2021-2001: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.50 and prior, 5.7.30 and…
PriorityP422medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
2.21%
80.6th percentile
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.50 and prior, 5.7.30 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mysql-8.0 | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | mysql | 5.6.0 – 5.6.50 | — |
| oracle | mysql | 5.7.0 – 5.7.30 | — |
| oracle | mysql | 8.0.0 – 8.0.17 | — |
| oracle_corporation | mysql_server | — | — |
| oracle_corporation | mysql_server | — | — |
| oracle_corporation | mysql_server | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv4.9MEDIUM
vendor_redhat7.8HIGH
vendor_debian4.9LOW
vendor_oracle4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2r9w-7426-5qwr: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)
ghsa_unreviewed·2022-05-24
CVE-2021-2001 [MEDIUM] GHSA-2r9w-7426-5qwr: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.50 and prior, 5.7.30 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
OSV
CVE-2021-2001: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)
osv·2021-01-20·CVSS 4.9
CVE-2021-2001 [MEDIUM] CVE-2021-2001: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.50 and prior, 5.7.30 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Red Hat
kernel: smackfs: restrict bytes count in smk_set_cipso()
vendor_redhat·2024-05-21·CVSS 7.8
CVE-2021-47336 [HIGH] CWE-20 kernel: smackfs: restrict bytes count in smk_set_cipso()
kernel: smackfs: restrict bytes count in smk_set_cipso()
In the Linux kernel, the following vulnerability has been resolved:
smackfs: restrict bytes count in smk_set_cipso()
Oops, I failed to update subject line.
From 07571157c91b98ce1a4aa70967531e64b78e8346 Mon Sep 17 00:00:00 2001
Date: Mon, 12 Apr 2021 22:25:06 +0900
Subject: [PATCH] smackfs: restrict bytes count in smk_set_cipso()
Commit 7ef4c19d245f3dc2 ("smackfs: restrict bytes count in smackfs write
functions") missed that count > SMK_CIPSOMAX check applies to only
format == SMK_FIXED24_FMT case.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Ent
Red Hat
kernel: ARM: 9064/1: hw_breakpoint: Do not directly check the event's overflow_handler hook
vendor_redhat·2024-02-28·CVSS 5.5
CVE-2021-47006 [MEDIUM] CWE-253 kernel: ARM: 9064/1: hw_breakpoint: Do not directly check the event's overflow_handler hook
kernel: ARM: 9064/1: hw_breakpoint: Do not directly check the event's overflow_handler hook
In the Linux kernel, the following vulnerability has been resolved:
ARM: 9064/1: hw_breakpoint: Do not directly check the event's overflow_handler hook
The commit 1879445dfa7b ("perf/core: Set event's default
::overflow_handler()") set a default event->overflow_handler in
perf_event_alloc(), and replace the check event->overflow_handler with
is_default_overflow_handler(), but one is missing.
Currently, the bp->overflow_handler can not be NULL. As a result,
enable_single_step() is always not invoked.
Comments from Zhen Lei:
https://patchwork.kernel.org/project/linux-arm-kernel/patch/[email protected]/
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Red Hat
mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2021)
vendor_redhat·2021-01-19·CVSS 4.9
CVE-2021-2001 [MEDIUM] mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2021)
mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2021)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.50 and prior, 5.7.30 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Package: mysql (Red Hat Enterprise Linux 6) - Out of support scope
Package: mariadb (Red Hat Enterprise Linux 7) - Not affected
Package: maria
Oracle
Oracle Oracle MySQL Risk Matrix: Server: Optimizer — CVE-2021-2001
vendor_oracle·2021-01-15·CVSS 4.9
CVE-2021-2001 [MEDIUM] Oracle Oracle MySQL Risk Matrix: Server: Optimizer — CVE-2021-2001
Oracle Oracle MySQL Risk Matrix: Server: Optimizer vulnerability
CVE: CVE-2021-2001
CVSS: 4.9
Protocol: MySQL Protocol
Remote exploit: No
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Debian
CVE-2021-2001: mysql-8.0 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...
vendor_debian·2021·CVSS 4.9
CVE-2021-2001 [MEDIUM] CVE-2021-2001: mysql-8.0 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.50 and prior, 5.7.30 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CS5THZSGI7O2CZO44NWYE57AG2T7NK3K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T7EAHJPWOOF4D6PEFLXW5IQWRRSZ3HRC/https://security.gentoo.org/glsa/202105-27https://security.netapp.com/advisory/ntap-20210219-0003/https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CS5THZSGI7O2CZO44NWYE57AG2T7NK3K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T7EAHJPWOOF4D6PEFLXW5IQWRRSZ3HRC/https://security.gentoo.org/glsa/202105-27https://security.netapp.com/advisory/ntap-20210219-0003/https://www.oracle.com/security-alerts/cpujan2021.html
2021-01-20
Published