<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T10:16:31.498002+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:1671</id>
    <title>ALSA-2025:1671 — Important: mysql security update</title>
    <updated>2026-10-04T10:16:31.545376+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: mysql, AlmaLinux:9: mysql-common, AlmaLinux:9: mysql-devel, AlmaLinux:9: mysql-errmsg, AlmaLinux:9: mysql-libs, AlmaLinux:9: mysql-server, AlmaLinux:9: mysql-test</p>
<p>MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries.</p>
<p>Security Fix(es):</p>
<p>* openssl: SSL_select_next_proto buffer overread (CVE-2024-5535)
  * krb5: GSS message token handling (CVE-2024-37371)
  * curl: libcurl: ASN.1 date parser overread (CVE-2024-7264)
  * mysql: Thread Pooling unspecified vulnerability (CPU Oct 2024) (CVE-2024-21238)
  * mysql: X Plugin unspecified vulnerability (CPU Oct 2024) (CVE-2024-21196)
  * mysql: Optimizer unspecified vulnerability (CPU Oct 2024) (CVE-2024-21241)
  * mysql: Client programs unspecified vulnerability (CPU Oct 2024) (CVE-2024-21231)
  * mysql: Information Schema unspecified vulnerability (CPU Oct 2024) (CVE-2024-21197)
  * mysql: InnoDB unspecified vulnerability (CPU Oct 2024) (CVE-2024-21218)
  * mysql: Optimizer unspecified vulnerability (CPU Oct 2024) (CVE-2024-21201)
  * mysql: InnoDB unspecified vulnerability (CPU Oct 2024) (CVE-2024-21236)
  * mysql: Group Replication GCS unspecified vulnerability (CPU Oct 2024) (CVE-2024-21237)
  * mysql: FTS unspecified vulnerability (CPU Oct 2024) (CVE-2024-21203)
  * mysql: Health Monitor unspecified vulnerability (CPU Oct 2024) (CVE-2024-21212)
  * mysql: DML unspecified vulnerability (CPU Oct 2024) (CVE-2024-21219)
  * mysql: Optimizer unspecified vulnerability (CPU Oct 2024) (CVE-2024-21230)
  * mysql: InnoDB unspecified vulnerability (CPU Oct 2024) (CVE-2024-21213)
  * mysql: InnoDB unspec…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:1671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-00625</id>
    <title>bdu:2025-00625</title>
    <updated>2026-10-04T10:16:31.545485+00:00</updated>
    <content>bdu:2025-00625</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-00625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-21490</id>
    <title>BELL-CVE-2025-21490</title>
    <updated>2026-10-04T10:16:31.545504+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: mariadb, Alpaquita:stream: mariadb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-21490"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-mariadb-2025-21490</id>
    <title>BIT-mariadb-2025-21490</title>
    <updated>2026-10-04T10:16:31.545524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: mariadb</p>
<p>Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-mariadb-2025-21490"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0054</id>
    <title>certfr-2025-avi-0054 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Elles permettent à un attaquant de provoquer un déni…</title>
    <updated>2026-10-04T10:16:31.545546+00:00</updated>
    <content>certfr-2025-avi-0054</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0054"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-02309</id>
    <title>cnvd-2025-02309</title>
    <updated>2026-10-04T10:16:31.545562+00:00</updated>
    <content>cnvd-2025-02309</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-02309"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258219</id>
    <title>EUVD-2026-258219</title>
    <updated>2026-10-04T10:16:31.545573+00:00</updated>
    <content>EUVD-2026-258219</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258219"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21490</id>
    <title>fkie_cve-2025-21490</title>
    <updated>2026-10-04T10:16:31.545582+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-21490"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rh26-2566-h5m7</id>
    <title>GHSA-rh26-2566-h5m7</title>
    <updated>2026-10-04T10:16:31.545604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rh26-2566-h5m7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21490</id>
    <title>msrc_CVE-2025-21490 — Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected ar…</title>
    <updated>2026-10-04T10:16:31.545620+00:00</updated>
    <content>msrc_CVE-2025-21490</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-21490"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1103</id>
    <title>OESA-2025-1103 — mysql security update</title>
    <updated>2026-10-04T10:16:31.545638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: mysql, openEuler:22.03-LTS-SP4: mysql, openEuler:24.03-LTS: mysql, openEuler:24.03-LTS-SP1: mysql, openEuler:20.03-LTS-SP4: mysql</p>
<p>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MySQL client programs and generic MySQL files. %if

Security Fix(es):</p>
<p>Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).(CVE-2025-21490)</p>
<p>Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).(CVE-2025-21491)</p>
<p>Vulnera…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14826-1</id>
    <title>openSUSE-SU-2025:14826-1 — libmariadbd-devel-11.7.2-1.1 on GA media</title>
    <updated>2026-10-04T10:16:31.545754+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libmariadbd-devel-11.7.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14826-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:0335</id>
    <title>RHSA-2026:0335 — Red Hat Security Advisory: mariadb:10.11 security update</title>
    <updated>2026-10-04T10:16:31.545772+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mariadb: MariaDB Server Crash Due to Empty Backtrace Log mariadb: MariaDB Server Crash via Item_direct_view_ref mariadb: MariaDB Server Crash mysql: Client: mysqldump unspecified vulnerability (CPU Apr 2024) mariadb: MariaDB: mariadb-dump utility vulnerable to remote code execution via improper path validation mysql: mariadb: High Privilege Denial of Service Vulnerability in MySQL Server (CPU Jan 2025) mysql: mariadb: InnoDB unspecified vulnerability (CPU Apr 2025) mysql: mariadb: mysqldump unspecified vulnerability (CPU Apr 2025) mysql: Optimizer unspecified vulnerability (CPU Jan 2026)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:0335"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01716-1</id>
    <title>SUSE-SU-2025:01716-1 — Security update for mariadb</title>
    <updated>2026-10-04T10:16:31.545800+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for mariadb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01716-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21490</id>
    <title>UBUNTU-CVE-2025-21490</title>
    <updated>2026-10-04T10:16:31.545815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: mysql-5.5, Ubuntu:Pro:16.04:LTS: mysql-5.7, Ubuntu:16.04:LTS: mariadb-10.0, Ubuntu:16.04:LTS: percona-server-5.6, Ubuntu:16.04:LTS: percona-xtradb-cluster-5.6, Ubuntu:Pro:18.04:LTS: mysql-5.7, Ubuntu:18.04:LTS: mariadb-10.1, Ubuntu:20.04:LTS: mysql-8.0, Ubuntu:20.04:LTS: mariadb-10.3, Ubuntu:22.04:LTS: mariadb-10.6 and 3 more</p>
<p>Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21490"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0167</id>
    <title>WID-SEC-W-2025-0167 — Oracle MySQL: Mehrere Schwachstellen</title>
    <updated>2026-10-04T10:16:31.545854+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0167"/>
  </entry>
</feed>
