CVE-2026-21937

medium
Published 2026-03-17 ยท Modified 2026-04-01
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.5

Description

RHSA-2026:6391: mysql:8.4 security update (Moderate)

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description mysql: DDL unspecified vulnerability (CPU Jan 2026) Red Hat statement Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update. CVSS v3: 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 10mysql8.4-0:8.4.8-1.el10_1RHSA-2026:41622026-03-10T00:00:00Zโ€ฆ

Description

mysql: DDL unspecified vulnerability (CPU Jan 2026)

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.

CVSS v3: 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10mysql8.4-0:8.4.8-1.el10_1RHSA-2026:41622026-03-10T00:00:00Z
Red Hat Enterprise Linux 8mysql:8.0-8100020260223150324.489197e6RHSA-2026:55802026-03-24T00:00:00Z
Red Hat Enterprise Linux 8mysql:8.4-8100020260219114250.489197e6RHSA-2026:63912026-04-01T00:00:00Z
Red Hat Enterprise Linux 9mysql-0:8.0.45-1.el9_7RHSA-2026:48282026-03-17T00:00:00Z
Red Hat Enterprise Linux 9mysql:8.4-9070020260313201256.rhel9RHSA-2026:56402026-03-24T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6mysqlNot affected

Apply commands

bash fix
Apply RHSA-2026:4162 for Red Hat Enterprise Linux 10
yum update -y mysql8
# or:
dnf upgrade -y mysql8

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Not affected

OS impact

OSVersionStatusFixed in
rockylinux rocky8fixed
redhat rhel9fixed
suse slesaffected
rockylinux rocky9fixed
debian debiansidfixed8.0.45-1
almalinux almalinux9fixedmysql-test-8.4.8-1.module_el9.7.0+219+aca48cd3.aarch64.rpm
almalinux almalinux8fixedmysql-devel-8.0.45-1.module_el8.10.0+4142+0b28b031.aarch64.rpm
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.