Several security issues were fixed in MySQL.
Software Description:
- mysql-8.4: MySQL database
- mysql-8.0: MySQL database
Details:
It was discovered that MySQL Router incorrectly handled repeated TLS
protocol upgrade requests. An unauthenticated remote attacker could
possibly use this issue to cause MySQL Router to crash, resulting in a
denial of service. (CVE-2026-46862)
It was discovered that MySQL Server incorrectly handled connection
authentication. An unauthenticated remote attacker could possibly use this
issue to cause MySQL to crash, resulting in a denial of service.
(CVE-2026-46863)
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS mysql-server 8.4.10-0ubuntu0.26.04.1 Ubuntu 25.10 mysql-server 8.4.10-0ubuntu0.25.10.1 Ubuntu 24.04 LTS mysql-server-8.0 8.0.46-0ubuntu0.24.04.3 Ubuntu 22.04 LTS mysql-server-8.0 8.0.46-0ubuntu0.22.04.3 This update may use a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-8457-1
CVE-2026-46862, CVE-2026-46863
Get the latest Linux and open source security news straight to your inbox.