- Issued:
- 2021-10-12
- Updated:
- 2021-10-12
RHSA-2021:3811 - Moderate: rh-mysql80-mysql security, bug fix, and enhancement update
Synopsis
Moderate: rh-mysql80-mysql security, bug fix, and enhancement update
Type/Severity
Security Advisory Moderate
Topic
An update for rh-mysql80-mysql is now available for Red Hat Software Collections.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon, mysqld, and many client programs.
The following packages have been upgraded to a later upstream version: rh-mysql80-mysql (8.0.26). (BZ#2003105)
Security Fix(es):
-
mysql: Server: Stored Procedure multiple vulnerabilities (CVE-2020-14672, CVE-2021-2046, CVE-2021-2072, CVE-2021-2081, CVE-2021-2215, CVE-2021-2217, CVE-2021-2293, CVE-2021-2304, CVE-2021-2424)
-
mysql: Server: FTS multiple vulnerabilities (CVE-2020-14765, CVE-2020-14789, CVE-2020-14804)
-
mysql: Server: Optimizer multiple vulnerabilities (CVE-2020-14769, CVE-2020-14773, CVE-2020-14777, CVE-2020-14785, CVE-2020-14793, CVE-2020-14794, CVE-2020-14809, CVE-2020-14830, CVE-2020-14836, CVE-2020-14837, CVE-2020-14839, CVE-2020-14845, CVE-2020-14846, CVE-2020-14861, CVE-2020-14866, CVE-2020-14868, CVE-2020-14888, CVE-2020-14891, CVE-2020-14893, CVE-2021-2001, CVE-2021-2021, CVE-2021-2024, CVE-2021-2030, CVE-2021-2031, CVE-2021-2036, CVE-2021-2055, CVE-2021-2060, CVE-2021-2065, CVE-2021-2070, CVE-2021-2076, CVE-2021-2164, CVE-2021-2169, CVE-2021-2170, CVE-2021-2193, CVE-2021-2203, CVE-2021-2212, CVE-2021-2213, CVE-2021-2230, CVE-2021-2278, CVE-2021-2298, CVE-2021-2299, CVE-2021-2342, CVE-2021-2357, CVE-2021-2367, CVE-2021-2383, CVE-2021-2384, CVE-2021-2387, CVE-2021-2410, CVE-2021-2412, CVE-2021-2418, CVE-2021-2425, CVE-2021-2426, CVE-2021-2427, CVE-2021-2437, CVE-2021-2441, CVE-2021-2444)
-
mysql: InnoDB multiple vulnerabilities (CVE-2020-14775, CVE-2020-14776, CVE-2020-14821, CVE-2020-14829, CVE-2020-14848, CVE-2021-2022, CVE-2021-2028, CVE-2021-2048, CVE-2021-2174, CVE-2021-2180, CVE-2021-2194, CVE-2021-2372, CVE-2021-2374, CVE-2021-2389, CVE-2021-2390, CVE-2021-2429, CVE-2020-14791, CVE-2021-2042)
-
mysql: Server: PS multiple vulnerabilities (CVE-2020-14786, CVE-2020-14790, CVE-2020-14844, CVE-2021-2422)
-
mysql: Server: Security multiple vulnerabilities (CVE-2020-14800, CVE-2020-14838, CVE-2020-14860)
-
mysql: Server: Locking multiple vulnerabilities (CVE-2020-14812, CVE-2021-2058, CVE-2021-2402)
-
mysql: Server: DML multiple vulnerabilities (CVE-2020-14814, CVE-2020-14828, CVE-2021-2056, CVE-2021-2087, CVE-2021-2088, CVE-2021-2166, CVE-2021-2172, CVE-2021-2196, CVE-2021-2300, CVE-2021-2305, CVE-2021-2370, CVE-2021-2440)
-
mysql: Server: Charsets unspecified vulnerability (CVE-2020-14852)
-
mysql: Server: DDL multiple vulnerabilities (CVE-2020-14867, CVE-2021-2061, CVE-2021-2122, CVE-2021-2339, CVE-2021-2352, CVE-2021-2399)
-
mysql: Server: X Plugin unspecified vulnerability (CVE-2020-14870)
-
mysql: Server: Logging unspecified vulnerability (CVE-2020-14873)
-
mysql: Server: Replication multiple vulnerabilities (CVE-2021-2002, CVE-2021-2171, CVE-2021-2178, CVE-2021-2202, CVE-2021-2356, CVE-2021-2385)
-
mysql: C API multiple vulnerabilities (CVE-2021-2010, CVE-2021-2011)
-
mysql: Server: Components Services unspecified vulnerability (CVE-2021-2038)
-
mysql: Server: Options unspecified vulnerability (CVE-2021-2146)
-
mysql: Server: Group Replication Plugin multiple vulnerabilities (CVE-2021-2179, CVE-2021-2232)
-
mysql: Server: Partition multiple vulnerabilities (CVE-2021-2201, CVE-2021-2208)
-
mysql: Server: Information Schema multiple vulnerabilities (CVE-2021-2032, CVE-2021-2226, CVE-2021-2301, CVE-2021-2308)
-
mysql: Server: Packaging unspecified vulnerability (CVE-2021-2307)
-
mysql: Server: Federated unspecified vulnerability (CVE-2021-2354)
-
mysql: Server: GIS unspecified vulnerability (CVE-2021-2417)
-
mysql: Server: Memcached unspecified vulnerability (CVE-2021-2340)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
- Segfault and possible DoS with a crafted query (BZ#2003100)
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing this update, the MySQL server daemon (mysqld) will be restarted automatically.
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Software Collections (for RHEL Workstation) | 1 | x86_64 |
| Red Hat Software Collections (for RHEL Server) | 1 | x86_64 |
| Red Hat Software Collections (for RHEL Server) | 1 | x86_64 |
| Red Hat Software Collections (for RHEL Server for System Z) | 1 | s390x |
| Red Hat Software Collections (for RHEL Server for System Z) | 1 | s390x |
| Red Hat Software Collections (for RHEL Server for IBM Power LE) | 1 | ppc64le |
| Red Hat Software Collections (for RHEL Server for IBM Power LE) | 1 | ppc64le |
Updated Packages
- rh-mysql80-mysql-config-8.0.26-1.el7.ppc64le.rpm
- rh-mysql80-mysql-syspaths-8.0.26-1.el7.x86_64.rpm
- rh-mysql80-mysql-debuginfo-8.0.26-1.el7.s390x.rpm
- rh-mysql80-mysql-server-syspaths-8.0.26-1.el7.s390x.rpm
- rh-mysql80-mysql-test-8.0.26-1.el7.s390x.rpm
- rh-mysql80-mysql-server-syspaths-8.0.26-1.el7.ppc64le.rpm
- rh-mysql80-mysql-test-8.0.26-1.el7.ppc64le.rpm
- rh-mysql80-mysql-common-8.0.26-1.el7.x86_64.rpm
- rh-mysql80-mysql-server-8.0.26-1.el7.ppc64le.rpm
- rh-mysql80-mysql-server-8.0.26-1.el7.s390x.rpm
- rh-mysql80-mysql-server-8.0.26-1.el7.x86_64.rpm
- rh-mysql80-mysql-8.0.26-1.el7.s390x.rpm
- rh-mysql80-mysql-config-syspaths-8.0.26-1.el7.x86_64.rpm
- rh-mysql80-mysql-8.0.26-1.el7.src.rpm
- rh-mysql80-mysql-devel-8.0.26-1.el7.ppc64le.rpm
- rh-mysql80-mysql-config-syspaths-8.0.26-1.el7.s390x.rpm
- rh-mysql80-mysql-devel-8.0.26-1.el7.x86_64.rpm
- rh-mysql80-mysql-errmsg-8.0.26-1.el7.ppc64le.rpm
- rh-mysql80-mysql-config-syspaths-8.0.26-1.el7.ppc64le.rpm
- rh-mysql80-mysql-config-8.0.26-1.el7.x86_64.rpm
- rh-mysql80-mysql-debuginfo-8.0.26-1.el7.x86_64.rpm
- rh-mysql80-mysql-errmsg-8.0.26-1.el7.s390x.rpm
- rh-mysql80-mysql-server-syspaths-8.0.26-1.el7.x86_64.rpm
- rh-mysql80-mysql-syspaths-8.0.26-1.el7.ppc64le.rpm
- rh-mysql80-mysql-common-8.0.26-1.el7.ppc64le.rpm
- rh-mysql80-mysql-common-8.0.26-1.el7.s390x.rpm
- rh-mysql80-mysql-config-8.0.26-1.el7.s390x.rpm
- rh-mysql80-mysql-syspaths-8.0.26-1.el7.s390x.rpm
- rh-mysql80-mysql-devel-8.0.26-1.el7.s390x.rpm
- rh-mysql80-mysql-errmsg-8.0.26-1.el7.x86_64.rpm
- rh-mysql80-mysql-8.0.26-1.el7.x86_64.rpm
- rh-mysql80-mysql-debuginfo-8.0.26-1.el7.ppc64le.rpm
- rh-mysql80-mysql-test-8.0.26-1.el7.x86_64.rpm
- rh-mysql80-mysql-8.0.26-1.el7.ppc64le.rpm
Fixes
- This content is not included.BZ - 1890737
- This content is not included.BZ - 1890738
- This content is not included.BZ - 1890739
- This content is not included.BZ - 1890742
- This content is not included.BZ - 1890743
- This content is not included.BZ - 1890744
- This content is not included.BZ - 1890745
- This content is not included.BZ - 1890746
- This content is not included.BZ - 1890747
- This content is not included.BZ - 1890748
- This content is not included.BZ - 1890749
- This content is not included.BZ - 1890750
- This content is not included.BZ - 1890751
- This content is not included.BZ - 1890753
- This content is not included.BZ - 1890754
- This content is not included.BZ - 1890755
- This content is not included.BZ - 1890756
- This content is not included.BZ - 1890757
- This content is not included.BZ - 1890758
- This content is not included.BZ - 1890760
- This content is not included.BZ - 1890761
- This content is not included.BZ - 1890762
- This content is not included.BZ - 1890763
- This content is not included.BZ - 1890764
- This content is not included.BZ - 1890765
- This content is not included.BZ - 1890766
- This content is not included.BZ - 1890767
- This content is not included.BZ - 1890768
- This content is not included.BZ - 1890769
- This content is not included.BZ - 1890770
- This content is not included.BZ - 1890771
- This content is not included.BZ - 1890772
- This content is not included.BZ - 1890773
- This content is not included.BZ - 1890774
- This content is not included.BZ - 1890775
- This content is not included.BZ - 1890776
- This content is not included.BZ - 1890778
- This content is not included.BZ - 1890779
- This content is not included.BZ - 1890781
- This content is not included.BZ - 1890782
- This content is not included.BZ - 1890783
- This content is not included.BZ - 1890784
- This content is not included.BZ - 1922379
- This content is not included.BZ - 1922380
- This content is not included.BZ - 1922383
- This content is not included.BZ - 1922384
- This content is not included.BZ - 1922388
- This content is not included.BZ - 1922389
- This content is not included.BZ - 1922390
- This content is not included.BZ - 1922391
- This content is not included.BZ - 1922392
- This content is not included.BZ - 1922393
- This content is not included.BZ - 1922394
- This content is not included.BZ - 1922395
- This content is not included.BZ - 1922396
- This content is not included.BZ - 1922397
- This content is not included.BZ - 1922398
- This content is not included.BZ - 1922399
- This content is not included.BZ - 1922400
- This content is not included.BZ - 1922401
- This content is not included.BZ - 1922402
- This content is not included.BZ - 1922403
- This content is not included.BZ - 1922404
- This content is not included.BZ - 1922405
- This content is not included.BZ - 1922406
- This content is not included.BZ - 1922407
- This content is not included.BZ - 1922408
- This content is not included.BZ - 1922410
- This content is not included.BZ - 1922411
- This content is not included.BZ - 1922416
- This content is not included.BZ - 1922419
- This content is not included.BZ - 1951751
- This content is not included.BZ - 1951754
- This content is not included.BZ - 1951755
- This content is not included.BZ - 1951756
- This content is not included.BZ - 1951757
- This content is not included.BZ - 1951758
- This content is not included.BZ - 1951759
- This content is not included.BZ - 1951760
- This content is not included.BZ - 1951761
- This content is not included.BZ - 1951762
- This content is not included.BZ - 1951763
- This content is not included.BZ - 1951764
- This content is not included.BZ - 1951765
- This content is not included.BZ - 1951766
- This content is not included.BZ - 1951767
- This content is not included.BZ - 1951768
- This content is not included.BZ - 1951769
- This content is not included.BZ - 1951770
- This content is not included.BZ - 1951771
- This content is not included.BZ - 1951772
- This content is not included.BZ - 1951773
- This content is not included.BZ - 1951774
- This content is not included.BZ - 1951775
- This content is not included.BZ - 1951776
- This content is not included.BZ - 1951777
- This content is not included.BZ - 1951778
- This content is not included.BZ - 1951779
- This content is not included.BZ - 1951780
- This content is not included.BZ - 1951781
- This content is not included.BZ - 1951782
- This content is not included.BZ - 1951783
- This content is not included.BZ - 1951784
- This content is not included.BZ - 1951785
- This content is not included.BZ - 1951786
- This content is not included.BZ - 1952802
- This content is not included.BZ - 1992279
- This content is not included.BZ - 1992280
- This content is not included.BZ - 1992294
- This content is not included.BZ - 1992297
- This content is not included.BZ - 1992298
- This content is not included.BZ - 1992299
- This content is not included.BZ - 1992300
- This content is not included.BZ - 1992301
- This content is not included.BZ - 1992302
- This content is not included.BZ - 1992303
- This content is not included.BZ - 1992304
- This content is not included.BZ - 1992305
- This content is not included.BZ - 1992306
- This content is not included.BZ - 1992307
- This content is not included.BZ - 1992308
- This content is not included.BZ - 1992309
- This content is not included.BZ - 1992310
- This content is not included.BZ - 1992311
- This content is not included.BZ - 1992312
- This content is not included.BZ - 1992313
- This content is not included.BZ - 1992314
- This content is not included.BZ - 1992315
- This content is not included.BZ - 1992316
- This content is not included.BZ - 1992317
- This content is not included.BZ - 1992318
- This content is not included.BZ - 1992319
- This content is not included.BZ - 1992320
- This content is not included.BZ - 1992321
- This content is not included.BZ - 1992322
- This content is not included.BZ - 1992323
- This content is not included.BZ - 1992324
- This content is not included.BZ - 1992325
- This content is not included.BZ - 1992326
- This content is not included.BZ - 2003100
- This content is not included.BZ - 2003105
CVEs
- CVE-2020-14672
- CVE-2020-14765
- CVE-2020-14769
- CVE-2020-14773
- CVE-2020-14775
- CVE-2020-14776
- CVE-2020-14777
- CVE-2020-14785
- CVE-2020-14786
- CVE-2020-14789
- CVE-2020-14790
- CVE-2020-14791
- CVE-2020-14793
- CVE-2020-14794
- CVE-2020-14800
- CVE-2020-14804
- CVE-2020-14809
- CVE-2020-14812
- CVE-2020-14814
- CVE-2020-14821
- CVE-2020-14828
- CVE-2020-14829
- CVE-2020-14830
- CVE-2020-14836
- CVE-2020-14837
- CVE-2020-14838
- CVE-2020-14839
- CVE-2020-14844
- CVE-2020-14845
- CVE-2020-14846
- CVE-2020-14848
- CVE-2020-14852
- CVE-2020-14860
- CVE-2020-14861
- CVE-2020-14866
- CVE-2020-14867
- CVE-2020-14868
- CVE-2020-14870
- CVE-2020-14873
- CVE-2020-14888
- CVE-2020-14891
- CVE-2020-14893
- CVE-2021-2001
- CVE-2021-2002
- CVE-2021-2010
- CVE-2021-2011
- CVE-2021-2021
- CVE-2021-2022
- CVE-2021-2024
- CVE-2021-2028
- CVE-2021-2030
- CVE-2021-2031
- CVE-2021-2032
- CVE-2021-2036
- CVE-2021-2038
- CVE-2021-2042
- CVE-2021-2046
- CVE-2021-2048
- CVE-2021-2055
- CVE-2021-2056
- CVE-2021-2058
- CVE-2021-2060
- CVE-2021-2061
- CVE-2021-2065
- CVE-2021-2070
- CVE-2021-2072
- CVE-2021-2076
- CVE-2021-2081
- CVE-2021-2087
- CVE-2021-2088
- CVE-2021-2122
- CVE-2021-2146
- CVE-2021-2164
- CVE-2021-2166
- CVE-2021-2169
- CVE-2021-2170
- CVE-2021-2171
- CVE-2021-2172
- CVE-2021-2174
- CVE-2021-2178
- CVE-2021-2179
- CVE-2021-2180
- CVE-2021-2193
- CVE-2021-2194
- CVE-2021-2196
- CVE-2021-2201
- CVE-2021-2202
- CVE-2021-2203
- CVE-2021-2208
- CVE-2021-2212
- CVE-2021-2213
- CVE-2021-2215
- CVE-2021-2217
- CVE-2021-2226
- CVE-2021-2230
- CVE-2021-2232
- CVE-2021-2278
- CVE-2021-2293
- CVE-2021-2298
- CVE-2021-2299
- CVE-2021-2300
- CVE-2021-2301
- CVE-2021-2304
- CVE-2021-2305
- CVE-2021-2307
- CVE-2021-2308
- CVE-2021-2339
- CVE-2021-2340
- CVE-2021-2342
- CVE-2021-2352
- CVE-2021-2354
- CVE-2021-2356
- CVE-2021-2357
- CVE-2021-2367
- CVE-2021-2370
- CVE-2021-2372
- CVE-2021-2374
- CVE-2021-2383
- CVE-2021-2384
- CVE-2021-2385
- CVE-2021-2387
- CVE-2021-2389
- CVE-2021-2390
- CVE-2021-2399
- CVE-2021-2402
- CVE-2021-2410
- CVE-2021-2412
- CVE-2021-2417
- CVE-2021-2418
- CVE-2021-2422
- CVE-2021-2424
- CVE-2021-2425
- CVE-2021-2426
- CVE-2021-2427
- CVE-2021-2429
- CVE-2021-2437
- CVE-2021-2440
- CVE-2021-2441
- CVE-2021-2444
- CVE-2021-35537
- CVE-2021-35629
References
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.