Skip to main content
Vulnerability Database/CVE-2025-50097

CVE-2025-50097: Oracle MySQL Server DOS Vulnerability

CVE-2025-50097 is a denial of service vulnerability in Oracle MySQL Server affecting versions 8.0.0-8.0.42, 8.4.0-8.4.5, and 9.0.0-9.3.0. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2025-50097 Overview

CVE-2025-50097 is a denial of service vulnerability in the Oracle MySQL Server product, specifically within the Server: Security: Encryption component. The flaw affects MySQL Server versions 8.0.0 through 8.0.42, 8.4.0 through 8.4.5, and 9.0.0 through 9.3.0. A high-privileged attacker with network access via multiple protocols can exploit the weakness to cause a hang or repeatable crash, resulting in a complete denial of service of the database server. The vulnerability is classified under [CWE-400] Uncontrolled Resource Consumption. Oracle addressed the issue in the July 2025 Critical Patch Update.

Critical Impact

Successful exploitation causes a complete denial of service (hang or repeatable crash) of the MySQL Server, disrupting all dependent applications and services.

Affected Products

  • Oracle MySQL Server 8.0.0 through 8.0.42
  • Oracle MySQL Server 8.4.0 through 8.4.5
  • Oracle MySQL Server 9.0.0 through 9.3.0

Discovery Timeline

  • 2025-07-15 - CVE-2025-50097 published to NVD as part of the Oracle July 2025 Critical Patch Update
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-50097

Vulnerability Analysis

The vulnerability resides in the encryption subsystem of Oracle MySQL Server. An authenticated attacker holding high privileges on the database instance can trigger a condition that causes the server process to hang or crash reliably. Because the flaw is network-reachable through multiple MySQL protocols, exploitation does not require local access to the host. The impact is limited to availability, with no confidentiality or integrity loss reported by Oracle. The classification as [CWE-400] Uncontrolled Resource Consumption indicates the server fails to constrain the resources consumed while handling specific encryption-related operations.

Root Cause

The root cause lies in how the MySQL Server encryption component processes certain requests or inputs. Under specific conditions, resource handling within this component enters an unbounded or failure state that either exhausts server resources or corrupts internal state, forcing the process to halt. Oracle has not published low-level technical details beyond the component location and impact scope.

Attack Vector

Exploitation requires network access to the MySQL Server and an authenticated account with high privileges. The attacker leverages one of the supported MySQL protocols to send crafted requests to the encryption subsystem. Repeated exploitation yields a reliable, complete denial of service. Because the attack complexity is low and no user interaction is required, any account already granted elevated database privileges represents a viable exploitation path.

No public proof-of-concept exploit code is available for CVE-2025-50097. Refer to the Oracle Critical Patch Update July 2025 advisory for vendor-authoritative technical guidance.

Detection Methods for CVE-2025-50097

Indicators of Compromise

  • Unexpected mysqld process crashes or hangs correlated with authenticated client sessions holding elevated privileges.
  • Recurring restarts of the MySQL Server service without corresponding administrative maintenance activity.
  • Error log entries from the encryption or InnoDB subsystems immediately preceding server termination.

Detection Strategies

  • Monitor MySQL error logs (hostname.err) for repeated abnormal shutdowns, assertion failures, or stack traces referencing encryption routines.
  • Correlate authenticated session activity with server termination events to identify accounts triggering repeatable crashes.
  • Alert on rapid succession of failed queries or protocol errors originating from a single high-privileged account.

Monitoring Recommendations

  • Enable the MySQL general query log and audit log to capture privileged operations against the server, particularly those touching encryption features.
  • Ingest MySQL logs and host telemetry into a centralized SIEM to correlate crash events with client identity and source IP.
  • Track service uptime metrics and set thresholds that alert on unplanned mysqld restarts.

How to Mitigate CVE-2025-50097

Immediate Actions Required

  • Apply the July 2025 Critical Patch Update from Oracle to all affected MySQL Server instances.
  • Inventory MySQL deployments and identify any instance running 8.0.0–8.0.42, 8.4.0–8.4.5, or 9.0.0–9.3.0.
  • Audit database accounts holding high privileges and revoke unnecessary elevated permissions.
  • Restrict network exposure of MySQL Server to trusted application hosts only.

Patch Information

Oracle released fixes for CVE-2025-50097 in the Oracle Critical Patch Update July 2025. Administrators should upgrade to a patched release within the 8.0.x, 8.4.x, or 9.x branch as documented in the advisory. Verify the running version after upgrade with SELECT VERSION();.

Workarounds

  • Enforce least-privilege access by removing administrative roles (for example SUPER, SYSTEM_VARIABLES_ADMIN, encryption-related privileges) from application service accounts.
  • Place MySQL Server behind a database firewall or network ACLs that limit connections to known application tier hosts.
  • Enable connection rate limiting and account resource limits (MAX_USER_CONNECTIONS, MAX_QUERIES_PER_HOUR) to constrain misuse by any single account.
  • Configure automated service recovery so the server restarts quickly if a crash occurs while patching is scheduled.
bash
# Configuration example: restrict privileges and enforce account resource limits
REVOKE SUPER ON *.* FROM 'app_user'@'%';
ALTER USER 'app_user'@'%' WITH MAX_USER_CONNECTIONS 20 MAX_QUERIES_PER_HOUR 5000;
FLUSH PRIVILEGES;

# Verify server version after applying the July 2025 CPU
mysql -u root -p -e "SELECT VERSION();"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.