CVE Vulnerabilities

CVE-2021-2390

Integer Underflow (Wrap or Wraparound)

Published: Jul 21, 2021 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.1 HIGH
AV:N/AC:M/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

NameVendorStart VersionEnd Version
Mysql_serverOracle5.7.0 (including)5.7.34 (including)
Mysql_serverOracle8.0.0 (including)8.0.25 (including)
Red Hat Enterprise Linux 8RedHatmysql:8.0-8040020210824134700.522a0ee4*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mysql80-mysql-0:8.0.26-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSRedHatrh-mysql80-mysql-0:8.0.26-1.el7*
Mariadb-10.3Ubuntugroovy*
Mariadb-5.5Ubuntutrusty*
Mysql-5.5Ubuntuesm-infra-legacy/trusty*
Mysql-5.5Ubuntutrusty*
Mysql-5.5Ubuntutrusty/esm*
Mysql-5.6Ubuntutrusty*
Mysql-5.7Ubuntubionic*
Mysql-5.7Ubuntuesm-infra/bionic*
Mysql-5.7Ubuntuesm-infra/xenial*
Mysql-5.7Ubuntuupstream*
Mysql-5.7Ubuntuxenial*
Mysql-8.0Ubuntuesm-infra/focal*
Mysql-8.0Ubuntufocal*
Mysql-8.0Ubuntugroovy*
Mysql-8.0Ubuntuhirsute*
Mysql-8.0Ubuntuimpish*
Mysql-8.0Ubuntujammy*
Mysql-8.0Ubuntukinetic*
Mysql-8.0Ubuntulunar*
Mysql-8.0Ubuntumantic*
Mysql-8.0Ubuntunoble*
Mysql-8.0Ubuntuoracular*
Mysql-8.0Ubuntuupstream*
Percona-server-5.6Ubuntuesm-apps/xenial*
Percona-server-5.6Ubuntuxenial*
Percona-xtradb-cluster-5.5Ubuntutrusty*
Percona-xtradb-cluster-5.6Ubuntuesm-apps/xenial*
Percona-xtradb-cluster-5.6Ubuntuxenial*

References