Home / mailingsPDF  

[USN-8457-1] MySQL vulnerabilities

Posted on 22 June 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8457-1
June 22, 2026

mysql-8.0, mysql-8.4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 25.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in MySQL.

Software Description:
- mysql-8.4: MySQL database
- mysql-8.0: MySQL database

Details:

It was discovered that MySQL Router incorrectly handled repeated TLS
protocol upgrade requests. An unauthenticated remote attacker could
possibly use this issue to cause MySQL Router to crash, resulting in a
denial of service. (CVE-2026-46862)

It was discovered that MySQL Server incorrectly handled connection
authentication. An unauthenticated remote attacker could possibly use this
issue to cause MySQL to crash, resulting in a denial of service.
(CVE-2026-46863)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
mysql-server 8.4.10-0ubuntu0.26.04.1

Ubuntu 25.10
mysql-server 8.4.10-0ubuntu0.25.10.1

Ubuntu 24.04 LTS
mysql-server-8.0 8.0.46-0ubuntu0.24.04.3

Ubuntu 22.04 LTS
mysql-server-8.0 8.0.46-0ubuntu0.22.04.3

This update may use a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References:
https://ubuntu.com/security/notices/USN-8457-1
CVE-2026-46862, CVE-2026-46863

Package Information:
https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.10-0ubuntu0.26.04.1
https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.10-0ubuntu0.25.10.1
https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.3
https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.3

--===============1645864960219031724==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP