Bug 2319437 - mysql8.0: Oracle CPU 2024-10 [fedora-all]
Summary: mysql8.0: Oracle CPU 2024-10 [fedora-all]
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: mysql8.0
Version: 40
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Michal Schorm
QA Contact:
URL:
Whiteboard: {"flaws": ["1665c19e-24d5-4487-a02e-1...
Depends On:
Blocks: CVE-2024-5535 CVE-2024-37371 CVE-2024-7264 CVE-2024-21238 CVE-2024-21196 CVE-2024-21241 CVE-2024-21231 CVE-2024-21197 CVE-2024-21218 CVE-2024-21201 CVE-2024-21236 CVE-2024-21237 CVE-2024-21203 CVE-2024-21212 CVE-2024-21219 CVE-2024-21230 CVE-2024-21213 CVE-2024-21194 CVE-2024-21199 CVE-2024-21193 CVE-2024-21198 CVE-2024-21247 CVE-2024-21239 CVE-2025-21504 CVE-2025-21525 CVE-2025-21536 CVE-2025-21521 CVE-2025-21534 CVE-2025-21494
TreeView+ depends on / blocked
 
Reported: 2024-10-17 17:14 UTC by Mauro Matteo Cascella
Modified: 2025-01-24 11:09 UTC (History)
5 users (show)

Fixed In Version: mysql8.0-8.0.40-1.fc41 mysql8.0-8.0.40-1.fc40
Clone Of:
Environment:
Last Closed: 2024-11-02 02:23:44 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Mauro Matteo Cascella 2024-10-17 17:14:15 UTC
More information about this security flaw is available in the following bug:

https://bugzilla.redhat.com/show_bug.cgi?id=2318900

Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Mauro Matteo Cascella 2024-10-21 10:20:54 UTC
This tracking bug is for CVEs fixed upstream in MySQL 8.0.40 (Oracle CPU Oct 2024):
https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL

Comment 2 Fedora Update System 2024-10-24 23:24:43 UTC
FEDORA-2024-0c1c9227e5 (mysql8.0-8.0.40-1.fc40) has been submitted as an update to Fedora 40.
https://bodhi.fedoraproject.org/updates/FEDORA-2024-0c1c9227e5

Comment 3 Fedora Update System 2024-10-24 23:24:44 UTC
FEDORA-2024-9bef6cc6d4 (mysql8.0-8.0.40-1.fc41) has been submitted as an update to Fedora 41.
https://bodhi.fedoraproject.org/updates/FEDORA-2024-9bef6cc6d4

Comment 4 Fedora Update System 2024-10-25 01:41:16 UTC
FEDORA-2024-9bef6cc6d4 has been pushed to the Fedora 41 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-9bef6cc6d4`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-9bef6cc6d4

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2024-10-25 01:56:54 UTC
FEDORA-2024-0c1c9227e5 has been pushed to the Fedora 40 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-0c1c9227e5`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-0c1c9227e5

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2024-11-02 02:23:44 UTC
FEDORA-2024-9bef6cc6d4 (mysql8.0-8.0.40-1.fc41) has been pushed to the Fedora 41 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 7 Fedora Update System 2024-11-02 03:32:04 UTC
FEDORA-2024-0c1c9227e5 (mysql8.0-8.0.40-1.fc40) has been pushed to the Fedora 40 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 8 Mauro Matteo Cascella 2025-01-24 11:08:47 UTC
Attaching CVE-2024-37371, CVE-2025-21521, CVE-2025-21525, CVE-2025-21504, CVE-2025-21536, CVE-2025-21534, CVE-2025-21494 (fixed in MySQL 8.0.40) from Oracle CPU Jan 2025:
https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL


Note You need to log in before you can comment on or make changes to this bug.