Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in the RHEL 9-to-10 Leapp scan_mysql actor in leapp-repository / leapp-upgrade-el9toel10. The actor invokes mysqld --validate-config as root without dropping privileges to the packaged MySQL service identity (User=mysql). An attacker who already has OS-level code execution as the mysql service user can plant a version-2 persisted configuration (mysqld-auto.cnf) and a shared object under /var/lib/mysql, redirecting plugin_dir and setting early_plugin_load (or equivalent loader options). When an administrator later runs leapp preupgrade or leapp upgrade, MySQL can dlopen that attacker-controlled object before runtime-user and plugin-symbol checks, allowing an ELF constructor to execute as unconfined UID 0.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:67609 https://access.redhat.com/errata/RHSA-2026:67609
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:67608 https://access.redhat.com/errata/RHSA-2026:67608