[security - medium] mysql:8.0 security update, rapidjson-1.1.0-6.module+el8+1989+b2d38253

エラータID: AXSA:2026-809:01

リリース日: 
2026/06/21 Sunday - 13:12
題名: 
[security - medium] mysql:8.0 security update, rapidjson-1.1.0-6.module+el8+1989+b2d38253
影響のあるチャネル: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries.

Security Fix(es):

* mysql: InnoDB unspecified vulnerability (CPU Apr 2026) (CVE-2026-22004)
* mysql: Information Schema unspecified vulnerability (CPU Apr 2026) (CVE-2026-22001)
* mysql: Group Replication Plugin unspecified vulnerability (CPU Apr 2026) (CVE-2026-34271)
* mysql: Optimizer unspecified vulnerability (CPU Apr 2026) (CVE-2026-22009)
* mysql: InnoDB unspecified vulnerability (CPU Apr 2026) (CVE-2026-35237)
* mysql: Optimizer unspecified vulnerability (CPU Apr 2026) (CVE-2026-21998)
* mysql: Optimizer unspecified vulnerability (CPU Apr 2026) (CVE-2026-22005)
* mysql: InnoDB unspecified vulnerability (CPU Apr 2026) (CVE-2026-35238)
* mysql: DML unspecified vulnerability (CPU Apr 2026) (CVE-2026-35239)
* mysql: Optimizer unspecified vulnerability (CPU Apr 2026) (CVE-2026-22002)
* mysql: InnoDB unspecified vulnerability (CPU Apr 2026) (CVE-2026-35236)
* mysql: JSON unspecified vulnerability (CPU Apr 2026) (CVE-2026-34308)
* mysql: Optimizer unspecified vulnerability (CPU Apr 2026) (CVE-2026-34303)
* mysql: DML unspecified vulnerability (CPU Apr 2026) (CVE-2026-34293)
* mysql: Optimizer unspecified vulnerability (CPU Apr 2026) (CVE-2026-35240)
* mysql: Optimizer unspecified vulnerability (CPU Apr 2026) (CVE-2026-34267)
* mysql: Optimizer unspecified vulnerability (CPU Apr 2026) (CVE-2026-22017)
* mysql: InnoDB unspecified vulnerability (CPU Apr 2026) (CVE-2026-34304)
* mysql: Information Schema unspecified vulnerability (CPU Apr 2026) (CVE-2026-22015)
* mysql: Group Replication Plugin unspecified vulnerability (CPU Apr 2026) (CVE-2026-34276)
* mysql: Group Replication Plugin unspecified vulnerability (CPU Apr 2026) (CVE-2026-34270)
* mysql: Optimizer unspecified vulnerability (CPU Apr 2026) (CVE-2026-34278)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-21998
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-22001
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
CVE-2026-22002
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-22004
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-22005
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-22009
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-22015
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
CVE-2026-22017
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34267
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34270
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34271
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34276
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34278
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34293
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34303
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34304
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34308
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-35236
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-35237
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-35238
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-35239
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-35240
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

Modularity name: "mysql"
Stream name: "8.0"

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. mecab-ipadic-2.7.0.20070801-17.module+el8+1989+b2d38253.src.rpm
    MD5: c492c3cd004d4b7d88dc7373c77f9703
    SHA-256: 80bc3b576ef6f162371ed6e2e33e58e762872fe0ed6aa6bdef9309f13ee93c13
    Size: 10.54 MB
  2. mecab-0.996-2.module+el8+1989+b2d38253.src.rpm
    MD5: 5dbda2eb52248523ca98117078ceaf6c
    SHA-256: 556feedaac7a1fa2b64413ff717cc3ee8bf4a839d5c0a1fa4572f77c2f5be7db
    Size: 960.68 kB
  3. mysql-8.0.46-1.module+el8+1989+b2d38253.ML.1.src.rpm
    MD5: 12730bcd281e6fa47cbe75b2d0b2880b
    SHA-256: fb597bf2b286444361d48f3ce8e8abeb16a83c43c94eb07dd97d617ff1c03fcd
    Size: 466.38 MB
  4. rapidjson-1.1.0-6.module+el8+1989+b2d38253.src.rpm
    MD5: d0d464f5a5462ea3534ea847dd1a0c75
    SHA-256: eaaab41d10032d086368f0a5714d29cd434f2665a994f65aad4fa141be8ce96d
    Size: 0.98 MB

Asianux Server 8 for x86_64
  1. mecab-0.996-2.module+el8+1989+b2d38253.x86_64.rpm
    MD5: ad131d76a743e9478ea2e32e4eecde7d
    SHA-256: 2992d14dc3301136cba1f69503ac770a56695fa06bab5e10de0611878c49764b
    Size: 392.41 kB
  2. mecab-debugsource-0.996-2.module+el8+1989+b2d38253.x86_64.rpm
    MD5: e993c1a434aaa594f4b24a0867d2c386
    SHA-256: c28817457a7ea0676bb15faee49541b2dcb2e38e22ff91d8739e35229cde875c
    Size: 165.54 kB
  3. mecab-devel-0.996-2.module+el8+1989+b2d38253.x86_64.rpm
    MD5: a88e58301913c0ce3bacecadd2e192a7
    SHA-256: 8a7c807b58f869695746a5e5056df4492502d7c246f738d6a3a275fa9b65843c
    Size: 78.61 kB
  4. mecab-ipadic-2.7.0.20070801-17.module+el8+1989+b2d38253.x86_64.rpm
    MD5: a6b04ca5525d105af061a37a509d5382
    SHA-256: 9f03bc1d740f1b0d0460a72549ba7b30a303b4e827944e87e2e8fcfb32d2184f
    Size: 10.52 MB
  5. mecab-ipadic-EUCJP-2.7.0.20070801-17.module+el8+1989+b2d38253.x86_64.rpm
    MD5: 6e2aacee3713f29950631fddcc2fc379
    SHA-256: 89f35cb77d0a810ecb1961187df3dc08f8e45221ecb9e1ce6fc9dc38f7289d0e
    Size: 9.40 MB
  6. mysql-8.0.46-1.module+el8+1989+b2d38253.ML.1.x86_64.rpm
    MD5: 051bfd4d2c139c51e5b6e94f574e4b90
    SHA-256: 662704fac6de7346eea7528c1f3aa2e9677b18084fa0bb118d48d3ef7b337335
    Size: 14.56 MB
  7. mysql-common-8.0.46-1.module+el8+1989+b2d38253.ML.1.x86_64.rpm
    MD5: 04ece257e031415e050aded68954607d
    SHA-256: 1290840bd60c2dbbf98a43209a00b187b5b4fe2fed2987270ddb704b66df7c7a
    Size: 135.76 kB
  8. mysql-debugsource-8.0.46-1.module+el8+1989+b2d38253.ML.1.x86_64.rpm
    MD5: bc8f5ebb263444d1389e8c968cf7ad1d
    SHA-256: ef9cddac987fb24955e55696e02ec8db73f5ea5dca0a4ccfc14f3c8b268e5f7e
    Size: 17.76 MB
  9. mysql-devel-8.0.46-1.module+el8+1989+b2d38253.ML.1.x86_64.rpm
    MD5: fd354fa9ff82290b4eb166e2c65eae53
    SHA-256: bf214e37a6e327ed41b30bfe3a0ca9f8001901cacb527ca20b179dd59e7252df
    Size: 161.54 kB
  10. mysql-errmsg-8.0.46-1.module+el8+1989+b2d38253.ML.1.x86_64.rpm
    MD5: e978c63ef037cbcf74bf3fbbadcf7ab9
    SHA-256: fb67d9f3fecc7810a3094a884c487cd4155778b8512a90565af24219e7c2cf75
    Size: 644.48 kB
  11. mysql-libs-8.0.46-1.module+el8+1989+b2d38253.ML.1.x86_64.rpm
    MD5: f2a8dda900d6c5d6c91660c3df751af0
    SHA-256: 0a62c1a5dec92b64604d3a39ed162269f79c323e01314df8670db4470e52133c
    Size: 1.48 MB
  12. mysql-server-8.0.46-1.module+el8+1989+b2d38253.ML.1.x86_64.rpm
    MD5: 5f43837bf5d1f04c7c334ea55750d03f
    SHA-256: 48030be10c3996714c670f46c5f44bc3bfc9dbf2b3af915b3afff018a456f5e6
    Size: 32.55 MB
  13. mysql-test-8.0.46-1.module+el8+1989+b2d38253.ML.1.x86_64.rpm
    MD5: 7aa0bb5a92b242f724f4a58a5d7fb60e
    SHA-256: accb9f964ea211b264868ce958587e697d4cbcd2452548e938825586e88def50
    Size: 404.31 MB