Release date:
2026-09-28 23:35:24 UTC
Description:
* SECURITY UPDATE: backport the 5.7-applicable security bugfix set of the
2024/2025 CPU windows (MySQL 8.0.37-8.0.42; 2024_bugfix07 from the 8.4 line), patches 2024_bugfix01..11:
- 2024_bugfix01-bug35799038.patch: reject IMPORT TABLESPACE on secondary-index nullability mismatch and validate index trees after import, marking corrupt secondary indexes instead of crashing later on invalid page access. Fixes CVE-2024-21199.
- 2024_bugfix02-bug36593265.patch: heap buffer overflow in strlen over a non-NUL-terminated buffer when parsing AES KDF options of aes_encrypt()/aes_decrypt().
- 2024_bugfix03-bug32416819.patch: reattach engine ha_data in ha_commit_low/ha_rollback_low even when the transaction ha_list is empty (XA on replica), preventing InnoDB transaction-system corruption at shutdown.
- 2024_bugfix04-bug34930219.patch: synchronize SHOW PROCESSLIST / information_schema.processlist access to THD::active_vio-backed protocol state via an atomically cached connection-alive flag, preventing reads of a freed stack-allocated Protocol (completed by 2024_bugfix11-bug36778475).
- 2024_bugfix05-bug35513196.patch: propagate evaluation errors in IFNULL/COALESCE/shift operations and Item::send, preventing crashes on error paths that previously continued with invalid values.
- 2024_bugfix06-bug35846221.patch: add missing Item_func_make_set::fix_after_pullout(), so MAKE_SET arguments are not misclassified as constant after subquery pullout (assertion failure / wrong plan).
- 2024_bugfix07-bug38729126.patch: correct Item_direct_view_ref::used_tables() so it bases the table map on the direct child reference rather than walking down the inner reference chain. This fixes the JOIN::update_depend_map() crash on GROUP BY over correlated view references (Bug#35854686) without the merged-view wrong-results regression that the Bug#35854686-only fix introduced; Bug#38729126 supersedes Bug#35854686 (upstream fix first released in MySQL 8.4.11/9.7.2; not present in any 8.0 release).
- 2024_bugfix08-bug36317795.patch: pass the plugin reference to deinit callbacks during plugin shutdown paths, matching plugin_deinitialize, so plugins dereferencing the argument cannot crash the server.
- 2024_bugfix09-bug36600203.patch: do not leak the column-length buffer in the mysql client table-format output path (print_table_data) when the result set has no rows under --column-type-info. Fixes CVE-2024-21231.
- 2024_bugfix10-bug36684463.patch: UpdateXML() returned a pointer to a stack buffer; copy the result into the item's own buffer (stack use-after-return).
- 2024_bugfix11-bug36778475.patch: cache the protocol read/write status the same way connection-alive is cached and read the cached value in thread_state_info(), so SHOW PROCESSLIST / information_schema.processlist no longer dereferences another thread's (possibly freed stack-allocated) Protocol via get_rw_status(). Completes 2024_bugfix04.
* CVE-2024-20994 (Server: Information Schema) is fixed by
2024_bugfix04-bug34930219.patch together with 2024_bugfix11-bug36778475.patch:
the SHOW PROCESSLIST / information_schema.processlist use-after-free of a
freed stack-allocated Protocol object is present and reachable in the 5.7
tree on both the connection-alive and the rw-status paths. bugfix04 caches
connection-alive and bugfix11 caches rw-status, so neither path dereferences
the inspected thread's protocol. The upstream fixes land in 8.0.37 and
8.0.42 (April 2024 and April 2025 CPUs).
* CVE-2024-21199 (InnoDB) is fixed by 2024_bugfix01-bug35799038.patch: the
IMPORT TABLESPACE code path in storage/innobase/row/row0import.cc is present
and reachable in 5.7.44 and originally lacked the secondary-index
nullability-mismatch rejection and post-import index validation, so a
schema-mismatched .cfg could leave secondary indexes silently corrupt and
later crash the server on invalid page access; the backport of upstream
Bug#35799038 (8.0.40) adds the rejection and btr_validate_index sweep.
* CVE-2024-21231 (Client programs) is fixed by 2024_bugfix09-bug36600203.patch:
print_table_data() in client/mysql.cc allocated the per-column buffer before
an early return taken on an empty result under --column-type-info, leaking
it; the backport of upstream Bug#36600203 (8.0.40) moves the allocation below
the early return.
* The set is the complete 5.7-applicable portion of the 2024 CPU windows on
the supported 8.0 line. Of the Bug#-named patches, bugfix01, bugfix04+11 and
bugfix09 fix the CVEs claimed above (their vulnerable code paths are present
in 5.7.44); the remaining patches (bugfix02-03, 05-08, 10) are upstream
bugfixes applied as general hardening and are NOT claimed as CVE fixes for
5.7 -- the other 2024 CPU CVEs list only 8.0/8.4/9.0 as affected and 5.7 has
been assessed Not vulnerable for them.
Addresses: CVE-2024-20994, CVE-2024-21199, CVE-2024-21231
Updated packages:
-
libmysql5.7client-dev_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:65987a72ab473609bca0e90822f945960c4a4aff
-
libmysql5.7client20_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:485001e3eafff198b0dc6a628320e4dd05adf3c2
-
libmysql5.7d-dev_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:7245dd9cc1a658dd3388724e010f20aca539b003
-
mysql5.7-client_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:f6ccfc8b64555597dd7bde217dd0a49b051ada01
-
mysql5.7-common_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:e1e78aeca0880a74a16d1b7fb6153094106a3d12
-
mysql5.7-community-client_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:073789e22d0a9a9895de9b98f146ff3613bc4383
-
mysql5.7-community-server_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:32488713f1b97f542aae3ebc671d7ca1565240ca
-
mysql5.7-community-source_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:c99ba8bf01436fe1e375bfd323b70eeef27833a0
-
mysql5.7-community-test_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:2d309ea7263b4ff107d699b02a1a68b8daa1f2af
-
mysql5.7-server_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:be16c819dccc54b735d21db0da0a935c307c1f1b
-
mysql5.7-testsuite_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:3e649ea0500eb6638a3e32480dc1a0e29f6159e3
-
libmysql5.7client-dev_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:13f5bc128f68e1055330ec6ddbc4492ea28a6aa9
-
libmysql5.7client20_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:4e507ab456fda5eb8f3d05e25106e4a27e90d7fc
-
libmysql5.7d-dev_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:fe1dafd282ff6807daab37767c60612737c4d1fc
-
mysql5.7-client_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:57b6d6524fa16afd96e05045dcf1f9eb1d5339b2
-
mysql5.7-common_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:5b052e07880128f9c3eafc65904159982cd935e3
-
mysql5.7-community-client_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:aabf5c8d5fbe206764fc0255efb4edee5b8cf2b0
-
mysql5.7-community-server_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:a927d3a5d87afd7f59e95253f39581123d0927e8
-
mysql5.7-community-source_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:43e25ed5086ac5566b27eb14bf5b716d8229efbe
-
mysql5.7-community-test_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:7486a3a9b23304d568c18a47ae256e8b7cb5e524
-
mysql5.7-server_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:9d6a813ca00ac90b75b595ae00d855fd636cf9ae
-
mysql5.7-testsuite_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:82c6f53565f86ed97aea872822ef179a78b98863
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.