[CLSA-2026:1790638511] Fix CVE(s): CVE-2024-20994, CVE-2024-21199, CVE-2024-21231
Type:
security
Severity:
Moderate
Release date:
2026-09-28 23:35:24 UTC
Description:
* SECURITY UPDATE: backport the 5.7-applicable security bugfix set of the 2024/2025 CPU windows (MySQL 8.0.37-8.0.42; 2024_bugfix07 from the 8.4 line), patches 2024_bugfix01..11: - 2024_bugfix01-bug35799038.patch: reject IMPORT TABLESPACE on secondary-index nullability mismatch and validate index trees after import, marking corrupt secondary indexes instead of crashing later on invalid page access. Fixes CVE-2024-21199. - 2024_bugfix02-bug36593265.patch: heap buffer overflow in strlen over a non-NUL-terminated buffer when parsing AES KDF options of aes_encrypt()/aes_decrypt(). - 2024_bugfix03-bug32416819.patch: reattach engine ha_data in ha_commit_low/ha_rollback_low even when the transaction ha_list is empty (XA on replica), preventing InnoDB transaction-system corruption at shutdown. - 2024_bugfix04-bug34930219.patch: synchronize SHOW PROCESSLIST / information_schema.processlist access to THD::active_vio-backed protocol state via an atomically cached connection-alive flag, preventing reads of a freed stack-allocated Protocol (completed by 2024_bugfix11-bug36778475). - 2024_bugfix05-bug35513196.patch: propagate evaluation errors in IFNULL/COALESCE/shift operations and Item::send, preventing crashes on error paths that previously continued with invalid values. - 2024_bugfix06-bug35846221.patch: add missing Item_func_make_set::fix_after_pullout(), so MAKE_SET arguments are not misclassified as constant after subquery pullout (assertion failure / wrong plan). - 2024_bugfix07-bug38729126.patch: correct Item_direct_view_ref::used_tables() so it bases the table map on the direct child reference rather than walking down the inner reference chain. This fixes the JOIN::update_depend_map() crash on GROUP BY over correlated view references (Bug#35854686) without the merged-view wrong-results regression that the Bug#35854686-only fix introduced; Bug#38729126 supersedes Bug#35854686 (upstream fix first released in MySQL 8.4.11/9.7.2; not present in any 8.0 release). - 2024_bugfix08-bug36317795.patch: pass the plugin reference to deinit callbacks during plugin shutdown paths, matching plugin_deinitialize, so plugins dereferencing the argument cannot crash the server. - 2024_bugfix09-bug36600203.patch: do not leak the column-length buffer in the mysql client table-format output path (print_table_data) when the result set has no rows under --column-type-info. Fixes CVE-2024-21231. - 2024_bugfix10-bug36684463.patch: UpdateXML() returned a pointer to a stack buffer; copy the result into the item's own buffer (stack use-after-return). - 2024_bugfix11-bug36778475.patch: cache the protocol read/write status the same way connection-alive is cached and read the cached value in thread_state_info(), so SHOW PROCESSLIST / information_schema.processlist no longer dereferences another thread's (possibly freed stack-allocated) Protocol via get_rw_status(). Completes 2024_bugfix04. * CVE-2024-20994 (Server: Information Schema) is fixed by 2024_bugfix04-bug34930219.patch together with 2024_bugfix11-bug36778475.patch: the SHOW PROCESSLIST / information_schema.processlist use-after-free of a freed stack-allocated Protocol object is present and reachable in the 5.7 tree on both the connection-alive and the rw-status paths. bugfix04 caches connection-alive and bugfix11 caches rw-status, so neither path dereferences the inspected thread's protocol. The upstream fixes land in 8.0.37 and 8.0.42 (April 2024 and April 2025 CPUs). * CVE-2024-21199 (InnoDB) is fixed by 2024_bugfix01-bug35799038.patch: the IMPORT TABLESPACE code path in storage/innobase/row/row0import.cc is present and reachable in 5.7.44 and originally lacked the secondary-index nullability-mismatch rejection and post-import index validation, so a schema-mismatched .cfg could leave secondary indexes silently corrupt and later crash the server on invalid page access; the backport of upstream Bug#35799038 (8.0.40) adds the rejection and btr_validate_index sweep. * CVE-2024-21231 (Client programs) is fixed by 2024_bugfix09-bug36600203.patch: print_table_data() in client/mysql.cc allocated the per-column buffer before an early return taken on an empty result under --column-type-info, leaking it; the backport of upstream Bug#36600203 (8.0.40) moves the allocation below the early return. * The set is the complete 5.7-applicable portion of the 2024 CPU windows on the supported 8.0 line. Of the Bug#-named patches, bugfix01, bugfix04+11 and bugfix09 fix the CVEs claimed above (their vulnerable code paths are present in 5.7.44); the remaining patches (bugfix02-03, 05-08, 10) are upstream bugfixes applied as general hardening and are NOT claimed as CVE fixes for 5.7 -- the other 2024 CPU CVEs list only 8.0/8.4/9.0 as affected and 5.7 has been assessed Not vulnerable for them. Addresses: CVE-2024-20994, CVE-2024-21199, CVE-2024-21231
Updated packages:
  • libmysql5.7client-dev_5.7.44-1debian10+tuxcare.els12_amd64.deb
    sha:65987a72ab473609bca0e90822f945960c4a4aff
  • libmysql5.7client20_5.7.44-1debian10+tuxcare.els12_amd64.deb
    sha:485001e3eafff198b0dc6a628320e4dd05adf3c2
  • libmysql5.7d-dev_5.7.44-1debian10+tuxcare.els12_amd64.deb
    sha:7245dd9cc1a658dd3388724e010f20aca539b003
  • mysql5.7-client_5.7.44-1debian10+tuxcare.els12_amd64.deb
    sha:f6ccfc8b64555597dd7bde217dd0a49b051ada01
  • mysql5.7-common_5.7.44-1debian10+tuxcare.els12_amd64.deb
    sha:e1e78aeca0880a74a16d1b7fb6153094106a3d12
  • mysql5.7-community-client_5.7.44-1debian10+tuxcare.els12_amd64.deb
    sha:073789e22d0a9a9895de9b98f146ff3613bc4383
  • mysql5.7-community-server_5.7.44-1debian10+tuxcare.els12_amd64.deb
    sha:32488713f1b97f542aae3ebc671d7ca1565240ca
  • mysql5.7-community-source_5.7.44-1debian10+tuxcare.els12_amd64.deb
    sha:c99ba8bf01436fe1e375bfd323b70eeef27833a0
  • mysql5.7-community-test_5.7.44-1debian10+tuxcare.els12_amd64.deb
    sha:2d309ea7263b4ff107d699b02a1a68b8daa1f2af
  • mysql5.7-server_5.7.44-1debian10+tuxcare.els12_amd64.deb
    sha:be16c819dccc54b735d21db0da0a935c307c1f1b
  • mysql5.7-testsuite_5.7.44-1debian10+tuxcare.els12_amd64.deb
    sha:3e649ea0500eb6638a3e32480dc1a0e29f6159e3
  • libmysql5.7client-dev_5.7.44-1debian10+tuxcare.els12_arm64.deb
    sha:13f5bc128f68e1055330ec6ddbc4492ea28a6aa9
  • libmysql5.7client20_5.7.44-1debian10+tuxcare.els12_arm64.deb
    sha:4e507ab456fda5eb8f3d05e25106e4a27e90d7fc
  • libmysql5.7d-dev_5.7.44-1debian10+tuxcare.els12_arm64.deb
    sha:fe1dafd282ff6807daab37767c60612737c4d1fc
  • mysql5.7-client_5.7.44-1debian10+tuxcare.els12_arm64.deb
    sha:57b6d6524fa16afd96e05045dcf1f9eb1d5339b2
  • mysql5.7-common_5.7.44-1debian10+tuxcare.els12_arm64.deb
    sha:5b052e07880128f9c3eafc65904159982cd935e3
  • mysql5.7-community-client_5.7.44-1debian10+tuxcare.els12_arm64.deb
    sha:aabf5c8d5fbe206764fc0255efb4edee5b8cf2b0
  • mysql5.7-community-server_5.7.44-1debian10+tuxcare.els12_arm64.deb
    sha:a927d3a5d87afd7f59e95253f39581123d0927e8
  • mysql5.7-community-source_5.7.44-1debian10+tuxcare.els12_arm64.deb
    sha:43e25ed5086ac5566b27eb14bf5b716d8229efbe
  • mysql5.7-community-test_5.7.44-1debian10+tuxcare.els12_arm64.deb
    sha:7486a3a9b23304d568c18a47ae256e8b7cb5e524
  • mysql5.7-server_5.7.44-1debian10+tuxcare.els12_arm64.deb
    sha:9d6a813ca00ac90b75b595ae00d855fd636cf9ae
  • mysql5.7-testsuite_5.7.44-1debian10+tuxcare.els12_arm64.deb
    sha:82c6f53565f86ed97aea872822ef179a78b98863
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.