Release date:
2026-09-28 23:40:38 UTC
Description:
* SECURITY UPDATE: backport the 5.7-applicable security bugfix set of the
2024/2025 CPU windows (MySQL 8.0.37-8.0.42; 2024_bugfix07 from the 8.4 line), patches 2024_bugfix01..11:
- 2024_bugfix01-bug35799038.patch: reject IMPORT TABLESPACE on secondary-index nullability mismatch and validate index trees after import, marking corrupt secondary indexes instead of crashing later on invalid page access. Fixes CVE-2024-21199.
- 2024_bugfix02-bug36593265.patch: heap buffer overflow in strlen over a non-NUL-terminated buffer when parsing AES KDF options of aes_encrypt()/aes_decrypt().
- 2024_bugfix03-bug32416819.patch: reattach engine ha_data in ha_commit_low/ha_rollback_low even when the transaction ha_list is empty (XA on replica), preventing InnoDB transaction-system corruption at shutdown.
- 2024_bugfix04-bug34930219.patch: synchronize SHOW PROCESSLIST / information_schema.processlist access to THD::active_vio-backed protocol state via an atomically cached connection-alive flag, preventing reads of a freed stack-allocated Protocol (completed by 2024_bugfix11-bug36778475).
- 2024_bugfix05-bug35513196.patch: propagate evaluation errors in IFNULL/COALESCE/shift operations and Item::send, preventing crashes on error paths that previously continued with invalid values.
- 2024_bugfix06-bug35846221.patch: add missing Item_func_make_set::fix_after_pullout(), so MAKE_SET arguments are not misclassified as constant after subquery pullout (assertion failure / wrong plan).
- 2024_bugfix07-bug38729126.patch: correct Item_direct_view_ref::used_tables() so it bases the table map on the direct child reference rather than walking down the inner reference chain. This fixes the JOIN::update_depend_map() crash on GROUP BY over correlated view references (Bug#35854686) without the merged-view wrong-results regression that the Bug#35854686-only fix introduced; Bug#38729126 supersedes Bug#35854686 (upstream fix first released in MySQL 8.4.11/9.7.2; not present in any 8.0 release).
- 2024_bugfix08-bug36317795.patch: pass the plugin reference to deinit callbacks during plugin shutdown paths, matching plugin_deinitialize, so plugins dereferencing the argument cannot crash the server.
- 2024_bugfix09-bug36600203.patch: do not leak the column-length buffer in the mysql client table-format output path (print_table_data) when the result set has no rows under --column-type-info. Fixes CVE-2024-21231.
- 2024_bugfix10-bug36684463.patch: UpdateXML() returned a pointer to a stack buffer; copy the result into the item's own buffer (stack use-after-return).
- 2024_bugfix11-bug36778475.patch: cache the protocol read/write status the same way connection-alive is cached and read the cached value in thread_state_info(), so SHOW PROCESSLIST / information_schema.processlist no longer dereferences another thread's (possibly freed stack-allocated) Protocol via get_rw_status(). Completes 2024_bugfix04.
* CVE-2024-20994 (Server: Information Schema) is fixed by
2024_bugfix04-bug34930219.patch together with 2024_bugfix11-bug36778475.patch:
the SHOW PROCESSLIST / information_schema.processlist use-after-free of a
freed stack-allocated Protocol object is present and reachable in the 5.7
tree on both the connection-alive and the rw-status paths. bugfix04 caches
connection-alive and bugfix11 caches rw-status, so neither path dereferences
the inspected thread's protocol. The upstream fixes land in 8.0.37 and
8.0.42 (April 2024 and April 2025 CPUs).
* CVE-2024-21199 (InnoDB) is fixed by 2024_bugfix01-bug35799038.patch: the
IMPORT TABLESPACE code path in storage/innobase/row/row0import.cc is present
and reachable in 5.7.44 and originally lacked the secondary-index
nullability-mismatch rejection and post-import index validation, so a
schema-mismatched .cfg could leave secondary indexes silently corrupt and
later crash the server on invalid page access; the backport of upstream
Bug#35799038 (8.0.40) adds the rejection and btr_validate_index sweep.
* CVE-2024-21231 (Client programs) is fixed by 2024_bugfix09-bug36600203.patch:
print_table_data() in client/mysql.cc allocated the per-column buffer before
an early return taken on an empty result under --column-type-info, leaking
it; the backport of upstream Bug#36600203 (8.0.40) moves the allocation below
the early return.
* The set is the complete 5.7-applicable portion of the 2024 CPU windows on
the supported 8.0 line. Of the Bug#-named patches, bugfix01, bugfix04+11 and
bugfix09 fix the CVEs claimed above (their vulnerable code paths are present
in 5.7.44); the remaining patches (bugfix02-03, 05-08, 10) are upstream
bugfixes applied as general hardening and are NOT claimed as CVE fixes for
5.7 -- the other 2024 CPU CVEs list only 8.0/8.4/9.0 as affected and 5.7 has
been assessed Not vulnerable for them.
Addresses: CVE-2024-20994, CVE-2024-21199, CVE-2024-21231
Updated packages:
-
libmysql5.7client-dev_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:e5c0fd08b811e8b310a088021db333eee6ddaf99
-
libmysql5.7client20_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:b4160b1b6ba11c2cf12d21d7abbcbe30774f1989
-
libmysql5.7d-dev_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:87796d5ff9ddd1da891241d7d7c66d6db6467a8b
-
mysql5.7-client_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:b1e41bc1620b50b27daadbd2db929d699a793282
-
mysql5.7-common_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:8de6ab478715f444241bc7e8e44408cc7bd319c9
-
mysql5.7-community-client_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:2ee67e5d56aa78556bba8c265dcae15c628ded4c
-
mysql5.7-community-server_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:e9f148c6425a4fb456e0d3a3340c58ff35a48c27
-
mysql5.7-community-source_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:698a9c47996c377b472e638e4253a1e05903af50
-
mysql5.7-community-test_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:7655ab44c2563da8398681f76a7c587f119575e3
-
mysql5.7-server_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:18821582dc20bb0235de454bb63941851de7c539
-
mysql5.7-testsuite_5.7.44-1debian10+tuxcare.els12_amd64.deb
sha:e2b746cb863fb8620e339e3951f5203dee21e300
-
libmysql5.7client-dev_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:835529881dac6bf57824f93156e3aa14027829b0
-
libmysql5.7client20_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:28ca0ea6c11d3e0a73b2e01a0bad32193c9c2fc1
-
libmysql5.7d-dev_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:592eee6a869ebe1d73206a93445add005e4d604e
-
mysql5.7-client_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:8006d90e064cc2b957f56226945941aa647e1cd1
-
mysql5.7-common_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:1f5f9caf6b49be1998ba514fea9a233e276faaf8
-
mysql5.7-community-client_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:6ace5d3af1b609db23de67d5b0d248b2ae8ef4b9
-
mysql5.7-community-server_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:6fc000ebaaa139fb1c366e4e6558e8bf098179a4
-
mysql5.7-community-source_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:ded4df8951e6e335f287b9f56eb73276175575ba
-
mysql5.7-community-test_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:61a346728351e5dc54da56168cc07061b95ef24d
-
mysql5.7-server_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:8666ba9773787a4291bd9a41413bc6f5582b69de
-
mysql5.7-testsuite_5.7.44-1debian10+tuxcare.els12_arm64.deb
sha:3c7ee1d37a39099d966d92aa905df2c10db29e65
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.