Red Hat released Important updates for MySQL and MariaDB packages in Red Hat Software Collections, addressing the configuration-file injection flaw CVE-2016-6662, MyISAM repair race conditions CVE-2016-6663/CVE-2016-5616, and insecure mysqld_safe error-log handling tracked as CVE-2016-6664/CVE-2016-5617. Depending on configuration, attackers with database privileges, FILE access, or local shell access could write option files, manipulate files writable by the mysql account, or exploit symlink and log-path handling to obtain elevated execution; root-level impact depended on mysqld_safe and file-permission configuration.
The updates also remediate remotely reachable denial-of-service flaws CVE-2016-3492 and CVE-2016-5612, which allow low-privileged network attackers to hang or repeatedly crash affected MySQL servers, alongside additional Oracle CPU vulnerabilities. Affected Software Collections deployments should install the applicable updated packages—mysql55-mysql 5.5.52, mariadb55-mariadb 5.5.53, rh-mysql56-mysql 5.6.34, or rh-mariadb100-mariadb 10.0.28 or later; installation automatically restarts mysqld. Red Hat noted that default RHEL configurations reduce exposure to several escalation paths through root-owned configuration files, mysqld_safe execution as mysql, and disabled symbolic links.

Get the actors, campaigns, and ATT&CK mapping behind it.
17 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2017:0184 for Red Hat Enterprise Linux 6 mysql, remediating the MyISAM table-repair race condition CVE-2016-6663. Exploitation required shell access and could allow a database user to alter permissions on files writable by the mysql account.
Red Hat issued Important advisory RHSA-2016:2928 for Red Hat Software Collections, upgrading rh-mariadb101-mariadb to MariaDB 10.1.19. The update remediated CVE-2016-6662, the MyISAM table-repair race CVE-2016-6663/CVE-2016-5616, and additional MariaDB server vulnerabilities.
Red Hat issued Important advisory RHSA-2016:2927, upgrading rh-mariadb100-mariadb to version 10.0.28. The Software Collections update addressed CVE-2016-6662, CVE-2016-6663/CVE-2016-5616, and multiple additional MySQL/MariaDB server-component vulnerabilities.
Red Hat issued Important advisory RHSA-2016:2749, upgrading rh-mysql56-mysql to 5.6.34 for affected Software Collections deployments. The update remediated CVE-2016-6662, the MyISAM repair race, and mysqld_safe error-log handling flaws, among other vulnerabilities.
Red Hat issued Important advisory RHSA-2016:2131 for Red Hat Software Collections, upgrading mariadb55-mariadb to 5.5.53. It remediated the configuration-file writing flaw CVE-2016-6662, the MyISAM race CVE-2016-6663, and several additional MySQL/MariaDB server vulnerabilities.
Red Hat issued Important advisory RHSA-2016:2130 for Red Hat Software Collections, upgrading mysql55-mysql to 5.5.52. The update addressed CVE-2016-6662, CVE-2016-6663/CVE-2016-5616, CVE-2016-5617/CVE-2016-6664, and multiple Oracle October CPU MySQL Server flaws.
CVE-2016-6664 and duplicate identifier CVE-2016-5617 were identified as insecure error-log ownership and permission handling in mysqld_safe. When mysqld_safe ran as root, a local mysql user could manipulate the log path or symlinks to escalate to root; MySQL later completed remediation in 5.5.54, 5.6.35, and 5.7.17.
CVE-2016-6663, also assigned duplicate identifier CVE-2016-5616, was identified as a MySQL/MariaDB MyISAM race condition. Under conditions including local shell access, writable database-file locations, and enabled symbolic links, it could permit privilege escalation; MySQL fixed it in 5.5.52, 5.6.33, and 5.7.15.
Oracle documented CVE-2016-5626 in its October 2016 Critical Patch Update as a remotely exploitable flaw in the MySQL Server GIS component. A low-privileged network attacker could cause affected servers to hang or repeatedly crash, resulting in complete denial of service.
Oracle documented CVE-2016-5624 in its October 2016 Critical Patch Update. A low-privileged network attacker could exploit the MySQL Server DML vulnerability to hang or repeatedly crash the server, causing complete denial of service; Red Hat remediated it in multiple advisories, including RHSA-2016:2595 for RHEL 7.
CVE-2016-5612 affected the MySQL Server DML component and could let a low-privileged network attacker cause a server hang or repeatable crash. Oracle listed the issue as fixed upstream in MySQL 5.6.32.
Oracle documented CVE-2016-3492 in its October 2016 Critical Patch Update. A low-privileged network attacker could cause affected MySQL Server Optimizer versions to hang or repeatedly crash, resulting in complete denial of service.
Oracle documented CVE-2016-5507 in its October 2016 Critical Patch Update. A high-privileged network attacker could exploit the MySQL Server InnoDB flaw to cause a hang or repeatable crash, resulting in complete denial of service; Red Hat addressed it through RHSA-2016:2749.
MySQL published version 5.7.15 release notes, documenting changes in the 5.7.15 release. This version was an upstream remediation release for several vulnerabilities already noted in the timeline.
Red Hat issued Important advisory RHSA-2016:1602 for Red Hat Enterprise Linux 7, upgrading MariaDB to 5.5.50-1.el7_2. The update remediated 16 MySQL-derived vulnerabilities, including flaws in DML, MyISAM, prepared statements, replication, encryption, parsing, and connection functionality.
Red Hat released RHSA-2016:1601, updating rh-mysql56-mysql packages to address CVE-2016-5630. The InnoDB vulnerability affected MySQL 5.6.31 and earlier and 5.7.13 and earlier and allowed a remote authenticated administrator to cause denial of service.
CVE-2016-6662 was identified as a MySQL/MariaDB logging flaw through which an administrative database user or user with FILE privileges could write option files and potentially achieve code execution through mysqld_safe. MySQL fixed unsafe logging and option-file behavior in 5.5.52, 5.6.33, and 5.7.15, with additional secure_file_priv hardening in 5.5.53, 5.6.34, and 5.7.16.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
34 references tracked. Mallory keeps watching after this page renders.
dev.mysql.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcejira.mariadb.org
Open sourcelegalhackers.com
Open sourcelegalhackers.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.