Red Hat released RHSA-2016:1601 to upgrade rh-mysql56-mysql to MySQL 5.6.32 on supported RHEL 6 and RHEL 7 x86_64 Server and Workstation systems using Red Hat Software Collections. The update remediates vulnerabilities across InnoDB, Parser, Full-Text Search, Optimizer, Types, encryption, DML, privileges, and replication components. Several flaws—including CVE-2016-3501, CVE-2016-3486, CVE-2016-3521, CVE-2016-3614, and CVE-2016-5609—could allow authenticated network attackers, often with low privileges, to repeatedly crash or hang MySQL and cause denial of service; CVE-2016-3477 also carried confidentiality and integrity risk.
Red Hat also shipped RHSA-2016:1603 and RHSA-2016:1637, upgrading Software Collections MariaDB packages to 5.5.50 and 10.1.16, respectively, to address CVE-2016-3477, CVE-2016-3521, CVE-2016-3615, and CVE-2016-5440. Organizations running the affected Software Collections MySQL or MariaDB deployments should install the applicable errata and account for the automatic restart of the mysqld daemon; native RHEL MySQL/MariaDB packages listed by Red Hat as not affected do not require these specific updates.

See real exploitation activity before you spend the cycle.
68 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2016:1637, upgrading rh-mariadb101-mariadb in Red Hat Software Collections to MariaDB 10.1.16. The update fixed CVE-2016-3477, CVE-2016-3521, CVE-2016-3615, and CVE-2016-5440 for supported RHEL 6 and 7 systems.
Red Hat addressed CVE-2016-3477, CVE-2016-3521, CVE-2016-3615, and CVE-2016-5440 in the Red Hat Software Collections rh-mariadb100-mariadb package through RHSA-2016:1604.
Red Hat issued Important advisory RHSA-2016:1603, upgrading mariadb55-mariadb in Red Hat Software Collections to version 5.5.50. It fixed CVE-2016-3477, CVE-2016-3521, CVE-2016-3615, and CVE-2016-5440 for affected RHEL 6 and 7 Server and Workstation deployments.
Red Hat fixed CVE-2016-3477, CVE-2016-3521, CVE-2016-3615, and CVE-2016-5440 in the RHEL 7 mariadb package through RHSA-2016:1602.
Red Hat issued the Important RHSA-2016:1601 advisory, upgrading rh-mysql56-mysql in Red Hat Software Collections to MySQL 5.6.32. The update remediated multiple MySQL flaws, including CVE-2016-3459, CVE-2016-3477, CVE-2016-3486, CVE-2016-3501, CVE-2016-3521, CVE-2016-3614, CVE-2016-3615, CVE-2016-5439, CVE-2016-5440, CVE-2016-5609, CVE-2016-5627, CVE-2016-8284, and CVE-2016-8288, for affected RHEL 6 and 7 Software Collections deployments.
Red Hat issued RHSA-2016:1481 to remediate CVE-2016-0650, a Moderate-severity authenticated availability vulnerability in the MySQL/MariaDB Replication component, in the mariadb55-mariadb package for Red Hat Software Collections on RHEL 6. The fix also applied to listed RHEL 6.6 and 6.7 EUS Software Collections packages.
Red Hat issued RHSA-2016:1480 to fix CVE-2016-3477, CVE-2016-3521, CVE-2016-3615, and CVE-2016-5440 in the mysql55-mysql package for Red Hat Software Collections on RHEL 6.
Red Hat published a record for CVE-2016-5444, a Low-severity remote unauthenticated confidentiality vulnerability in the Server: Connection component of Oracle MySQL and MariaDB. The issue affects specified MySQL and MariaDB releases and was addressed by existing 2016 Red Hat advisories.
Oracle disclosed CVE-2016-3471, a difficult-to-exploit MySQL Server Option vulnerability affecting MySQL 5.5.45 and earlier and 5.6.26 and earlier, in its July 2016 Critical Patch Update. A high-privileged local attacker could compromise or take over MySQL Server; Red Hat stated that affected MariaDB and MySQL packages had already been rebased and remediated through multiple RHSA advisories.
Oracle's July 2016 Critical Patch Update referenced MySQL vulnerabilities affecting Parser, Types, DML, row-based replication, InnoDB, Full-Text Search, Optimizer, Privileges, and Encryption components.
Red Hat issued RHSA-2016:1132, rebasing the Red Hat Software Collections rh-mariadb100-mariadb package to fixed upstream versions for CVE-2016-3459.
Red Hat remediated CVE-2016-0655, a Moderate-severity authenticated availability vulnerability in Oracle MySQL and MariaDB InnoDB, through RHSA-2016:0705 for rh-mysql56-mysql on RHEL 6 and 7 Software Collections. RHSA-2016:1132 later also fixed the issue for rh-mariadb100-mariadb, including listed EUS streams.
Red Hat remediated CVE-2016-0668, a difficult-to-exploit local denial-of-service flaw in Oracle MySQL Server's InnoDB component, through RHSA-2016:0705 and RHSA-2016:1132. The fixes covered affected Red Hat Software Collections deployments across RHEL 6 and 7, including listed EUS streams.
Red Hat released RHSA-2016:0705 to fix CVE-2016-0647, a Moderate-severity Full-Text Search availability vulnerability, in the rh-mysql56-mysql package for Red Hat Software Collections on RHEL 6, including referenced EUS streams.
Red Hat addressed CVE-2016-0644, a low-privileged local denial-of-service vulnerability in MySQL Server's DDL component, through multiple RHSA advisories affecting RHEL 7 and Red Hat Software Collections. Exploitation could cause MySQL Server to hang or repeatedly crash.
CVE-2016-0668, a low-severity authenticated local availability vulnerability in the InnoDB component of Oracle MySQL and MariaDB, was published. It affected MySQL 5.6.28 and earlier, 5.7.10 and earlier, and specified MariaDB 10.0.x and 10.1.x releases.
CVE-2016-0666, a Low-severity authenticated local availability vulnerability in MySQL and MariaDB Server Security: Privileges functionality, was made public. It affected specified MySQL versions through 5.7.11 and MariaDB versions before 5.5.49, 10.0.25, and 10.1.14.
CVE-2016-0640, a Moderate-severity authenticated local integrity and availability vulnerability in the MySQL and MariaDB Server DML component, was publicly disclosed. It affected specified MySQL releases through 5.7.10 and MariaDB releases before 5.5.48, 10.0.24, and 10.1.12.
Oracle referenced CVE-2016-0647, an authenticated low-privilege denial-of-service vulnerability in the MySQL Server Full-Text Search component, in its April 2016 Critical Patch Update. The flaw affected MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier, allowing attackers to hang or repeatedly crash the server.
Oracle addressed CVE-2016-0650, a Server: Replication vulnerability affecting MySQL versions through 5.5.47, 5.6.28, and 5.7.10, in its April 2016 Critical Patch Update. A low-privileged local attacker could repeatedly hang or crash MySQL Server, causing denial of service.
Oracle referenced CVE-2016-0644, an authenticated local availability vulnerability in the MySQL and MariaDB Server DDL subcomponent, in its April 2016 Critical Patch Update. The issue affected MySQL through versions 5.5.47, 5.6.28, and 5.7.10, and specified earlier MariaDB releases.
Oracle addressed CVE-2016-0640, a MySQL Server DML flaw affecting MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier, in its April 2016 Critical Patch Update. A low-privileged authenticated attacker could cause denial of service or perform unauthorized data update, insert, or delete operations.
Red Hat remediated CVE-2016-0616, a moderate authenticated remote availability flaw in the MySQL/MariaDB Optimizer component, through RHSA-2016:0534 for RHEL 7 MariaDB. Later 2016 Software Collections advisories fixed affected MariaDB and MySQL packages for RHEL 6, including specified EUS streams.
Red Hat fixed CVE-2016-0598, a low-severity authenticated remote partial-availability flaw in MySQL and MariaDB Server DML functionality, through RHSA-2016:0534 for RHEL 7 MariaDB. Later Software Collections advisories remediated affected MySQL and MariaDB packages for RHEL 6, including listed EUS streams.
Red Hat fixed CVE-2016-0597, a moderate-severity remote authenticated MySQL/MariaDB Optimizer availability flaw, beginning with RHSA-2016:0534 for RHEL 7 MariaDB. Additional 2016 Software Collections advisories remediated affected MySQL and MariaDB packages for RHEL 6, including listed EUS streams.
Red Hat remediated CVE-2016-0608, a low-severity remote authenticated partial-availability flaw in the MySQL and MariaDB User-Defined Function component, beginning with RHSA-2016:0534 for RHEL 7 MariaDB. Subsequent 2016 Software Collections errata fixed affected MySQL and MariaDB packages for RHEL 6, including listed EUS streams.
Red Hat fixed the low-severity authenticated remote MySQL/MariaDB InnoDB availability flaw CVE-2016-0600 in RHEL 7 MariaDB through RHSA-2016:0534. Further Software Collections errata remediated affected MySQL and MariaDB packages for RHEL 6, including listed EUS streams.
Red Hat remediated CVE-2016-2047 in the RHEL 7 MariaDB package through RHSA-2016:0534. The Moderate-severity MariaDB client-library flaw allowed a network-positioned attacker to impersonate a database server because TLS/SSL certificate hostname validation was improper.
Red Hat remediated CVE-2016-0606, a low-severity remote authenticated integrity vulnerability in MySQL and MariaDB encryption functionality, through RHSA-2016:0534 for RHEL 7 MariaDB. Later 2016 Software Collections advisories fixed affected MySQL and MariaDB packages for RHEL 6, including listed EUS streams.
Red Hat remediated CVE-2016-0609, a low-severity remote authenticated availability flaw in MySQL and MariaDB privilege functionality, beginning with RHSA-2016:0534 for RHEL 7 MariaDB. Subsequent 2016 Software Collections advisories fixed affected MySQL and MariaDB packages for RHEL 6, including listed EUS streams.
Red Hat released RHSA-2016:0534 for RHEL 7 MariaDB, remediating CVE-2016-0596, a Moderate-severity remote authenticated partial-denial-of-service vulnerability in the MySQL and MariaDB Server DML component. Subsequent 2016 Software Collections advisories also fixed the issue for affected MySQL and MariaDB packages.
Red Hat released RHSA-2016:0534 for RHEL 7 MariaDB, remediating CVE-2015-4836, a Moderate-severity remote authenticated partial-denial-of-service vulnerability in Oracle MySQL Server's Server: SP component. The flaw affects MySQL 5.5.45 and earlier and 5.6.26 and earlier.
Red Hat released RHSA-2016:0534 for RHEL 7 MariaDB, remediating CVE-2015-4858, a Moderate-severity DML-related vulnerability in Oracle MySQL Server. The flaw allowed remote authenticated attackers to cause partial denial of service on affected MySQL versions.
Red Hat released RHSA-2016:0534 to fix CVE-2015-4792 in the RHEL 7 MariaDB component. The Moderate-severity flaw affects the MySQL Server Partition component and allows remote authenticated attackers to affect availability through unspecified vectors.
Red Hat remediated CVE-2016-0546 in RHEL 7 MariaDB through RHSA-2016:0534. The low-severity MySQL/MariaDB Client vulnerability affected specified MySQL and MariaDB releases and could allow local users to affect confidentiality, integrity, and availability.
Red Hat released RHSA-2016:0534 for RHEL 7 MariaDB, remediating CVE-2015-4802, a Moderate-severity authenticated remote partial-denial-of-service flaw in Oracle MySQL Server's Partition component.
Red Hat remediated CVE-2015-4870 in RHEL 7 MariaDB through RHSA-2016:0534. The Moderate-severity MySQL Server Parser flaw allowed remote authenticated attackers to affect availability through unspecified vectors.
Red Hat remediated CVE-2015-4861 in RHEL 7 MariaDB through RHSA-2016:0534. The Moderate-severity Oracle MySQL InnoDB flaw allowed remote authenticated users to cause partial denial of service; subsequent 2016 Software Collections advisories fixed affected MySQL and MariaDB-derived packages.
Red Hat remediated CVE-2015-4826 in the RHEL 7 MariaDB package through RHSA-2016:0534. The Moderate-severity Oracle MySQL Server Types vulnerability affected MySQL 5.5.45 and earlier and 5.6.26 and earlier and could allow remote authenticated attackers to affect confidentiality through unspecified vectors.
Andrej Nemec reported CVE-2016-2047, in which MySQL's ssl_verify_server_cert() improperly parsed X509_NAME_oneline() output for the certificate CN. An attacker could embed "/CN=" in another subject field to bypass hostname validation and facilitate a man-in-the-middle attack.
Martin Prpič recorded CVE-2016-0606, a difficult-to-exploit authenticated remote vulnerability in MySQL Server's Security: Encryption component. The flaw affected MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9, and could allow unauthorized update, insert, or delete operations on accessible data.
Martin Prpič recorded CVE-2016-0609, a very difficult-to-exploit remotely reachable MySQL Server Security: Privileges vulnerability requiring multiple authentications. It affected MySQL through 5.5.46, 5.6.27, and 5.7.9 and could allow attackers to repeatedly hang or crash the server, causing complete denial of service.
Martin Prpič documented CVE-2016-0596, an authenticated remote vulnerability in MySQL Server's DML component affecting MySQL 5.5.46 and earlier and 5.6.27 and earlier. Exploitation through multiple protocols could hang or repeatedly crash MySQL Server, causing complete denial of service.
Martin Prpič documented CVE-2016-0616, an easily exploitable authenticated remote vulnerability in the MySQL Server Optimizer component affecting MySQL 5.5.46 and earlier. Exploitation through multiple protocols could hang or repeatedly crash MySQL Server, causing complete denial of service.
Oracle's January 2016 Critical Patch Update addressed CVE-2016-0600, a difficult-to-exploit authenticated remote vulnerability in the MySQL Server InnoDB component. Affected MySQL versions through 5.5.46, 5.6.27, and 5.7.9 could be subjected to partial denial of service through multiple protocols.
Oracle documented CVE-2016-0597, an easily exploitable authenticated remote vulnerability in MySQL Server's Optimizer component, in its January 2016 Critical Patch Update. The issue affected MySQL through versions 5.5.46, 5.6.27, and 5.7.9 and could let attackers repeatedly hang or crash the server, causing complete denial of service.
Oracle documented CVE-2016-0598, a difficult-to-exploit authenticated remote vulnerability in MySQL Server's DML component, in its January 2016 Critical Patch Update. Affected versions through MySQL 5.5.46, 5.6.27, and 5.7.9 could be repeatedly hung or crashed, causing complete denial of service.
Martin Prpič recorded CVE-2015-4800, an authenticated remote MySQL Server Optimizer vulnerability affecting MySQL 5.6.26 and earlier. Exploitation through multiple protocols could hang or repeatedly crash MySQL Server, causing complete denial of service; Red Hat later remediated it through RHSA-2016:0705.
CVE-2015-4913, a Moderate-severity remote authenticated partial-denial-of-service vulnerability in Oracle MySQL Server's Server:DML functionality, was published. It affected MySQL 5.5.45 and earlier and 5.6.26 and earlier and was distinct from CVE-2015-4858.
CVE-2015-4815, a Moderate-severity remote authenticated availability vulnerability in Oracle MySQL Server's Server: DDL component, was made public. It affected MySQL 5.5.45 and earlier and 5.6.26 and earlier, allowing partial impact on server availability through unspecified vectors.
Oracle referenced CVE-2015-4830 in its October 2015 Critical Patch Update information for MySQL. The Moderate-severity Server: Security: Privileges vulnerability affects MySQL 5.5.45 and earlier and 5.6.26 and earlier, allowing a remote authenticated attacker to affect integrity through unspecified vectors.
Red Hat released RHSA-2015:1628, RHSA-2015:1629, and RHSA-2015:1630 to remediate CVE-2015-4879 in mysql55-mysql and rh-mysql56-mysql packages for RHEL and Red Hat Software Collections. The DML vulnerability affected authenticated remote users and could affect confidentiality, integrity, and availability.
Red Hat issued RHSA-2015:1628, RHSA-2015:1629, and RHSA-2015:1630 to remediate CVE-2015-4819 in mysql55-mysql and rh-mysql56-mysql packages for RHEL and Red Hat Software Collections. The local MySQL client-program vulnerability affects confidentiality, integrity, and availability through unspecified vectors.
Red Hat analysis attributed CVE-2015-4819 to a buffer overflow in mysqlslap command-line argument parsing and concluded that no trust boundary was crossed. Analyst Tomas Hoger assessed it was not a security vulnerability; FORTIFY_SOURCE would limit the strncpy-related overflow to an application abort.
Red Hat documented CVE-2015-4879, a very difficult-to-exploit authenticated network vulnerability in Oracle MySQL Server's DML component that could enable server takeover and possible arbitrary code execution. Oracle fixed it in MySQL 5.5.45 and 5.6.26, MariaDB addressed it in 10.0.21, and Red Hat issued fixes through multiple RHEL and Software Collections advisories.
MariaDB addressed CVE-2015-4870, an authenticated remote Server: Parser denial-of-service vulnerability in Oracle MySQL Server, in MariaDB version 10.0.22. Successful exploitation could repeatedly hang or crash the server.
MariaDB addressed the authenticated remote MySQL Server DML denial-of-service vulnerability CVE-2015-4858 in MariaDB 10.0.22. The flaw could allow an authenticated remote attacker to repeatedly hang or crash MySQL Server.
Red Hat documented CVE-2016-0651, a low-privileged local vulnerability in Oracle MySQL Server's Optimizer component that can repeatedly hang or crash the server, causing complete denial of service. MariaDB fixed the issue in version 5.5.47; Red Hat stated that RHSA-2016:0534 and Software Collections advisories already remediated affected packages.
Red Hat documented CVE-2016-0649 as a Moderate-severity authenticated availability vulnerability in the Prepared Statements subcomponent of Oracle MySQL and MariaDB. The issue affects specified MySQL and MariaDB releases and was remediated through multiple existing 2016 RHEL and Software Collections advisories.
Red Hat documented CVE-2016-0641 as a Moderate-severity MyISAM vulnerability in Oracle MySQL and MariaDB that lets authenticated local users affect confidentiality and availability. The issue affects specified MySQL releases through 5.7.10 and MariaDB releases before 5.5.48, 10.0.24, and 10.1.12, and was addressed through existing 2016 Red Hat advisories.
Red Hat documented CVE-2016-0643 as a Moderate-severity authenticated confidentiality vulnerability in the Oracle MySQL and MariaDB Server DML component. The issue affects specified MySQL and MariaDB versions and was remediated through existing 2016 RHEL and Software Collections advisories.
Red Hat documented CVE-2016-3452 as a Low-severity, unauthenticated remote confidentiality vulnerability in the Server: Security: Encryption component of Oracle MySQL and MariaDB. The issue affects specified MySQL and MariaDB versions and was fixed through existing 2016 RHEL and Software Collections advisories.
Red Hat documented CVE-2016-0646 as a Moderate-severity local availability vulnerability in Oracle MySQL and MariaDB Server DML functionality. The issue affects specified MySQL and MariaDB versions and was remediated through existing 2016 RHEL and Software Collections advisories.
Red Hat documented CVE-2016-0648 as a Moderate-severity authenticated availability vulnerability in the MySQL Server PS subcomponent, affecting specified MySQL and MariaDB versions. Red Hat assigned a CVSS v2 score of 4.0 and noted that existing errata fixed affected RHEL 7 and Software Collections packages.
Red Hat publicly posted vulnerability records for CVE-2016-5609, a MySQL DML availability flaw, and CVE-2016-8288, a MySQL InnoDB Plugin integrity flaw.
Oracle's October 2016 Critical Patch Update included or referenced CVE-2016-5609 and CVE-2016-5627, which affect MySQL DML and InnoDB components, respectively.
Red Hat addressed CVE-2016-0666, a low-privileged local denial-of-service flaw in MySQL Server's Security: Privileges component, through multiple 2016 advisories. The fixes covered affected Red Hat Enterprise Linux 7 and Red Hat Software Collections packages for RHEL 6 and 7.
Red Hat published CVE-2016-0642, a Moderate-severity authenticated vulnerability in Oracle MySQL's Federated component that can affect integrity and availability. It affects MySQL through 5.5.48, 5.6.29, and 5.7.11; Red Hat noted fixes were available through RHSA-2016:0534 and subsequent Software Collections advisories.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.