Red Hat released RHSA-2015:0116, RHSA-2015:0117, and RHSA-2015:0118 to upgrade MySQL and MariaDB packages to version 5.5.41 and remediate seven vulnerabilities inherited from Oracle’s January 2015 Critical Patch Update. Affected deployments include Red Hat Enterprise Linux 7 MariaDB installations and Red Hat Software Collections 1 MySQL/MariaDB installations on RHEL 6 and 7, including applicable RHUI Server variants.
The flaws affect InnoDB DML and foreign-key handling, privilege management, replication, DDL, and encryption functionality. Included issues such as CVE-2014-6568 could allow an authenticated remote user to cause partial service-availability impact, while CVE-2015-0374 could expose confidential information through Server Security, Privileges, and Foreign Key functionality. Red Hat advised affected users to install the updated packages; the mysqld service restarts automatically after installation.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2015:1628, fixing the affected mysql55-mysql component for Red Hat Enterprise Linux 5, including fixes for CVE-2014-6568 and CVE-2015-0374.
Red Hat released RHBA-2015:0825 to fix the affected mariadb-galera component in Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7.
RHBA-2015:0820 fixed affected Ceph, MariaDB Galera, OpenStack utility, and Python components in Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6.
Red Hat issued Moderate-severity RHSA-2015:0117 for mariadb55-mariadb in Red Hat Software Collections 1, upgrading MariaDB to 5.5.41 and fixing seven vulnerabilities affecting applicable RHEL 6 and 7 systems.
Red Hat issued Moderate-severity RHSA-2015:0118, upgrading RHEL 7 MariaDB packages to version 5.5.41 and remediating seven MySQL-derived vulnerabilities, including CVE-2014-6568 and CVE-2015-0374.
Red Hat issued Moderate-severity RHSA-2015:0116 for mysql55-mysql in Red Hat Software Collections 1, upgrading MySQL to 5.5.41 and fixing seven MySQL vulnerabilities for affected RHEL 6 and 7 deployments.
Oracle's January 2015 Critical Patch Update included the MySQL vulnerabilities later tracked as CVE-2014-6568, CVE-2015-0374, CVE-2015-0381, CVE-2015-0382, CVE-2015-0391, CVE-2015-0411, and CVE-2015-0432.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.