Back Linuxsecurity Fedora 44 MySQL 8.4.10 Critical DoS Vulnerability CVE-2026
MySQL 8.4.10 Release notes: Upstream changelog: Oracle Critical Security Patch Update - June 2026: CVE-2026-46863 (CVSS 7.5) - Server: Connection Handling The only CVE from the June 2026 CPU affecting the 'mysql8.4' package. Remotely exploitable without authentication (DoS). The remaining 7 CVEs affect MySQL Shell (VS Code extension), MySQL Router, and NDB Cluster Operator — none of which are built or shipped by this package.
* Tue Jun 23 2026 Michal Schorm - 8.4.10-1 - Rebase to 8.4.10 * Fri Jun 12 2026 Yaakov Selkowitz - 8.4.9-4 - Rebuilt for openssl 4.0 * Mon Jun 8 2026 František Zatloukal - 8.4.9-3 - Rebuilt for icu 78.3 * Wed May 13 2026 Pavol Sloboda - 8.4.9-2 - Bump release for openssl4 fixup
* Tue Jun 23 2026 Michal Schorm - 8.4.10-1 - Rebase to 8.4.10 * Fri Jun 12 2026 Yaakov Selkowitz - 8.4.9-4 - Rebuilt for openssl 4.0 * Mon Jun 8 2026 František Zatloukal - 8.4.9-3 - Rebuilt for icu 78.3 * Wed May 13 2026 Pavol Sloboda - 8.4.9-2 - Bump release for openssl4 fixup
[ 1 ] Bug #2489372 - mysql8.4-8.4.10 is available
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8c7f5e32c5' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
