{"id":"USN-8363-2","summary":"mysql-8.0 vulnerabilities","details":"USN-8363-1 fixed several vulnerabilities in MySQL. This update\nprovides the corresponding fixes for MySQL on Ubuntu 20.04 LTS.\n\nOriginal advisory details:\n\n Multiple security issues were discovered in MySQL and this update includes\n new upstream MySQL versions to fix these issues.\n\n MySQL has been updated to 8.0.46 in Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.\n Ubuntu 25.10 and Ubuntu 26.04 LTS have been updated to MySQL 8.4.9.\n\n In addition to security fixes, the updated packages contain bug fixes, new\n features, and possibly incompatible changes.\n\n Please see the following for more information:\n\n https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-46.html\n https://dev.mysql.com/doc/relnotes/mysql/8.4/en/news-8-4-9.html\n https://www.oracle.com/security-alerts/cpuapr2026.html","modified":"2026-06-03T18:03:09.917955216Z","published":"2026-06-03T07:43:47Z","related":["UBUNTU-CVE-2026-21998","UBUNTU-CVE-2026-22001","UBUNTU-CVE-2026-22002","UBUNTU-CVE-2026-22004","UBUNTU-CVE-2026-22005","UBUNTU-CVE-2026-22009","UBUNTU-CVE-2026-22015","UBUNTU-CVE-2026-22017","UBUNTU-CVE-2026-34267","UBUNTU-CVE-2026-34270","UBUNTU-CVE-2026-34271","UBUNTU-CVE-2026-34276","UBUNTU-CVE-2026-34278","UBUNTU-CVE-2026-34293","UBUNTU-CVE-2026-34303","UBUNTU-CVE-2026-34304","UBUNTU-CVE-2026-34308","UBUNTU-CVE-2026-34317","UBUNTU-CVE-2026-34318","UBUNTU-CVE-2026-34319","UBUNTU-CVE-2026-35236","UBUNTU-CVE-2026-35237","UBUNTU-CVE-2026-35238","UBUNTU-CVE-2026-35239","UBUNTU-CVE-2026-35240"],"upstream":["CVE-2026-21998","CVE-2026-22001","CVE-2026-22002","CVE-2026-22004","CVE-2026-22005","CVE-2026-22009","CVE-2026-22015","CVE-2026-22017","CVE-2026-34267","CVE-2026-34270","CVE-2026-34271","CVE-2026-34276","CVE-2026-34278","CVE-2026-34293","CVE-2026-34303","CVE-2026-34304","CVE-2026-34308","CVE-2026-34317","CVE-2026-34318","CVE-2026-34319","CVE-2026-35236","CVE-2026-35237","CVE-2026-35238","CVE-2026-35239","CVE-2026-35240","UBUNTU-CVE-2026-21998","UBUNTU-CVE-2026-22001","UBUNTU-CVE-2026-22002","UBUNTU-CVE-2026-22004","UBUNTU-CVE-2026-22005","UBUNTU-CVE-2026-22009","UBUNTU-CVE-2026-22015","UBUNTU-CVE-2026-22017","UBUNTU-CVE-2026-34267","UBUNTU-CVE-2026-34270","UBUNTU-CVE-2026-34271","UBUNTU-CVE-2026-34276","UBUNTU-CVE-2026-34278","UBUNTU-CVE-2026-34293","UBUNTU-CVE-2026-34303","UBUNTU-CVE-2026-34304","UBUNTU-CVE-2026-34308","UBUNTU-CVE-2026-34317","UBUNTU-CVE-2026-34318","UBUNTU-CVE-2026-34319","UBUNTU-CVE-2026-35236","UBUNTU-CVE-2026-35237","UBUNTU-CVE-2026-35238","UBUNTU-CVE-2026-35239","UBUNTU-CVE-2026-35240"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8363-2"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-21998"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-22001"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-22002"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-22004"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-22005"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-22009"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-22015"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-22017"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34267"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34270"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34271"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34276"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34278"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34293"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34303"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34304"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34308"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34317"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34318"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34319"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-35236"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-35237"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-35238"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-35239"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-35240"}],"affected":[{"package":{"name":"mysql-8.0","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/mysql-8.0?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.0.46-0ubuntu0.20.04.1+esm2"}]}],"versions":["8.0.17-0ubuntu2","8.0.17-0ubuntu3","8.0.18-0ubuntu3","8.0.18-0ubuntu4","8.0.18-0ubuntu5","8.0.19-0ubuntu2","8.0.19-0ubuntu3","8.0.19-0ubuntu4","8.0.19-0ubuntu5","8.0.20-0ubuntu0.20.04.1","8.0.21-0ubuntu0.20.04.3","8.0.21-0ubuntu0.20.04.4","8.0.22-0ubuntu0.20.04.2","8.0.22-0ubuntu0.20.04.3","8.0.23-0ubuntu0.20.04.1","8.0.25-0ubuntu0.20.04.1","8.0.26-0ubuntu0.20.04.2","8.0.26-0ubuntu0.20.04.3","8.0.27-0ubuntu0.20.04.1","8.0.28-0ubuntu0.20.04.3","8.0.29-0ubuntu0.20.04.2","8.0.29-0ubuntu0.20.04.3","8.0.30-0ubuntu0.20.04.2","8.0.31-0ubuntu0.20.04.1","8.0.31-0ubuntu0.20.04.2","8.0.32-0buntu0.20.04.1","8.0.32-0ubuntu0.20.04.2","8.0.33-0ubuntu0.20.04.1","8.0.33-0ubuntu0.20.04.2","8.0.33-0ubuntu0.20.04.4","8.0.34-0ubuntu0.20.04.1","8.0.35-0ubuntu0.20.04.1","8.0.36-0ubuntu0.20.04.1","8.0.37-0ubuntu0.20.04.3","8.0.39-0ubuntu0.20.04.1","8.0.40-0ubuntu0.20.04.1","8.0.41-0ubuntu0.20.04.1","8.0.42-0ubuntu0.20.04.1","8.0.43-0ubuntu0.20.04.1+esm1","8.0.45-0ubuntu0.20.04.1+esm2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_version":"8.0.46-0ubuntu0.20.04.1+esm2","binary_name":"libmysqlclient21"},{"binary_version":"8.0.46-0ubuntu0.20.04.1+esm2","binary_name":"mysql-client"},{"binary_version":"8.0.46-0ubuntu0.20.04.1+esm2","binary_name":"mysql-client-8.0"},{"binary_version":"8.0.46-0ubuntu0.20.04.1+esm2","binary_name":"mysql-client-core-8.0"},{"binary_version":"8.0.46-0ubuntu0.20.04.1+esm2","binary_name":"mysql-router"},{"binary_version":"8.0.46-0ubuntu0.20.04.1+esm2","binary_name":"mysql-server"},{"binary_version":"8.0.46-0ubuntu0.20.04.1+esm2","binary_name":"mysql-server-8.0"},{"binary_version":"8.0.46-0ubuntu0.20.04.1+esm2","binary_name":"mysql-server-core-8.0"},{"binary_version":"8.0.46-0ubuntu0.20.04.1+esm2","binary_name":"mysql-source-8.0"},{"binary_version":"8.0.46-0ubuntu0.20.04.1+esm2","binary_name":"mysql-testsuite"},{"binary_version":"8.0.46-0ubuntu0.20.04.1+esm2","binary_name":"mysql-testsuite-8.0"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[{"id":"CVE-2026-21998","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-22001","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-22002","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-22004","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-22005","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-22009","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-22015","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-22017","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-34267","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-34270","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-34271","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-34276","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-34278","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-34293","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-34303","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-34304","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-34308","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-34317","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-34318","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-34319","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-35236","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-35237","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-35238","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-35239","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-35240","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8363-2.json"}}],"schema_version":"1.7.5"}