PatchSiren cyber security CVE debrief
CVE-2017-3251 Oracle CVE debrief
CVE-2017-3251 describes a MySQL Server vulnerability in Oracle’s Optimizer subcomponent that can let a high-privileged attacker reachable over the network trigger a hang or repeatable crash of the server. The impact is availability-only, but the issue is operationally important because it can produce a complete denial of service on affected MySQL deployments.
- Vendor
- Oracle
- Product
- Mysql
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Database administrators, SREs, platform teams, and security teams running Oracle MySQL Server 5.7.16 or earlier should review exposure, especially where privileged database accounts or remote administrative access are present.
Technical summary
According to the NVD record and Oracle’s January 2017 CPU advisory, the flaw is in the MySQL Server component, specifically the Server: Optimizer subcomponent. The CVSS v3.0 vector (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) indicates a network-exploitable issue that requires high privileges but no user interaction, and successful exploitation can cause a hang or frequently repeatable crash. The affected version range in the supplied corpus ends at MySQL 5.7.16.
Defensive priority
Medium. The vulnerability does not indicate confidentiality or integrity impact, but it can take down database availability and requires attention wherever privileged access is exposed or tightly controlled.
Recommended defensive actions
- Confirm whether any Oracle MySQL Server installations are at version 5.7.16 or earlier.
- Review which accounts have the privileges needed to reach MySQL management or administrative paths.
- Restrict network access to MySQL service endpoints to trusted hosts only.
- Prioritize upgrade or vendor remediation planning for any affected instances.
- Validate monitoring and restart procedures for MySQL availability incidents so repeatable crashes are detected quickly.
Evidence notes
The description, CVSS vector, and affected version ceiling come from the NVD CVE record for CVE-2017-3251. Oracle’s January 2017 CPU advisory is listed in the official references, along with downstream security tracker and distro advisory references that corroborate broad vendor tracking. No exploit details or remediation version beyond the supplied corpus were used.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3251 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3251
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3251 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3251
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2017:2886
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201702-17
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.