PatchSiren cyber security CVE debrief
CVE-2017-3256 Oracle CVE debrief
CVE-2017-3256 is a network-reachable availability issue in Oracle MySQL Server’s replication component. According to NVD, a low-privileged attacker can trigger a hang or repeatedly crash the server, causing a complete denial of service. The affected product scope covers Oracle MySQL 5.7.16 and earlier.
- Vendor
- Oracle
- Product
- Mysql
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Database administrators, SREs, and platform owners running Oracle MySQL 5.7.16 or earlier, especially on servers exposed to untrusted networks or used in replication topologies.
Technical summary
NVD describes the issue as affecting the MySQL Server component, specifically Server: Replication. The attack vector is network-based and requires low privileges, with no user interaction. Successful exploitation can cause a hang or frequently repeatable crash, resulting in availability loss only. NVD classifies the weakness as CWE-20 (Improper Input Validation) and lists vulnerable Oracle MySQL versions up to and including 5.7.16.
Defensive priority
Medium severity, but higher operational priority for exposed or mission-critical MySQL servers because the impact is a repeatable service crash/hang.
Recommended defensive actions
- Upgrade Oracle MySQL to a version newer than 5.7.16 using Oracle’s patched releases.
- Inventory all MySQL instances and confirm whether they match the affected CPE range for Oracle MySQL up to 5.7.16.
- Restrict network access to MySQL services so only trusted hosts and administration paths can reach them.
- Review replication deployments for availability safeguards such as monitoring, restart automation, and failover procedures.
- Apply vendor-supported downstream package updates where applicable, including distribution advisories referenced by NVD.
Evidence notes
The supplied NVD record states the affected CPE range (oracle:mysql:* through 5.7.16), the CVSS v3.0 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), and the CWE-20 classification. NVD also references Oracle’s January 2017 CPU advisory as the vendor patch reference, plus downstream advisories from Red Hat and Gentoo.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3256 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3256
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3256 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3256
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2017:2886
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201702-17
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.