USN-5400-2

Source
https://ubuntu.com/security/notices/USN-5400-2
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5400-2.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5400-2
Upstream
Related
Published
2022-05-04T12:45:12.880353Z
Modified
2025-10-13T04:35:54Z
Summary
mysql-5.7 vulnerabilities
Details

USN-5400-1 fixed several vulnerabilities in MySQL. This update provides the corresponding update for Ubuntu 16.04 ESM.

Original advisory details:

Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues.

MySQL has been updated in Ubuntu 16.04 ESM to MySQL 5.7.38.

In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes.

Please see the following for more information:

https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-38.html https://www.oracle.com/security-alerts/cpuapr2022.html

References

Affected packages

Ubuntu:Pro:16.04:LTS / mysql-5.7

Package

Name
mysql-5.7
Purl
pkg:deb/ubuntu/mysql-5.7@5.7.38-0ubuntu0.16.04.1+esm1?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.7.38-0ubuntu0.16.04.1+esm1

Affected versions

5.*

5.7.11-0ubuntu4
5.7.11-0ubuntu5
5.7.11-0ubuntu6
5.7.12-0ubuntu1
5.7.12-0ubuntu1.1
5.7.13-0ubuntu0.16.04.2
5.7.15-0ubuntu0.16.04.1
5.7.16-0ubuntu0.16.04.1
5.7.17-0ubuntu0.16.04.1
5.7.17-0ubuntu0.16.04.2
5.7.18-0ubuntu0.16.04.1
5.7.19-0ubuntu0.16.04.1
5.7.20-0ubuntu0.16.04.1
5.7.21-0ubuntu0.16.04.1
5.7.22-0ubuntu0.16.04.1
5.7.23-0ubuntu0.16.04.1
5.7.24-0ubuntu0.16.04.1
5.7.25-0ubuntu0.16.04.2
5.7.26-0ubuntu0.16.04.1
5.7.27-0ubuntu0.16.04.1
5.7.28-0ubuntu0.16.04.2
5.7.29-0ubuntu0.16.04.1
5.7.30-0ubuntu0.16.04.1
5.7.31-0ubuntu0.16.04.1
5.7.32-0ubuntu0.16.04.1
5.7.33-0ubuntu0.16.04.1
5.7.35-0ubuntu0.16.04.1+esm1
5.7.36-0ubuntu0.16.04.1+esm1
5.7.37-0ubuntu0.16.04.1+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmysqlclient-dev",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "libmysqlclient20",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "libmysqld-dev",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "mysql-client",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "mysql-client-5.7",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "mysql-client-core-5.7",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "mysql-common",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "mysql-server",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "mysql-server-5.7",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "mysql-server-core-5.7",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "mysql-source-5.7",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "mysql-testsuite",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "mysql-testsuite-5.7",
            "binary_version": "5.7.38-0ubuntu0.16.04.1+esm1"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Database specific

cves_map

{
    "ecosystem": "Ubuntu:Pro:16.04:LTS",
    "cves": [
        {
            "id": "CVE-2022-21417",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2022-21427",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2022-21444",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2022-21451",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2022-21454",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2022-21460",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}