Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "9.5"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*"
},
{
"extracted_events": [
{
"introduced": "7.3"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*"
},
{
"extracted_events": [
{
"last_affected": "16.04"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "18.04"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "19.10"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "20.04"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "30"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "31"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "32"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*"
}
]
}"2026-04-11T23:13:21Z"
[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "268414797295401743171423323680366405200",
"length": 623.0
},
"source": "https://github.com/mysql/mysql-server/commit/ea7d2e2d16ac03afdd9cb72a972a95981107bf51",
"id": "CVE-2020-2897-7ba491c1",
"target": {
"file": "storage/innobase/lob/lob0lob.cc",
"function": "ref_t::mark_not_partially_updatable"
},
"signature_type": "Function"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"178328081134631892205165699778675444929",
"297069519883944742228860306989667015308",
"271109606063349901820849047573123524993"
]
},
"source": "https://github.com/mysql/mysql-server/commit/ea7d2e2d16ac03afdd9cb72a972a95981107bf51",
"id": "CVE-2020-2897-85335a60",
"target": {
"file": "storage/innobase/lob/lob0lob.cc"
},
"signature_type": "Line"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "332510893913262879819453630442491115668",
"length": 3285.0
},
"source": "https://github.com/mysql/mysql-server/commit/ea7d2e2d16ac03afdd9cb72a972a95981107bf51",
"id": "CVE-2020-2897-ba81527a",
"target": {
"file": "storage/innobase/lob/lob0purge.cc",
"function": "purge"
},
"signature_type": "Function"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"180778886619526508923404944111269113775",
"147316919537316689965784322676330417174",
"5239905161954509642413945198745085468",
"17024492428593150706336629452115852309",
"104965365280811678162014628868762321369",
"282655202815067031575135368237605253571",
"200985396871617803559027719623855045437"
]
},
"source": "https://github.com/mysql/mysql-server/commit/ea7d2e2d16ac03afdd9cb72a972a95981107bf51",
"id": "CVE-2020-2897-d821719f",
"target": {
"file": "storage/innobase/lob/lob0purge.cc"
},
"signature_type": "Line"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"283235786766717374315559903386315292221",
"192355070266660537871885306096569471401",
"43630985206282853845868250559889278152",
"172939939025117458516457434116810536184"
]
},
"source": "https://github.com/mysql/mysql-server/commit/ea7d2e2d16ac03afdd9cb72a972a95981107bf51",
"id": "CVE-2020-2897-e9f11d86",
"target": {
"file": "storage/innobase/include/lob0lob.h"
},
"signature_type": "Line"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-2897.json"