Release of MySQL DBMS 9.6.0

Oracle has formed a new branch of the MySQL DBMS, version 9.6.0. The MySQL Community Server 9.6.0 builds are prepared for all major Linux distributions, FreeBSD, macOS, and Windows. In accordance with the release model introduced in 2023, MySQL 9.6 is classified under the 'Innovation' branches. Innovation branches are recommended for those who wish to access new functionality early, are published every three months, and are supported only until the next significant release is published (for example, support for branch 9.5 ends after the release of branch 9.6). Later, an LTS release of 9.7 is planned, recommended for deployments that require predictability and long-term stability of behavior. Following the LTS release, a new Innovation branch will be formed — MySQL 10.0.

The list of significant changes in MySQL 9.6 completely mirrors the changelog of MySQL 9.5. It also mentions the previously noted behavioral change of the 'innodb_log_writer_threads' parameter, the change in the default value of the 'binlog_transaction_dependency_history_size' parameter, deprecating the SCRAM-SHA-1 authentication method, and discontinuation of support for the variables 'group_replication_allow_local_lower_version_join' and 'replica_parallel_type'. The overall list of fixes differs and includes the following notable changes:

  • The audit system has been reworked, implementing a modular Audit Log subsystem that allows separate installation and management of various components for maintaining an audit log, as well as simplifying the configuration of log formats, audit file placements, and buffering parameters. To change the system variable 'audit_log_rotate_on_size', the AUDIT_ADMIN privileges are now required.
  • A new data structure and a new built-in library of functions for working with Global Transaction IDs (GTID) used in replication have been deployed. The new implementation features improved high performance and simplified code.
  • In the InnoDB storage engine, the efficiency of generating unique row IDs in tables without primary keys has been enhanced. The issue with the incorrect restoration of the status of transactions that were in 'PREPARED' state at the time of an unexpected shutdown has been resolved.
  • A new option ‘—container_aware’ has been added, which, when started, enables the recognition of CPU and memory limits set in the container.
  • Debugging capabilities for replication have been expanded.
  • The SQL functions MD5() and SHA1() have been separated into a separate component called 'classic_hashing', which can be disabled if necessary to block the use of insecure hashing algorithms.
  • Fourteen vulnerabilities have been fixed, two of which can be exploited remotely. The most serious issue has a critical severity level of 9.8, exists in the official Docker image with MySQL, and is related to a vulnerability in the SQLite library (CVE-2025-6965), which is used by auxiliary tools for configuring and operating MySQL. The second remotely exploitable vulnerability has a severity level of 7.5 and is caused by a buffer overflow (CVE-2025-9230) in the OpenSSL library. Less critical vulnerabilities affect OpenSSL, InnoDB, optimizer, DDL, parser, Pluggable Auth, and Thread Pooling. Details are not currently available.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster