[CLSA-2026:1791382244] Fix CVE(s): CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-07 14:10:59 UTC
Description:
* SECURITY UPDATE: out-of-bounds reads in the mysqlnd wire-protocol parser - debian/patches/php-7.0-CVE-2025-1218.patch: mysqlnd read fields out of a server packet before checking that the packet still held enough bytes, so a malicious or compromised MySQL server could make the client read past the end of the packet buffer and, in several places, hand the bytes it found there back to the application. The old BAIL_IF_NO_MORE_DATA macro only noticed an over-read after it had happened; it is replaced by a BAIL_IF_NOT_ENOUGH_DATA_EX(n) family evaluated before each read. php_mysqlnd_net_field_length() and its _ll() variant now take the number of bytes left in the packet and refuse to decode a 2-, 3- or 8-byte length prefix that does not fit, so the length read can no longer itself over-read; _ll() returns an explicit "no value" result that every caller checks. Every strdup() of a server-supplied string is replaced by a memchr()-bounded copy, which removes unbounded over-reads of the greeting packet's server version off a 2048-byte stack buffer, of the auth-switch plugin name in auth_response_read() and chg_user_read(), and of the same field in cached_sha2_result_read(), where the buffer is again on the stack. A truncated auth-switch packet no longer underflows new_auth_protocol_data_len to SIZE_MAX and drives a huge allocation and copy. The greeting's extended scramble, the fixed 31-byte greeting block, the server_status/warning_count pairs in auth_response_read(), ok_read(), eof_read() and rset_header_read(), the in-row EOF marker in rowp_read() and the fixed offsets read by the time, date and datetime binary fetchers are all now checked against the declared length before being read. Result-set field metadata no longer accepts a length that points past the end of the packet, which stopped heap bytes from being published as column names. cached_sha2_result_read() also no longer reads one byte past the end of the two-byte packet the server normally sends. - The same patch carries, as a prerequisite, upstream's earlier bounding of the greeting packet's auth_protocol field (upstream d37a20c4a24a70dbbcfd8724cd2ad5f1b005bd2a, first released in 8.2.27), which this branch did not have. Without it, removing the buf[header.size] = '\0' hack that CVE-2025-1218 removes would have turned that read into an unbounded stack over-read. - Two of the changes are hardening rather than memory-safety fixes and are taken only to stay close to upstream: the length checks added to prepare_read() cannot fire behind the PREPARE_RESPONSE_SIZE gate that precedes them, and the sha256_pk_request_response_read() change is a strictness change. The ext/mysqlnd/mysqlnd_ps.c hunk is a leak fix: it releases the connection reference and the execute command buffer before the memset() that resets a statement, on the failure path this fix makes newly reachable. - Upstream's 38 regression tests are NOT carried. They drive the dynamic-port fake server upstream added in the same commit, while the harness this tree has, ext/standard/tests/mysqli/fake_server.inc from the CVE-2024-8929 backport, binds a fixed port and would need all 38 rewritten around it. Nothing would run them either way: the rpm check stage is gated behind runselftest, which defaults to 0, and debian/rules has no test target. They were run locally instead, on a tree built from this repository's own patch series, first patched and then with only the C hunks of this patch reversed out and rebuilt: 32 of 38 pass patched, 0 fail; 8 of 38 pass unpatched, 24 fail. The 6 skips in both arms are the cached-sha2 and sha256-pk tests, which need an ext/openssl this build did not have. - Also fixes a pre-existing use-after-free on the row-reader failure path. The CVE-2024-8929 backport added error loops in the binary- and text-protocol row readers that zval_ptr_dtor() every field decoded so far and return FAIL without clearing the zvals, so the result set frees the same zvals again when it is torn down. The loops were already reachable before this change; the new too-short TIME/DATE/DATETIME check adds a second way in. All 3 sites now clear the zval after freeing it. Confirmed under AddressSanitizer with the Zend allocator disabled: heap-use-after-free in mysqlnd_result_buffered_zval free_result before, clean after, on both the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected. - The mysqlnd_ps.c hunk additionally releases the result's own connection reference on the prepare-EOF path. Before PHP 7.4 (upstream f365d0e00ed93b1c33e984ff3b4cc8677cbca193) free_result_contents() did not drop it, so that path leaked one reference. The sibling site in mysqlnd_stmt store_result() leaks the same reference but is not made reachable by this change and is left for a separate one.
CVEs fixed:
Updated packages:
  • alt-php70_7.0.33-150_amd64.deb
    sha:3de3c54d136bd428c284942b865d1aeda2706e83
  • alt-php70-bcmath_7.0.33-150_amd64.deb
    sha:3b7b435e958f1177459b9a2225120f456dff7569
  • alt-php70-cli_7.0.33-150_amd64.deb
    sha:7b54de92d5b95a8e95dde0f3e284a7abaa2da7bf
  • alt-php70-common_7.0.33-150_amd64.deb
    sha:7c4c7c7e44b131dcc2cf86897935ed4a3bd69bf6
  • alt-php70-dba_7.0.33-150_amd64.deb
    sha:3ae80149324d19dd9e477a4d63d0f806f0635a71
  • alt-php70-dev_7.0.33-150_amd64.deb
    sha:6c342ba9340fec4d764d0537e74707b1a4a8b5fa
  • alt-php70-enchant_7.0.33-150_amd64.deb
    sha:407a0c12cf434d53270cefe0747be71be2849b5d
  • alt-php70-firebird_7.0.33-150_amd64.deb
    sha:d15cb344242df006ff8042aef806b3166243ab9e
  • alt-php70-gd_7.0.33-150_amd64.deb
    sha:d66ca1d416bc558868f3c68be48c5c5b0d666d6f
  • alt-php70-imap_7.0.33-150_amd64.deb
    sha:13e6bf50dd9861decfb029343786eaf2c8934162
  • alt-php70-intl_7.0.33-150_amd64.deb
    sha:67dfc4d7800ce08a8bd167d77676e9922599be62
  • alt-php70-ldap_7.0.33-150_amd64.deb
    sha:e7c61d02a5e2cc8079f0bc5f6b4b1d8a237a29d0
  • alt-php70-mbstring_7.0.33-150_amd64.deb
    sha:6f501a8519a5abfa7b90bf0d73e7c3e294f385a7
  • alt-php70-mcrypt_7.0.33-150_amd64.deb
    sha:a6371d0c9dcee9a79517c4ac66ac7fb741f7927c
  • alt-php70-mysqlnd_7.0.33-150_amd64.deb
    sha:da12a64b06bb9e14051e67aeb0436d3f715f20a2
  • alt-php70-odbc_7.0.33-150_amd64.deb
    sha:4da3dcf35b9dd482e8cc9237ff27fe3fd6a08939
  • alt-php70-opcache_7.0.33-150_amd64.deb
    sha:4f1851f9822d2a807026889993028a2f61a3608c
  • alt-php70-pdo_7.0.33-150_amd64.deb
    sha:dffe72e07bea7fc85db09f4dd0253447ae5195e8
  • alt-php70-pgsql_7.0.33-150_amd64.deb
    sha:c9936827ebf16029719527c0345011ef0280a443
  • alt-php70-php-fpm_7.0.33-150_amd64.deb
    sha:60c9000e53749b3c1b8ffe22faa8156d62c1b16d
  • alt-php70-process_7.0.33-150_amd64.deb
    sha:3ebc8361f3fe7a684f11e4bf420170d85fdddece
  • alt-php70-pspell_7.0.33-150_amd64.deb
    sha:539d8d379d91d2af6c6be47a4b1e9571d6b21e8e
  • alt-php70-recode_7.0.33-150_amd64.deb
    sha:1a1e8441c6d457416dedeb738ef53274df19e405
  • alt-php70-snmp_7.0.33-150_amd64.deb
    sha:a71f8c3a5911ca45f62371c811e28b3d20ccca0e
  • alt-php70-soap_7.0.33-150_amd64.deb
    sha:2f12eac4126591bf3f1c411f37ce73b4e4175f5c
  • alt-php70-tidy_7.0.33-150_amd64.deb
    sha:5b5811b3c76b30fcd33a13617ce7620af1452fdc
  • alt-php70-xml_7.0.33-150_amd64.deb
    sha:725eae91337e48d9da6fc3b0dfc99f76ed4cdd6e
  • alt-php70-xmlrpc_7.0.33-150_amd64.deb
    sha:0e5ab4b970474b7a76c427caead070c527fa889f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.