[CLSA-2026:1791532798] Fix CVE(s): CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-09 08:00:10 UTC
Description:
* SECURITY UPDATE: out-of-bounds reads in the mysqlnd wire-protocol packet readers - debian/patches/php-7.3-CVE-2025-1218.patch: backport upstream commit 114dbb7436 in ext/mysqlnd/ - the packet readers decoded fields out of a server response before checking that the packet still held enough bytes for them, so a malicious or compromised MySQL server could make the client read past the end of the packet buffer by sending a truncated packet. BAIL_IF_NO_MORE_DATA, which only noticed an over-read after it had happened, is replaced by BAIL_IF_NOT_ENOUGH_DATA_EX(n); php_mysqlnd_net_field_length() and its _ll variant take a remaining_size argument and refuse to decode a length whose payload is not present; the auth-plugin-name reads in greet_read, auth_response_read and chg_user_read use memchr() instead of trusting a NUL terminator; and mysqlnd_ps_codec.c rejects a declared field length that is too short for the fixed offsets the TIME/DATE/DATETIME readers decode. The patch also carries the prerequisite upstream commit d37a20c4a2 (php-8.2.27), which bounds the auth_protocol read in greet_read: the CVE fix removes the NUL terminator that greeting buffer relied on, so without it that read would become a stack over-read. The ext/mysqlnd/mysqlnd_ps.c hunk is a memory-leak fix on the failure path the new bounds checks make reachable, and the prepare_read() and sha256_pk_request_response_read() hunks are hardening, not memory-safety fixes. Upstream's regression tests are not carried: they drive the dynamic-port fake server upstream added in the same commit, while this branch's ext/standard/tests/mysqli/fake_server.inc harness binds a fixed port, and nothing in this package runs the suite. The 32 of them that apply here were run locally instead, on a tree built from this repository's own patch series, first patched and then with only the C hunks of this patch reversed out and rebuilt: 32 of 32 pass patched, 0 fail; 8 of 32 pass unpatched, 24 fail. - debian/patches/php-7.3-CVE-2025-1218-caching-sha2.patch: the same fix for php_mysqlnd_cached_sha2_result_read(), which does not exist at php-7.3.33 but is introduced by debian/patches/php-7.3.33-caching-sha2-password.patch with the unterminated-plugin-name over-read and the one-byte over-read on the normal path. Kept separate because the Alpine build does not apply the caching_sha2_password backport. - Also fixes a pre-existing use-after-free on the row-reader failure path. The CVE-2024-8929 backport added error loops in the binary- and text-protocol row readers that zval_ptr_dtor() every field decoded so far and return FAIL without clearing the zvals, so the result set frees the same zvals again when it is torn down. The loops were already reachable before this change; the new too-short TIME/DATE/DATETIME check adds a second way in. All 3 sites now clear the zval after freeing it. Confirmed under AddressSanitizer with the Zend allocator disabled: heap-use-after-free in mysqlnd_result_buffered_zval free_result before, clean after, on both the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected. - CVE-2025-1218
CVEs fixed:
Updated packages:
  • alt-php73_7.3.33-83_amd64.deb
    sha:0b9daaa88f79489d47e2b43e0350fc3e2ebdbe5c
  • alt-php73-bcmath_7.3.33-83_amd64.deb
    sha:7af973f9d5792c909eb222696e6aae516d7bcedb
  • alt-php73-cli_7.3.33-83_amd64.deb
    sha:15b7775249bab7993742007313642bd308774f7f
  • alt-php73-common_7.3.33-83_amd64.deb
    sha:302a7132fba5125c961f67d010a9f09f3b3a9ce5
  • alt-php73-dba_7.3.33-83_amd64.deb
    sha:48fed4ffd00057a1a7c12243ac1bfb618be85c14
  • alt-php73-dev_7.3.33-83_amd64.deb
    sha:28586594e50db7d5897d31c9ec07fe3aa17f5ae5
  • alt-php73-enchant_7.3.33-83_amd64.deb
    sha:96b4a303b0f99544ca2ad2f7a463985958fde276
  • alt-php73-firebird_7.3.33-83_amd64.deb
    sha:581d13aa0f3ce760e5051bb5fdb041105d1e16de
  • alt-php73-gd_7.3.33-83_amd64.deb
    sha:90c7778b08f696a465d3bf60942d41611ee57538
  • alt-php73-imap_7.3.33-83_amd64.deb
    sha:a4ecf6eeb071696d81b2fedf18fafc574d5619ef
  • alt-php73-intl_7.3.33-83_amd64.deb
    sha:f49466f19582a3eebca589e18d112414ae817faf
  • alt-php73-ldap_7.3.33-83_amd64.deb
    sha:4a8e385946fb21ee5300952e5c68bf17dd2785f1
  • alt-php73-mbstring_7.3.33-83_amd64.deb
    sha:bb39c32334336e20ae6d6f32e2d73b07f15dd0a6
  • alt-php73-mysqlnd_7.3.33-83_amd64.deb
    sha:109e8ee2c47c970ce7222d036969e6105f910c71
  • alt-php73-odbc_7.3.33-83_amd64.deb
    sha:f7119d07fcc8b5b79541ddb0e0fdf6e54f2ff1ca
  • alt-php73-opcache_7.3.33-83_amd64.deb
    sha:81e406d731fda44601523d14fe6cbf2ace8b99ce
  • alt-php73-pdo_7.3.33-83_amd64.deb
    sha:a80463a38f3ddb88262360ebe01d281de06f7625
  • alt-php73-pgsql_7.3.33-83_amd64.deb
    sha:39e111622a736629b80531d3dd4b3e7e6d4e6480
  • alt-php73-php-fpm_7.3.33-83_amd64.deb
    sha:e9cfd4318f41df4cfbe81269d6d0f836f419ebb0
  • alt-php73-process_7.3.33-83_amd64.deb
    sha:3d6bb02bc84614849bda26a4d559a0448cb96495
  • alt-php73-pspell_7.3.33-83_amd64.deb
    sha:b24a8d5ff811195fcb629bfbb81968b5d0887a9c
  • alt-php73-recode_7.3.33-83_amd64.deb
    sha:0b7b5d2753d90f368a2d63b17968ffb5ad41cf3f
  • alt-php73-snmp_7.3.33-83_amd64.deb
    sha:5a66a6913e9d25207eb306be1d435d0f47253983
  • alt-php73-soap_7.3.33-83_amd64.deb
    sha:ef3fc0a4f6e6161fd681344785485f83c793e1eb
  • alt-php73-sodium_7.3.33-83_amd64.deb
    sha:f0fcdbe1d2e14f3a5d01e46fdf437c23196279b7
  • alt-php73-tidy_7.3.33-83_amd64.deb
    sha:716e3eda5d14457dd263e335a02bcbc02fa37648
  • alt-php73-xml_7.3.33-83_amd64.deb
    sha:b533fca84834fb120f3bf185aa031fc4e8080db9
  • alt-php73-xmlrpc_7.3.33-83_amd64.deb
    sha:530931120a54ba8c4b47dc632c027870fca6edd6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.