Release date:
2026-10-07 12:15:46 UTC
Description:
* SECURITY UPDATE: out-of-bounds reads in the mysqlnd wire-protocol parser
- debian/patches/php-7.0-CVE-2025-1218.patch: mysqlnd read fields out of a
server packet before checking that the packet still held enough bytes, so
a malicious or compromised MySQL server could make the client read past
the end of the packet buffer and, in several places, hand the bytes it
found there back to the application. The old BAIL_IF_NO_MORE_DATA macro
only noticed an over-read after it had happened; it is replaced by a
BAIL_IF_NOT_ENOUGH_DATA_EX(n) family evaluated before each read.
php_mysqlnd_net_field_length() and its _ll() variant now take the number
of bytes left in the packet and refuse to decode a 2-, 3- or 8-byte
length prefix that does not fit, so the length read can no longer itself
over-read; _ll() returns an explicit "no value" result that every caller
checks. Every strdup() of a server-supplied string is replaced by a
memchr()-bounded copy, which removes unbounded over-reads of the greeting
packet's server version off a 2048-byte stack buffer, of the auth-switch
plugin name in auth_response_read() and chg_user_read(), and of the same
field in cached_sha2_result_read(), where the buffer is again on the
stack. A truncated auth-switch packet no longer underflows
new_auth_protocol_data_len to SIZE_MAX and drives a huge allocation and
copy. The greeting's extended scramble, the fixed 31-byte greeting block,
the server_status/warning_count pairs in auth_response_read(), ok_read(),
eof_read() and rset_header_read(), the in-row EOF marker in rowp_read()
and the fixed offsets read by the time, date and datetime binary fetchers
are all now checked against the declared length before being read.
Result-set field metadata no longer accepts a length that points past the
end of the packet, which stopped heap bytes from being published as
column names. cached_sha2_result_read() also no longer reads one byte
past the end of the two-byte packet the server normally sends.
- The same patch carries, as a prerequisite, upstream's earlier bounding of
the greeting packet's auth_protocol field (upstream
d37a20c4a24a70dbbcfd8724cd2ad5f1b005bd2a, first released in 8.2.27),
which this branch did not have. Without it, removing the
buf[header.size] = '\0' hack that CVE-2025-1218 removes would have turned
that read into an unbounded stack over-read.
- Two of the changes are hardening rather than memory-safety fixes and are
taken only to stay close to upstream: the length checks added to
prepare_read() cannot fire behind the PREPARE_RESPONSE_SIZE gate that
precedes them, and the sha256_pk_request_response_read() change is a
strictness change. The ext/mysqlnd/mysqlnd_ps.c hunk is a leak fix: it
releases the connection reference and the execute command buffer before
the memset() that resets a statement, on the failure path this fix makes
newly reachable.
- Upstream's 38 regression tests are NOT carried. They drive the
dynamic-port fake server upstream added in the same commit, while the
harness this tree has, ext/standard/tests/mysqli/fake_server.inc from
the CVE-2024-8929 backport, binds a fixed port and would need all 38
rewritten around it. Nothing would run them either way: the rpm check
stage is gated behind runselftest, which defaults to 0, and
debian/rules has no test target. They were run locally instead, on a
tree built from this repository's own patch series, first patched and
then with only the C hunks of this patch reversed out and rebuilt: 32
of 38 pass patched, 0 fail; 8 of 38 pass unpatched, 24 fail. The 6
skips in both arms are the cached-sha2 and sha256-pk tests, which need
an ext/openssl this build did not have.
- Also fixes a pre-existing use-after-free on the row-reader failure path.
The CVE-2024-8929 backport added error loops in the binary- and
text-protocol row readers that zval_ptr_dtor() every field decoded so far
and return FAIL without clearing the zvals, so the result set frees the
same zvals again when it is torn down. The loops were already reachable
before this change; the new too-short TIME/DATE/DATETIME check adds a
second way in. All 3 sites now clear the zval after freeing it.
Confirmed under AddressSanitizer with the Zend allocator disabled:
heap-use-after-free in mysqlnd_result_buffered_zval free_result before,
clean after, on both the three new short-length tests and the nine
CVE-2024-8929 stmt-row tests. Upstream still carries the same loops
unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected.
- The mysqlnd_ps.c hunk additionally releases the result's own connection
reference on the prepare-EOF path. Before PHP 7.4 (upstream
f365d0e00ed93b1c33e984ff3b4cc8677cbca193) free_result_contents() did not
drop it, so that path leaked one reference. The sibling site in
mysqlnd_stmt store_result() leaks the same reference but is not made
reachable by this change and is left for a separate one.
Updated packages:
-
alt-php70_7.0.33-150_amd64.deb
sha:3de3c54d136bd428c284942b865d1aeda2706e83
-
alt-php70-bcmath_7.0.33-150_amd64.deb
sha:24218ea29e1ff266fb21ce783bfc902028471253
-
alt-php70-cli_7.0.33-150_amd64.deb
sha:239cd20987ab1aee19b573496943f42127b5f7f7
-
alt-php70-common_7.0.33-150_amd64.deb
sha:6142152370f584f62787d0eb14e27b8d4b446d0f
-
alt-php70-dba_7.0.33-150_amd64.deb
sha:b0f082e3111f33507b8963793785ed63f10deb13
-
alt-php70-dev_7.0.33-150_amd64.deb
sha:26c978b28ff14916bb370ab8e798e658e8dfa406
-
alt-php70-enchant_7.0.33-150_amd64.deb
sha:a60d24101712861469140f8acd8671fb38fdcd86
-
alt-php70-firebird_7.0.33-150_amd64.deb
sha:9ba8d4979390af382006827c50b6d060ce36edec
-
alt-php70-gd_7.0.33-150_amd64.deb
sha:80a6a3d7a4eb6ad273c4b0dc93a7a79395c10aee
-
alt-php70-imap_7.0.33-150_amd64.deb
sha:7fedca05ec3c55ab6bf2eb21272a68af69d3ee24
-
alt-php70-intl_7.0.33-150_amd64.deb
sha:71fec0d54080d2858154b78b9bc37162d3088428
-
alt-php70-ldap_7.0.33-150_amd64.deb
sha:c59168447dc7ebb1414ef607f168d70d553b3a99
-
alt-php70-mbstring_7.0.33-150_amd64.deb
sha:8a0af07d0b99dd0f9e99cb963f1691d5e7a5b4b4
-
alt-php70-mcrypt_7.0.33-150_amd64.deb
sha:c011968fd814932e79d114894793846ffeb536da
-
alt-php70-mysqlnd_7.0.33-150_amd64.deb
sha:1a60108ee2cc020a07e2d9322357c9c7555ffc65
-
alt-php70-odbc_7.0.33-150_amd64.deb
sha:69c66b5910c57a329eeb5f334cc10a8c7c49cc23
-
alt-php70-opcache_7.0.33-150_amd64.deb
sha:ded166854c147e364fc4f4bfa75427de97122c8e
-
alt-php70-pdo_7.0.33-150_amd64.deb
sha:95f05ec963c5e405920f4410367eb90ae32e8e84
-
alt-php70-pgsql_7.0.33-150_amd64.deb
sha:4da53b7e32d4266e2eacfc406f19f061529dd621
-
alt-php70-php-fpm_7.0.33-150_amd64.deb
sha:6544347aa4dfc4c50f968d893204130f241b9200
-
alt-php70-process_7.0.33-150_amd64.deb
sha:a27ac6b1caf70601bae067405846008f842dcfc3
-
alt-php70-pspell_7.0.33-150_amd64.deb
sha:9ae5c880c3e04f4025f2a835539c8db061788de8
-
alt-php70-recode_7.0.33-150_amd64.deb
sha:1800f0e83e7b12db4a7903d08f726c12b58dc468
-
alt-php70-snmp_7.0.33-150_amd64.deb
sha:aa53f838b12731c7c54407138997182bf0888c8a
-
alt-php70-soap_7.0.33-150_amd64.deb
sha:d70f9ab878daf14e6a4ef5ea48dea1843d18f35a
-
alt-php70-tidy_7.0.33-150_amd64.deb
sha:556cb5303f716b04752458074f8b3396c6a0db30
-
alt-php70-xml_7.0.33-150_amd64.deb
sha:fb8cfbcfeb42594dea7fc303a7535d5437b021eb
-
alt-php70-xmlrpc_7.0.33-150_amd64.deb
sha:3323b6bd3c27535b2fe6716931288145bb604574
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.