Release date:
2026-10-08 07:34:41 UTC
Description:
* SECURITY UPDATE: multiple out-of-bounds reads in the mysqlnd wire protocol
parser - a malicious or compromised MySQL server could send a truncated
packet and make the client read past the end of the packet buffer
- debian/patches/php-8.0-CVE-2025-1218.patch: backport upstream commit
114dbb7436 in ext/mysqlnd/. Replaces the after-the-fact
BAIL_IF_NO_MORE_DATA check with a BAIL_IF_NOT_ENOUGH_DATA_EX(n) family
that refuses the read before it happens, adds a remaining_size parameter
to php_mysqlnd_net_field_length()/_ll() so the 2/3/8-byte length prefixes
are bounds-checked, and adds the missing checks in greet_read (server
version, MariaDB RPL prefix, the fixed 31-byte block, the extended
scramble and the auth plugin name), auth_response_read, ok_read,
eof_read, rset_header_read, the READ_RSET_FIELD metadata macro,
rowp_read and its text-protocol field lengths, chg_user_read and
cached_sha2_result_read. In mysqlnd_ps_codec.c the new
ps_fetch_is_length_too_short() makes the prepared-statement
time/date/datetime fetchers reject a declared field length that is
shorter than the fixed offsets they read. The mysqlnd_ps.c hunk is a
memory-leak fix on the failure path the new checks make reachable, not
an over-read fix; the prepare_read() and
sha256_pk_request_response_read() hunks are hardening only - the former
provably cannot fire behind the existing PREPARE_RESPONSE_SIZE gate and
the latter is a strictness change. Carries all 38 upstream
ghsa-r6x9-5r99-36j7 phpt tests plus ext/mysqli/tests/fake_server.inc,
imported in full from upstream because the tests load it by that path.
This branch already carries an older, 870-line fake_server.inc at
ext/standard/tests/mysqli/ from the CVE-2024-8929 backport; that copy
predates upstream's dynamic-port API, so the two coexist rather than
one being rewritten to serve both. 14 of the
38 have the last one or two lines of their expected output adapted,
because mysqli on 8.0 does not throw on a failed connect and does not
populate the error message the 8.2 expectations print.
- Also fixes a pre-existing use-after-free on the row-reader failure path.
The CVE-2024-8929 backport added error loops in the binary- and
text-protocol row readers that zval_ptr_dtor() every field decoded so far
and return FAIL without clearing the zvals, so the result set frees the
same zvals again when it is torn down. The loops were already reachable
before this change; the new too-short TIME/DATE/DATETIME check adds a
second way in. All 3 sites now clear the zval after freeing it.
Confirmed under AddressSanitizer with the Zend allocator disabled:
heap-use-after-free in mysqlnd_result_buffered_zval free_result before,
clean after, on both the three new short-length tests and the nine
CVE-2024-8929 stmt-row tests. Upstream still carries the same loops
unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected.
- CVE-2025-1218
* debian/rules: build with -O2. The deb build never set an optimisation
level (only -fno-strict-aliasing/-fPIC/... were appended to CFLAGS), so
gcc compiled everything at its -O0 default. Unoptimised binaries failed
the perftest on ubuntu26.04 (alt-php80 took 3.85x the time of the distro
PHP 8.5.4 against a 2.55x limit). RPM (optflags, -O2) and Alpine (-Os)
builds were already optimised and are unchanged.
Updated packages:
-
alt-php80_8.0.30-69_amd64.deb
sha:ccc6dd568b01bfe37b8fd28d74296e85b5dc0b64
-
alt-php80-bcmath_8.0.30-69_amd64.deb
sha:8143f53fbba46b0e1d3ffd7c6453d7afc1b81856
-
alt-php80-cli_8.0.30-69_amd64.deb
sha:534951968a98c26714b1c5100831a894c11ccfad
-
alt-php80-common_8.0.30-69_amd64.deb
sha:a5343263bdbb53b3d2c93eeb005ded9589075884
-
alt-php80-dba_8.0.30-69_amd64.deb
sha:f9730f3d5fd7d45ea86fc7c64f395095be253b7d
-
alt-php80-dev_8.0.30-69_amd64.deb
sha:e760de652f342d94d020fc75e7ec0abc1efc91e0
-
alt-php80-enchant_8.0.30-69_amd64.deb
sha:bbd790d1405cb77e3e49ad20d40e20afae554e10
-
alt-php80-firebird_8.0.30-69_amd64.deb
sha:bd18ffc317a9d1b1381ad3baccc1b157bf8accb8
-
alt-php80-gd_8.0.30-69_amd64.deb
sha:0f0febeb9ebe4397a07f85b8ab94c80fa8b096d9
-
alt-php80-imap_8.0.30-69_amd64.deb
sha:5debaf840f6255291d84727cce4c9b91cc0a55ce
-
alt-php80-intl_8.0.30-69_amd64.deb
sha:6abcf69e17bd1aad9714576f20ae67d7f4e4fece
-
alt-php80-ldap_8.0.30-69_amd64.deb
sha:9e26f7bd8fa69132b3b41b9031f2d3d5c1353d58
-
alt-php80-mbstring_8.0.30-69_amd64.deb
sha:ca9e78035f01a641e9f03d86b39089eae5165dd9
-
alt-php80-mysqlnd_8.0.30-69_amd64.deb
sha:d97d553f9e29688283d27be653c76752c684e27d
-
alt-php80-odbc_8.0.30-69_amd64.deb
sha:817a425618029014083bbbd1cc62cd10e7432cfb
-
alt-php80-opcache_8.0.30-69_amd64.deb
sha:93d263f05ecdc71b988b8466429d1c3c20c58b00
-
alt-php80-pdo_8.0.30-69_amd64.deb
sha:bfe2418aa5d4d318323ade343605bc3ba5c3a1ea
-
alt-php80-pgsql_8.0.30-69_amd64.deb
sha:8529651b89a9d99e2ff76a247e797494bc033ca2
-
alt-php80-php-fpm_8.0.30-69_amd64.deb
sha:75b8344cf3c330bf60cd1074a279544e59f48a03
-
alt-php80-process_8.0.30-69_amd64.deb
sha:997f73933baa699a500b85490c0d1e5201a6b5e1
-
alt-php80-pspell_8.0.30-69_amd64.deb
sha:d3778afd58f948e0a89e80cb3953fc902c0de4e1
-
alt-php80-snmp_8.0.30-69_amd64.deb
sha:3a97b0cb688cf37380b5ab73d4f63a18a92e7ff6
-
alt-php80-soap_8.0.30-69_amd64.deb
sha:da85500b15e4e2c6e07f69e656e9e6bc03816656
-
alt-php80-sodium_8.0.30-69_amd64.deb
sha:385c160cc128b62f11c58360a5659c3cc8cd4ca9
-
alt-php80-tidy_8.0.30-69_amd64.deb
sha:df5751393eddb594819e2a009b02b4c729fd795f
-
alt-php80-xml_8.0.30-69_amd64.deb
sha:efffc4915fe7267028c62490023651df25308138
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.