[CLSA-2026:1791444869] Fix CVE(s): CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-08 07:34:41 UTC
Description:
* SECURITY UPDATE: multiple out-of-bounds reads in the mysqlnd wire protocol parser - a malicious or compromised MySQL server could send a truncated packet and make the client read past the end of the packet buffer - debian/patches/php-8.0-CVE-2025-1218.patch: backport upstream commit 114dbb7436 in ext/mysqlnd/. Replaces the after-the-fact BAIL_IF_NO_MORE_DATA check with a BAIL_IF_NOT_ENOUGH_DATA_EX(n) family that refuses the read before it happens, adds a remaining_size parameter to php_mysqlnd_net_field_length()/_ll() so the 2/3/8-byte length prefixes are bounds-checked, and adds the missing checks in greet_read (server version, MariaDB RPL prefix, the fixed 31-byte block, the extended scramble and the auth plugin name), auth_response_read, ok_read, eof_read, rset_header_read, the READ_RSET_FIELD metadata macro, rowp_read and its text-protocol field lengths, chg_user_read and cached_sha2_result_read. In mysqlnd_ps_codec.c the new ps_fetch_is_length_too_short() makes the prepared-statement time/date/datetime fetchers reject a declared field length that is shorter than the fixed offsets they read. The mysqlnd_ps.c hunk is a memory-leak fix on the failure path the new checks make reachable, not an over-read fix; the prepare_read() and sha256_pk_request_response_read() hunks are hardening only - the former provably cannot fire behind the existing PREPARE_RESPONSE_SIZE gate and the latter is a strictness change. Carries all 38 upstream ghsa-r6x9-5r99-36j7 phpt tests plus ext/mysqli/tests/fake_server.inc, imported in full from upstream because the tests load it by that path. This branch already carries an older, 870-line fake_server.inc at ext/standard/tests/mysqli/ from the CVE-2024-8929 backport; that copy predates upstream's dynamic-port API, so the two coexist rather than one being rewritten to serve both. 14 of the 38 have the last one or two lines of their expected output adapted, because mysqli on 8.0 does not throw on a failed connect and does not populate the error message the 8.2 expectations print. - Also fixes a pre-existing use-after-free on the row-reader failure path. The CVE-2024-8929 backport added error loops in the binary- and text-protocol row readers that zval_ptr_dtor() every field decoded so far and return FAIL without clearing the zvals, so the result set frees the same zvals again when it is torn down. The loops were already reachable before this change; the new too-short TIME/DATE/DATETIME check adds a second way in. All 3 sites now clear the zval after freeing it. Confirmed under AddressSanitizer with the Zend allocator disabled: heap-use-after-free in mysqlnd_result_buffered_zval free_result before, clean after, on both the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected. - CVE-2025-1218 * debian/rules: build with -O2. The deb build never set an optimisation level (only -fno-strict-aliasing/-fPIC/... were appended to CFLAGS), so gcc compiled everything at its -O0 default. Unoptimised binaries failed the perftest on ubuntu26.04 (alt-php80 took 3.85x the time of the distro PHP 8.5.4 against a 2.55x limit). RPM (optflags, -O2) and Alpine (-Os) builds were already optimised and are unchanged.
CVEs fixed:
Updated packages:
  • alt-php80_8.0.30-69_amd64.deb
    sha:ccc6dd568b01bfe37b8fd28d74296e85b5dc0b64
  • alt-php80-bcmath_8.0.30-69_amd64.deb
    sha:8143f53fbba46b0e1d3ffd7c6453d7afc1b81856
  • alt-php80-cli_8.0.30-69_amd64.deb
    sha:534951968a98c26714b1c5100831a894c11ccfad
  • alt-php80-common_8.0.30-69_amd64.deb
    sha:a5343263bdbb53b3d2c93eeb005ded9589075884
  • alt-php80-dba_8.0.30-69_amd64.deb
    sha:f9730f3d5fd7d45ea86fc7c64f395095be253b7d
  • alt-php80-dev_8.0.30-69_amd64.deb
    sha:e760de652f342d94d020fc75e7ec0abc1efc91e0
  • alt-php80-enchant_8.0.30-69_amd64.deb
    sha:bbd790d1405cb77e3e49ad20d40e20afae554e10
  • alt-php80-firebird_8.0.30-69_amd64.deb
    sha:bd18ffc317a9d1b1381ad3baccc1b157bf8accb8
  • alt-php80-gd_8.0.30-69_amd64.deb
    sha:0f0febeb9ebe4397a07f85b8ab94c80fa8b096d9
  • alt-php80-imap_8.0.30-69_amd64.deb
    sha:5debaf840f6255291d84727cce4c9b91cc0a55ce
  • alt-php80-intl_8.0.30-69_amd64.deb
    sha:6abcf69e17bd1aad9714576f20ae67d7f4e4fece
  • alt-php80-ldap_8.0.30-69_amd64.deb
    sha:9e26f7bd8fa69132b3b41b9031f2d3d5c1353d58
  • alt-php80-mbstring_8.0.30-69_amd64.deb
    sha:ca9e78035f01a641e9f03d86b39089eae5165dd9
  • alt-php80-mysqlnd_8.0.30-69_amd64.deb
    sha:d97d553f9e29688283d27be653c76752c684e27d
  • alt-php80-odbc_8.0.30-69_amd64.deb
    sha:817a425618029014083bbbd1cc62cd10e7432cfb
  • alt-php80-opcache_8.0.30-69_amd64.deb
    sha:93d263f05ecdc71b988b8466429d1c3c20c58b00
  • alt-php80-pdo_8.0.30-69_amd64.deb
    sha:bfe2418aa5d4d318323ade343605bc3ba5c3a1ea
  • alt-php80-pgsql_8.0.30-69_amd64.deb
    sha:8529651b89a9d99e2ff76a247e797494bc033ca2
  • alt-php80-php-fpm_8.0.30-69_amd64.deb
    sha:75b8344cf3c330bf60cd1074a279544e59f48a03
  • alt-php80-process_8.0.30-69_amd64.deb
    sha:997f73933baa699a500b85490c0d1e5201a6b5e1
  • alt-php80-pspell_8.0.30-69_amd64.deb
    sha:d3778afd58f948e0a89e80cb3953fc902c0de4e1
  • alt-php80-snmp_8.0.30-69_amd64.deb
    sha:3a97b0cb688cf37380b5ab73d4f63a18a92e7ff6
  • alt-php80-soap_8.0.30-69_amd64.deb
    sha:da85500b15e4e2c6e07f69e656e9e6bc03816656
  • alt-php80-sodium_8.0.30-69_amd64.deb
    sha:385c160cc128b62f11c58360a5659c3cc8cd4ca9
  • alt-php80-tidy_8.0.30-69_amd64.deb
    sha:df5751393eddb594819e2a009b02b4c729fd795f
  • alt-php80-xml_8.0.30-69_amd64.deb
    sha:efffc4915fe7267028c62490023651df25308138
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.