[CLSA-2026:1791447672] Fix CVE(s): CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-08 08:21:27 UTC
Description:
* SECURITY UPDATE: various packet overreads in the mysqlnd wire protocol - debian/patches/php-7.4-CVE-2025-1218.patch: backport upstream commit 114dbb7436 in ext/mysqlnd/ - the packet readers decoded fields out of a server response before checking that the packet still held enough bytes, so a malicious or compromised MySQL server could make the client read past the end of the packet buffer. BAIL_IF_NO_MORE_DATA, which only noticed an overread after it happened, is replaced by BAIL_IF_NOT_ENOUGH_DATA_EX(n); php_mysqlnd_net_field_length() and its _ll variant take a remaining_size argument and reject length encodings whose payload is not fully present; the auth-plugin-name branches use memchr() instead of trusting a NUL terminator; and the prepared-statement TIME/DATE/DATETIME readers stop decoding fixed offsets out of a shorter declared length. The mysqlnd_ps.c hunk is a leak fix on the newly reachable prepare-EOF failure path, and the prepare_read / sha256_pk_request_response_read hunks are hardening only, not memory-safety fixes. Also carries upstream's fake_server.inc additions and 38 regression tests, adapted for PHP 7.4 (see the patch header). - Also fixes a pre-existing use-after-free on the row-reader failure path. The CVE-2024-8929 backport added error loops in the binary- and text-protocol row readers that zval_ptr_dtor() every field decoded so far and return FAIL without clearing the zvals, so the result set frees the same zvals again when it is torn down. The loops were already reachable before this change; the new too-short TIME/DATE/DATETIME check adds a second way in. All 3 sites now clear the zval after freeing it. Confirmed under AddressSanitizer with the Zend allocator disabled: heap-use-after-free in mysqlnd_result_buffered_zval free_result before, clean after, on both the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected. - CVE-2025-1218
CVEs fixed:
Updated packages:
  • alt-php74_7.4.33-80_amd64.deb
    sha:360b28a0f6634ff8c3f5af220fcf72cf14b9d243
  • alt-php74-bcmath_7.4.33-80_amd64.deb
    sha:dac2f7eaf0d93cb1cc21a6d3b69897c8bbed7a27
  • alt-php74-cli_7.4.33-80_amd64.deb
    sha:c96ad8d9fc39913f4bcdf810d5d821d98c6bc940
  • alt-php74-common_7.4.33-80_amd64.deb
    sha:2d34e1eee68106e5ff216f82c36e565861bdb8eb
  • alt-php74-dba_7.4.33-80_amd64.deb
    sha:4b91966ae1d724b17337c4c0881ffcff68de2566
  • alt-php74-dev_7.4.33-80_amd64.deb
    sha:961f92cc75c4b607253334107e7952268ec4b655
  • alt-php74-enchant_7.4.33-80_amd64.deb
    sha:e1ad6f90167586b8d28ad924014aae0d14ff3bfe
  • alt-php74-firebird_7.4.33-80_amd64.deb
    sha:62b2fa1ec6e1479b30e2c2407ba55da957738990
  • alt-php74-gd_7.4.33-80_amd64.deb
    sha:70b3a929f7cf32d802c0ec5ea5292d9f855aa9e5
  • alt-php74-imap_7.4.33-80_amd64.deb
    sha:331ae3de49e9454fe9cd808ff1717d8e653d522b
  • alt-php74-intl_7.4.33-80_amd64.deb
    sha:2a3b52afd8dc3398870cd64a83ec1baca99a7956
  • alt-php74-ldap_7.4.33-80_amd64.deb
    sha:bc4b6c678ad83a0e179f948ecfe228036b571606
  • alt-php74-mbstring_7.4.33-80_amd64.deb
    sha:e99a689c40f11bb4f8b1be90376c8410542500f5
  • alt-php74-mysqlnd_7.4.33-80_amd64.deb
    sha:3806b1eb222069a54e5fb686050539b2ceb1a593
  • alt-php74-odbc_7.4.33-80_amd64.deb
    sha:d528c04e30de97a0b76069a7b80134dbdd428ebd
  • alt-php74-opcache_7.4.33-80_amd64.deb
    sha:cfaaa561433253275001d011803ce04ab57714b5
  • alt-php74-pdo_7.4.33-80_amd64.deb
    sha:9bf745a8500e0b8bcfce884dc8c4e74e8affb9e9
  • alt-php74-pgsql_7.4.33-80_amd64.deb
    sha:5c4b45e942fa499e53cc15d7229d5bea2496cab5
  • alt-php74-php-fpm_7.4.33-80_amd64.deb
    sha:3db6e3edbace420d7aafe0f8961936c94713def6
  • alt-php74-process_7.4.33-80_amd64.deb
    sha:f402bec66946dedbe720cc4bbf79577d61d07caf
  • alt-php74-pspell_7.4.33-80_amd64.deb
    sha:daaac4305d07242ed640a65b5bff0ff63b8c51e4
  • alt-php74-snmp_7.4.33-80_amd64.deb
    sha:11c922f36b49cfca0a594e7999a239287fa813f6
  • alt-php74-soap_7.4.33-80_amd64.deb
    sha:dd8db9f6ec79fcc20a2f3c8c742fbf7100344914
  • alt-php74-sodium_7.4.33-80_amd64.deb
    sha:57d5b234983559cef19f49a44fb0023f9a7dfbec
  • alt-php74-tidy_7.4.33-80_amd64.deb
    sha:a8d94bf31e26133d0628ff128904a13b3cc02f3e
  • alt-php74-xml_7.4.33-80_amd64.deb
    sha:14464811fd65533cb12f767ed2d01404b68dffa3
  • alt-php74-xmlrpc_7.4.33-80_amd64.deb
    sha:120421a427513b7bde737ad7e3fe6f4fecfe5626
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.