[CLSA-2026:1791461015] Fix CVE(s): CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-09 10:45:20 UTC
Description:
* SECURITY UPDATE: mysqlnd read past the end of a server packet - debian/patches/php-7.2-CVE-2025-1218.patch: the mysqlnd wire-protocol packet readers in ext/mysqlnd/mysqlnd_wireprotocol.c decoded fields out of a server response before checking that the packet still held enough bytes for them, so a malicious or compromised MySQL server could make the client read past the end of the packet buffer by sending a truncated packet. The affected readers are the greeting, auth response, OK, EOF, result-set header, result-set field metadata, row and change user packets, plus the backported caching_sha2_password result reader. The BAIL_IF_NO_MORE_DATA macro, which only noticed an over-read after it had already happened, is replaced by BAIL_IF_NOT_ENOUGH_DATA_EX(n), which checks before the bytes are read; php_mysqlnd_net_field_length() and its _ll variant now take the number of bytes left in the packet and refuse a length whose payload is not fully present; and the unterminated auth-plugin-name branches use memchr() instead of trusting a NUL terminator. In ext/mysqlnd/mysqlnd_ps_codec.c the TIME, DATE and DATETIME readers stop decoding fixed offsets out of a shorter declared length. Two of the upstream hunks are hardening rather than memory safety: the bounds added to php_mysqlnd_prepare_read() and php_mysqlnd_sha256_pk_request_response_read() cannot be violated behind the checks that already guard those functions. The ext/mysqlnd/mysqlnd_ps.c hunk is a memory-leak fix, releasing the connection reference and the execute command buffer on the failure path that the new bounds check makes reachable. The patch also carries upstream commit d37a20c4a2 (php-8.2.27), which bounds the auth plugin name read in the greeting parser. The CVE-2025-1218 fix removes the buffer's safety NUL terminator, which is only safe once that earlier commit is in; without it the auth_protocol read would become an unbounded read off a 2048-byte stack buffer. None of upstream's 38 regression tests are carried: they drive the dynamic-port fake server upstream added in the same commit, while the harness this package ships in ext/standard/tests/mysqli/fake_server.inc binds a fixed port, and nothing in this package runs the suite anyway. They were run locally instead, on a tree built from this repository's own patch series, first patched and then with only the C hunks of this patch reversed out and rebuilt: 38 of 38 pass patched, 0 fail; 9 of 38 pass unpatched, 29 fail. - Also fixes a pre-existing use-after-free on the row-reader failure path. The CVE-2024-8929 backport added error loops in the binary- and text-protocol row readers that zval_ptr_dtor() every field decoded so far and return FAIL without clearing the zvals, so the result set frees the same zvals again when it is torn down. The loops were already reachable before this change; the new too-short TIME/DATE/DATETIME check adds a second way in. All 3 sites now clear the zval after freeing it. Confirmed under AddressSanitizer with the Zend allocator disabled: heap-use-after-free in mysqlnd_result_buffered_zval free_result before, clean after, on both the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected. - The mysqlnd_ps.c hunk additionally releases the result's own connection reference on the prepare-EOF path. Before PHP 7.4 (upstream f365d0e00ed93b1c33e984ff3b4cc8677cbca193) free_result_contents() did not drop it, so that path leaked one reference. The sibling site in mysqlnd_stmt store_result() leaks the same reference but is not made reachable by this change and is left for a separate one. - CVE-2025-1218
CVEs fixed:
Updated packages:
  • alt-php72_7.2.34-99_amd64.deb
    sha:22f2e29a0ec155894c7cefcc40a137e4fea2aa0a
  • alt-php72-bcmath_7.2.34-99_amd64.deb
    sha:8cb806b3efd5e7304ec4698921ae230efc613d2c
  • alt-php72-cli_7.2.34-99_amd64.deb
    sha:d9e1506d0d7af6f1879914c6cf0fbe77307c81c1
  • alt-php72-common_7.2.34-99_amd64.deb
    sha:39831d131dfb645e37da10ad46b8b20fe68426b9
  • alt-php72-dba_7.2.34-99_amd64.deb
    sha:0dd7fcf963139b03f26a5552326f5d305dcdb11b
  • alt-php72-dev_7.2.34-99_amd64.deb
    sha:7dd210b8b832f1dd89694b131e82f49502e3dc31
  • alt-php72-enchant_7.2.34-99_amd64.deb
    sha:4911d898399000866ab6a97e2e9b560dfc429642
  • alt-php72-firebird_7.2.34-99_amd64.deb
    sha:bd62e7e3d60c33ab82428708707271bc618e0864
  • alt-php72-gd_7.2.34-99_amd64.deb
    sha:a6b757193515e2d10db22e334e2630f83b015ade
  • alt-php72-imap_7.2.34-99_amd64.deb
    sha:3d45511b2f992590389d60cb00afa7139f64a789
  • alt-php72-intl_7.2.34-99_amd64.deb
    sha:5e676c9ea8c95ea11c0d5c4e460aa9854ed599e1
  • alt-php72-ldap_7.2.34-99_amd64.deb
    sha:afae7055ec366cc81a5ea77ae388cefa0d50251d
  • alt-php72-mbstring_7.2.34-99_amd64.deb
    sha:1e08f3ac71b538406b5136a37d3608f22a52229c
  • alt-php72-mysqlnd_7.2.34-99_amd64.deb
    sha:eb884c2c7561aae9f83dbff1482f6ffdc9be1ffa
  • alt-php72-odbc_7.2.34-99_amd64.deb
    sha:06152769cb42f6266f21cdaa52251087481d4401
  • alt-php72-opcache_7.2.34-99_amd64.deb
    sha:126d61a4088a605f572082ee2019732460d7c1c4
  • alt-php72-pdo_7.2.34-99_amd64.deb
    sha:63bd11ab1f491f3203b68589e2f39d3edfda106c
  • alt-php72-pgsql_7.2.34-99_amd64.deb
    sha:f182e85f929209ecf2dc14ed1f80a09179fe9c6b
  • alt-php72-php-fpm_7.2.34-99_amd64.deb
    sha:d250c26a5c055a2b80bd1dcc2fe41124ae68b0dd
  • alt-php72-process_7.2.34-99_amd64.deb
    sha:6a5d180b64138ca00e54460e36e7c3bd697588eb
  • alt-php72-pspell_7.2.34-99_amd64.deb
    sha:e2e6faec60b398393002bb00eaf39ff4fa476eac
  • alt-php72-recode_7.2.34-99_amd64.deb
    sha:77e0996004705e8442637185f9d4f7fa967495bc
  • alt-php72-snmp_7.2.34-99_amd64.deb
    sha:a119c4c6f856dc6f023b3a9bb39cefe03c5299d5
  • alt-php72-soap_7.2.34-99_amd64.deb
    sha:2d00f9c30fc4e0c91497f0b1deae377d906af755
  • alt-php72-sodium_7.2.34-99_amd64.deb
    sha:164cf41ebd770aca8904be20c1bb2093034812cd
  • alt-php72-tidy_7.2.34-99_amd64.deb
    sha:dd6c9980dc0eedd08c814d4f59f87ea979745c7e
  • alt-php72-xml_7.2.34-99_amd64.deb
    sha:bb5ec4d230cb9c8c9e676f15a13639eb5a7ca870
  • alt-php72-xmlrpc_7.2.34-99_amd64.deb
    sha:ff26fa34e426695c6eca3d7b2c132c136aa6009a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.