Release date:
2026-10-09 10:45:20 UTC
Description:
* SECURITY UPDATE: mysqlnd read past the end of a server packet
- debian/patches/php-7.2-CVE-2025-1218.patch: the mysqlnd wire-protocol
packet readers in ext/mysqlnd/mysqlnd_wireprotocol.c decoded fields out
of a server response before checking that the packet still held enough
bytes for them, so a malicious or compromised MySQL server could make
the client read past the end of the packet buffer by sending a
truncated packet. The affected readers are the greeting, auth response,
OK, EOF, result-set header, result-set field metadata, row and change
user packets, plus the backported caching_sha2_password result reader.
The BAIL_IF_NO_MORE_DATA macro, which only noticed an over-read after
it had already happened, is replaced by BAIL_IF_NOT_ENOUGH_DATA_EX(n),
which checks before the bytes are read;
php_mysqlnd_net_field_length() and its _ll variant now take the number
of bytes left in the packet and refuse a length whose payload is not
fully present; and the unterminated auth-plugin-name branches use
memchr() instead of trusting a NUL terminator. In
ext/mysqlnd/mysqlnd_ps_codec.c the TIME, DATE and DATETIME readers stop
decoding fixed offsets out of a shorter declared length.
Two of the upstream hunks are hardening rather than memory safety: the
bounds added to php_mysqlnd_prepare_read() and
php_mysqlnd_sha256_pk_request_response_read() cannot be violated behind
the checks that already guard those functions. The
ext/mysqlnd/mysqlnd_ps.c hunk is a memory-leak fix, releasing the
connection reference and the execute command buffer on the failure path
that the new bounds check makes reachable.
The patch also carries upstream commit d37a20c4a2 (php-8.2.27), which
bounds the auth plugin name read in the greeting parser. The
CVE-2025-1218 fix removes the buffer's safety NUL terminator, which is
only safe once that earlier commit is in; without it the auth_protocol
read would become an unbounded read off a 2048-byte stack buffer.
None of upstream's 38 regression tests are carried: they drive the
dynamic-port fake server upstream added in the same commit, while the
harness this package ships in ext/standard/tests/mysqli/fake_server.inc
binds a fixed port, and nothing in this package runs the suite anyway.
They were run locally instead, on a tree built from this repository's
own patch series, first patched and then with only the C hunks of this
patch reversed out and rebuilt: 38 of 38 pass patched, 0 fail; 9 of 38
pass unpatched, 29 fail.
- Also fixes a pre-existing use-after-free on the row-reader failure path.
The CVE-2024-8929 backport added error loops in the binary- and
text-protocol row readers that zval_ptr_dtor() every field decoded so far
and return FAIL without clearing the zvals, so the result set frees the
same zvals again when it is torn down. The loops were already reachable
before this change; the new too-short TIME/DATE/DATETIME check adds a
second way in. All 3 sites now clear the zval after freeing it.
Confirmed under AddressSanitizer with the Zend allocator disabled:
heap-use-after-free in mysqlnd_result_buffered_zval free_result before,
clean after, on both the three new short-length tests and the nine
CVE-2024-8929 stmt-row tests. Upstream still carries the same loops
unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected.
- The mysqlnd_ps.c hunk additionally releases the result's own connection
reference on the prepare-EOF path. Before PHP 7.4 (upstream
f365d0e00ed93b1c33e984ff3b4cc8677cbca193) free_result_contents() did not
drop it, so that path leaked one reference. The sibling site in
mysqlnd_stmt store_result() leaks the same reference but is not made
reachable by this change and is left for a separate one.
- CVE-2025-1218
Updated packages:
-
alt-php72_7.2.34-99_amd64.deb
sha:22f2e29a0ec155894c7cefcc40a137e4fea2aa0a
-
alt-php72-bcmath_7.2.34-99_amd64.deb
sha:8cb806b3efd5e7304ec4698921ae230efc613d2c
-
alt-php72-cli_7.2.34-99_amd64.deb
sha:d9e1506d0d7af6f1879914c6cf0fbe77307c81c1
-
alt-php72-common_7.2.34-99_amd64.deb
sha:39831d131dfb645e37da10ad46b8b20fe68426b9
-
alt-php72-dba_7.2.34-99_amd64.deb
sha:0dd7fcf963139b03f26a5552326f5d305dcdb11b
-
alt-php72-dev_7.2.34-99_amd64.deb
sha:7dd210b8b832f1dd89694b131e82f49502e3dc31
-
alt-php72-enchant_7.2.34-99_amd64.deb
sha:4911d898399000866ab6a97e2e9b560dfc429642
-
alt-php72-firebird_7.2.34-99_amd64.deb
sha:bd62e7e3d60c33ab82428708707271bc618e0864
-
alt-php72-gd_7.2.34-99_amd64.deb
sha:a6b757193515e2d10db22e334e2630f83b015ade
-
alt-php72-imap_7.2.34-99_amd64.deb
sha:3d45511b2f992590389d60cb00afa7139f64a789
-
alt-php72-intl_7.2.34-99_amd64.deb
sha:5e676c9ea8c95ea11c0d5c4e460aa9854ed599e1
-
alt-php72-ldap_7.2.34-99_amd64.deb
sha:afae7055ec366cc81a5ea77ae388cefa0d50251d
-
alt-php72-mbstring_7.2.34-99_amd64.deb
sha:1e08f3ac71b538406b5136a37d3608f22a52229c
-
alt-php72-mysqlnd_7.2.34-99_amd64.deb
sha:eb884c2c7561aae9f83dbff1482f6ffdc9be1ffa
-
alt-php72-odbc_7.2.34-99_amd64.deb
sha:06152769cb42f6266f21cdaa52251087481d4401
-
alt-php72-opcache_7.2.34-99_amd64.deb
sha:126d61a4088a605f572082ee2019732460d7c1c4
-
alt-php72-pdo_7.2.34-99_amd64.deb
sha:63bd11ab1f491f3203b68589e2f39d3edfda106c
-
alt-php72-pgsql_7.2.34-99_amd64.deb
sha:f182e85f929209ecf2dc14ed1f80a09179fe9c6b
-
alt-php72-php-fpm_7.2.34-99_amd64.deb
sha:d250c26a5c055a2b80bd1dcc2fe41124ae68b0dd
-
alt-php72-process_7.2.34-99_amd64.deb
sha:6a5d180b64138ca00e54460e36e7c3bd697588eb
-
alt-php72-pspell_7.2.34-99_amd64.deb
sha:e2e6faec60b398393002bb00eaf39ff4fa476eac
-
alt-php72-recode_7.2.34-99_amd64.deb
sha:77e0996004705e8442637185f9d4f7fa967495bc
-
alt-php72-snmp_7.2.34-99_amd64.deb
sha:a119c4c6f856dc6f023b3a9bb39cefe03c5299d5
-
alt-php72-soap_7.2.34-99_amd64.deb
sha:2d00f9c30fc4e0c91497f0b1deae377d906af755
-
alt-php72-sodium_7.2.34-99_amd64.deb
sha:164cf41ebd770aca8904be20c1bb2093034812cd
-
alt-php72-tidy_7.2.34-99_amd64.deb
sha:dd6c9980dc0eedd08c814d4f59f87ea979745c7e
-
alt-php72-xml_7.2.34-99_amd64.deb
sha:bb5ec4d230cb9c8c9e676f15a13639eb5a7ca870
-
alt-php72-xmlrpc_7.2.34-99_amd64.deb
sha:ff26fa34e426695c6eca3d7b2c132c136aa6009a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.