Release date:
2026-10-09 12:54:01 UTC
Description:
* SECURITY UPDATE: out-of-bounds reads in the mysqlnd wire-protocol packet
readers
- debian/patches/php-7.3-CVE-2025-1218.patch: backport upstream commit
114dbb7436 in ext/mysqlnd/ - the packet readers decoded fields out of a
server response before checking that the packet still held enough bytes
for them, so a malicious or compromised MySQL server could make the
client read past the end of the packet buffer by sending a truncated
packet. BAIL_IF_NO_MORE_DATA, which only noticed an over-read after it
had happened, is replaced by BAIL_IF_NOT_ENOUGH_DATA_EX(n);
php_mysqlnd_net_field_length() and its _ll variant take a remaining_size
argument and refuse to decode a length whose payload is not present; the
auth-plugin-name reads in greet_read, auth_response_read and
chg_user_read use memchr() instead of trusting a NUL terminator; and
mysqlnd_ps_codec.c rejects a declared field length that is too short for
the fixed offsets the TIME/DATE/DATETIME readers decode.
The patch also carries the prerequisite upstream commit d37a20c4a2
(php-8.2.27), which bounds the auth_protocol read in greet_read: the
CVE fix removes the NUL terminator that greeting buffer relied on, so
without it that read would become a stack over-read.
The ext/mysqlnd/mysqlnd_ps.c hunk is a memory-leak fix on the failure
path the new bounds checks make reachable, and the prepare_read() and
sha256_pk_request_response_read() hunks are hardening, not memory-safety
fixes. Upstream's regression tests are not carried: they drive the
dynamic-port fake server upstream added in the same commit, while this
branch's ext/standard/tests/mysqli/fake_server.inc harness binds a
fixed port, and nothing in this package runs the suite. The 32 of them
that apply here were run locally instead, on a tree built from this
repository's own patch series, first patched and then with only the C
hunks of this patch reversed out and rebuilt: 32 of 32 pass patched, 0
fail; 8 of 32 pass unpatched, 24 fail.
- debian/patches/php-7.3-CVE-2025-1218-caching-sha2.patch: the same fix for
php_mysqlnd_cached_sha2_result_read(), which does not exist at
php-7.3.33 but is introduced by
debian/patches/php-7.3.33-caching-sha2-password.patch with the
unterminated-plugin-name over-read and the one-byte over-read on the
normal path. Kept separate because the Alpine build does not apply the
caching_sha2_password backport.
- Also fixes a pre-existing use-after-free on the row-reader failure path.
The CVE-2024-8929 backport added error loops in the binary- and
text-protocol row readers that zval_ptr_dtor() every field decoded so far
and return FAIL without clearing the zvals, so the result set frees the
same zvals again when it is torn down. The loops were already reachable
before this change; the new too-short TIME/DATE/DATETIME check adds a
second way in. All 3 sites now clear the zval after freeing it.
Confirmed under AddressSanitizer with the Zend allocator disabled:
heap-use-after-free in mysqlnd_result_buffered_zval free_result before,
clean after, on both the three new short-length tests and the nine
CVE-2024-8929 stmt-row tests. Upstream still carries the same loops
unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected.
- CVE-2025-1218
Updated packages:
-
alt-php73_7.3.33-83_amd64.deb
sha:0b9daaa88f79489d47e2b43e0350fc3e2ebdbe5c
-
alt-php73-bcmath_7.3.33-83_amd64.deb
sha:b8c350330d3fc56db2af956311647be938514951
-
alt-php73-cli_7.3.33-83_amd64.deb
sha:a56f843574327be855af38b63c788a9c1a0540aa
-
alt-php73-common_7.3.33-83_amd64.deb
sha:327ccf14331c29304bb180f3e74770863c3338fc
-
alt-php73-dba_7.3.33-83_amd64.deb
sha:bb0bf1ff6a0931454e93aef0f776361b043f5f30
-
alt-php73-dev_7.3.33-83_amd64.deb
sha:ef916f44d79c3551dc5c6890d92f7f87aac6f010
-
alt-php73-enchant_7.3.33-83_amd64.deb
sha:872075de6e108dffc580a90ac7e9f837ee193809
-
alt-php73-firebird_7.3.33-83_amd64.deb
sha:b3f3faccdb0a3b6658f6314104dc882a1e50a47e
-
alt-php73-gd_7.3.33-83_amd64.deb
sha:efc1f02dafe6a8a0cd84c84ee7a219a5775394bd
-
alt-php73-imap_7.3.33-83_amd64.deb
sha:686b6a9439df1eae82c511d30b4dd42c0c316d67
-
alt-php73-intl_7.3.33-83_amd64.deb
sha:f812cbaf78e8bea2bf1a6e45aec1b8cda05a9608
-
alt-php73-ldap_7.3.33-83_amd64.deb
sha:947cc32290006ca8b582ec71f2679aa75a30b40f
-
alt-php73-mbstring_7.3.33-83_amd64.deb
sha:c72a4bc310200376d4981e1d17e535183d15fdee
-
alt-php73-mysqlnd_7.3.33-83_amd64.deb
sha:68c8f18128644f546650d41303f46338c2c18783
-
alt-php73-odbc_7.3.33-83_amd64.deb
sha:72643e69bfa5b9662c670b785e2b0147d463a74c
-
alt-php73-opcache_7.3.33-83_amd64.deb
sha:4d1c2c688da363638edc2c6e8fe372c0c4545144
-
alt-php73-pdo_7.3.33-83_amd64.deb
sha:84b02dc0ce35d7aacd9b3e7c409a320e5a13e278
-
alt-php73-pgsql_7.3.33-83_amd64.deb
sha:011b105d3ac35782403f62bf8c6c901ecef95fd7
-
alt-php73-php-fpm_7.3.33-83_amd64.deb
sha:002a98f9ab89048abb7f14388656c371365b25ba
-
alt-php73-process_7.3.33-83_amd64.deb
sha:9db75cd3471e03a60e8637c5bb537fb8d8e90619
-
alt-php73-pspell_7.3.33-83_amd64.deb
sha:08c76bfd14283c7f4ad8c8778f4cabd84cd0ed45
-
alt-php73-recode_7.3.33-83_amd64.deb
sha:b5e692f6e69bc299c5afb60aa3f05a2d9acb24f4
-
alt-php73-snmp_7.3.33-83_amd64.deb
sha:97c1f0d100ae63ad53152051da3e71848e0c3e0a
-
alt-php73-soap_7.3.33-83_amd64.deb
sha:63b4eef4507ee09609b2a09b33644ea82816c661
-
alt-php73-sodium_7.3.33-83_amd64.deb
sha:0d1ae0bc49752a8e361927cbc1bce549b206f7a3
-
alt-php73-tidy_7.3.33-83_amd64.deb
sha:534ab71064bb675f5c5ae7b7bf3189ce71254a11
-
alt-php73-xml_7.3.33-83_amd64.deb
sha:9fd899e5be75ca66edc304d2d2c4d59f90c8ad16
-
alt-php73-xmlrpc_7.3.33-83_amd64.deb
sha:18e9deab6e79c7ef1eb84a75d674b2242b746094
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.