Release date:
2026-10-09 11:35:22 UTC
Description:
* SECURITY UPDATE: packet over-reads in the mysqlnd wire-protocol parser
- debian/patches/php-7.1-CVE-2025-1218.patch: the greeting, auth
response, OK, EOF, result-set header, result-set field, row, prepare
and backported caching_sha2 readers decoded fields out of a server
packet before checking that the packet still held enough bytes for
them, so a malicious or compromised MySQL server could make the client
read past the end of the packet buffer by sending a truncated packet.
The consequences range from a crash to heap bytes leaking into
user-visible result-set metadata (field catalog/db/table/name), and in
the auth-switch branches a length that underflows to SIZE_MAX and is
then handed to emalloc()/memcpy(). php_mysqlnd_net_field_length() and
its _ll variant now take the number of bytes left in the packet and
refuse encoded lengths whose payload is not fully present, returning
the new MYSQLND_INVALID_NET_FIELD_LENGTH sentinel without advancing the
read pointer; the BAIL_IF_NO_MORE_DATA macro, which only noticed an
over-read after it had already happened, is replaced by
BAIL_IF_NOT_ENOUGH_DATA_EX(n), which checks before the bytes are read;
the unterminated auth-plugin-name branches use memchr() instead of
trusting a NUL terminator; and mysqlnd_ps_codec.c gains
ps_fetch_is_length_too_short() so the TIME, DATE and DATETIME
prepared-statement readers stop decoding fixed offsets out of a shorter
declared length. This is a backport of upstream
114dbb74368e6a6cd6e48ddb4a76dbe8728b84e2. Upstream
d37a20c4a24a70dbbcfd8724cd2ad5f1b005bd2a is carried as a prerequisite:
the fix deletes the greeting buffer's NUL terminator, which would turn
this branch's unbounded estrdup() of the auth plugin name into a stack
over-read, so that commit's bounded form is backported with it. Two of
the hunks are hardening rather than memory-safety fixes:
php_mysqlnd_prepare_read() cannot violate the bounds it now checks
behind the PREPARE_RESPONSE_SIZE gate that already guards it, and the
php_mysqlnd_sha256_pk_request_response_read() hunk is a strictness
change. The mysqlnd_ps.c hunk is a memory-leak fix: it releases the
connection reference and the execute command buffer on the failure path
in mysqlnd_stmt_prepare_read_eof() that the new checks make reachable,
before the memset() that resets the statement.
Upstream's 38 regression tests are NOT carried: they drive the
dynamic-port fake server upstream added in the same commit, while the
harness this package ships in ext/standard/tests/mysqli/ binds a fixed
port, and nothing in this package runs the suite anyway. They were run
locally instead, on a tree built from this repository's own patch
series, first patched and then with only the C hunks of this patch
reversed out and rebuilt: 38 of 38 pass patched, 0 fail; 9 of 38 pass
unpatched, 29 fail.
- Also fixes a pre-existing use-after-free on the row-reader failure path.
The CVE-2024-8929 backport added error loops in the binary- and
text-protocol row readers that zval_ptr_dtor() every field decoded so far
and return FAIL without clearing the zvals, so the result set frees the
same zvals again when it is torn down. The loops were already reachable
before this change; the new too-short TIME/DATE/DATETIME check adds a
second way in. All 3 sites now clear the zval after freeing it.
Confirmed under AddressSanitizer with the Zend allocator disabled:
heap-use-after-free in mysqlnd_result_buffered_zval free_result before,
clean after, on both the three new short-length tests and the nine
CVE-2024-8929 stmt-row tests. Upstream still carries the same loops
unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected.
- The mysqlnd_ps.c hunk additionally releases the result's own connection
reference on the prepare-EOF path. Before PHP 7.4 (upstream
f365d0e00ed93b1c33e984ff3b4cc8677cbca193) free_result_contents() did not
drop it, so that path leaked one reference. The sibling site in
mysqlnd_stmt store_result() leaks the same reference but is not made
reachable by this change and is left for a separate one.
- CVE-2025-1218
Updated packages:
-
alt-php71_7.1.33-115_amd64.deb
sha:302eb4fede1a937fb3baaded33a7c9996f669d9b
-
alt-php71-bcmath_7.1.33-115_amd64.deb
sha:9bc2a456674a37f7e0674b63b6bbdb1714bdfdf6
-
alt-php71-cli_7.1.33-115_amd64.deb
sha:cc5e2d40a3857c57e7735f8d1b5263345597fb36
-
alt-php71-common_7.1.33-115_amd64.deb
sha:1a4d156de7e860b128dbb4919f9468001be139dd
-
alt-php71-dba_7.1.33-115_amd64.deb
sha:3f5d112c1069b86083c59c7bec89ca76da1eb3f1
-
alt-php71-dev_7.1.33-115_amd64.deb
sha:cc7a465d2dcc2938f137efc908ca7a31e88dc1f6
-
alt-php71-enchant_7.1.33-115_amd64.deb
sha:3135086ab6a59f08e4ad2376946dfd493207d325
-
alt-php71-firebird_7.1.33-115_amd64.deb
sha:54b92bd93bc7abf66b69537cfa60cd99b21b04fb
-
alt-php71-gd_7.1.33-115_amd64.deb
sha:14951ca96ba67651537337aa875f38ccb2865fa4
-
alt-php71-imap_7.1.33-115_amd64.deb
sha:bb9d5ab4d8ad0540f143ba510bf9a6fdf34a2fde
-
alt-php71-intl_7.1.33-115_amd64.deb
sha:ecf5109bf552fb4ed888960e247019241b393064
-
alt-php71-ldap_7.1.33-115_amd64.deb
sha:c86bcbbef4c69d7d758de6b55b7645484787d0cb
-
alt-php71-mbstring_7.1.33-115_amd64.deb
sha:ed766486b561415e222026578a475aa81e1d04b1
-
alt-php71-mcrypt_7.1.33-115_amd64.deb
sha:dfe2694ff934ef752ad8d71c0dc1602e96a0c636
-
alt-php71-mysqlnd_7.1.33-115_amd64.deb
sha:70deedd8cf9c61e337782b5bedf848c3e8c81698
-
alt-php71-odbc_7.1.33-115_amd64.deb
sha:5ee387f3392126eeaf24338d4d20ae0fc92d451f
-
alt-php71-opcache_7.1.33-115_amd64.deb
sha:2523b04f98c60189dd5ae485721a291458fd18c4
-
alt-php71-pdo_7.1.33-115_amd64.deb
sha:cc7bdfbe004a6b1bac0a60160e1fd79ec27f9a1d
-
alt-php71-pgsql_7.1.33-115_amd64.deb
sha:6394b746952f9503da0b92a7952c57d74bd66738
-
alt-php71-php-fpm_7.1.33-115_amd64.deb
sha:455847c7c1ab59cdece1f677d5178a16a7372cdc
-
alt-php71-process_7.1.33-115_amd64.deb
sha:29f3f9c288ccfda613b05eedc6ad7bb2aad0ad4a
-
alt-php71-pspell_7.1.33-115_amd64.deb
sha:4e02e6b3df4c40f0363d31abbe442abc1bb8c82d
-
alt-php71-recode_7.1.33-115_amd64.deb
sha:5b1cad9c7b0d55e378ec5bfa3bb09015b81e8a5f
-
alt-php71-snmp_7.1.33-115_amd64.deb
sha:37925f12863a551ea614509f25120683d092580c
-
alt-php71-soap_7.1.33-115_amd64.deb
sha:f35b610506a7c9e3115968e6af937de7236fc7f3
-
alt-php71-tidy_7.1.33-115_amd64.deb
sha:60a135e788c326ce320fd66c4e560e25af2a6753
-
alt-php71-xml_7.1.33-115_amd64.deb
sha:e358a742cc494ceed1d8b0ecd2d70349676f0bd7
-
alt-php71-xmlrpc_7.1.33-115_amd64.deb
sha:03ca255748756bf946f855b5dcb2b94f1b88d177
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.