[CLSA-2026:1791545712] Fix CVE(s): CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-09 11:35:22 UTC
Description:
* SECURITY UPDATE: packet over-reads in the mysqlnd wire-protocol parser - debian/patches/php-7.1-CVE-2025-1218.patch: the greeting, auth response, OK, EOF, result-set header, result-set field, row, prepare and backported caching_sha2 readers decoded fields out of a server packet before checking that the packet still held enough bytes for them, so a malicious or compromised MySQL server could make the client read past the end of the packet buffer by sending a truncated packet. The consequences range from a crash to heap bytes leaking into user-visible result-set metadata (field catalog/db/table/name), and in the auth-switch branches a length that underflows to SIZE_MAX and is then handed to emalloc()/memcpy(). php_mysqlnd_net_field_length() and its _ll variant now take the number of bytes left in the packet and refuse encoded lengths whose payload is not fully present, returning the new MYSQLND_INVALID_NET_FIELD_LENGTH sentinel without advancing the read pointer; the BAIL_IF_NO_MORE_DATA macro, which only noticed an over-read after it had already happened, is replaced by BAIL_IF_NOT_ENOUGH_DATA_EX(n), which checks before the bytes are read; the unterminated auth-plugin-name branches use memchr() instead of trusting a NUL terminator; and mysqlnd_ps_codec.c gains ps_fetch_is_length_too_short() so the TIME, DATE and DATETIME prepared-statement readers stop decoding fixed offsets out of a shorter declared length. This is a backport of upstream 114dbb74368e6a6cd6e48ddb4a76dbe8728b84e2. Upstream d37a20c4a24a70dbbcfd8724cd2ad5f1b005bd2a is carried as a prerequisite: the fix deletes the greeting buffer's NUL terminator, which would turn this branch's unbounded estrdup() of the auth plugin name into a stack over-read, so that commit's bounded form is backported with it. Two of the hunks are hardening rather than memory-safety fixes: php_mysqlnd_prepare_read() cannot violate the bounds it now checks behind the PREPARE_RESPONSE_SIZE gate that already guards it, and the php_mysqlnd_sha256_pk_request_response_read() hunk is a strictness change. The mysqlnd_ps.c hunk is a memory-leak fix: it releases the connection reference and the execute command buffer on the failure path in mysqlnd_stmt_prepare_read_eof() that the new checks make reachable, before the memset() that resets the statement. Upstream's 38 regression tests are NOT carried: they drive the dynamic-port fake server upstream added in the same commit, while the harness this package ships in ext/standard/tests/mysqli/ binds a fixed port, and nothing in this package runs the suite anyway. They were run locally instead, on a tree built from this repository's own patch series, first patched and then with only the C hunks of this patch reversed out and rebuilt: 38 of 38 pass patched, 0 fail; 9 of 38 pass unpatched, 29 fail. - Also fixes a pre-existing use-after-free on the row-reader failure path. The CVE-2024-8929 backport added error loops in the binary- and text-protocol row readers that zval_ptr_dtor() every field decoded so far and return FAIL without clearing the zvals, so the result set frees the same zvals again when it is torn down. The loops were already reachable before this change; the new too-short TIME/DATE/DATETIME check adds a second way in. All 3 sites now clear the zval after freeing it. Confirmed under AddressSanitizer with the Zend allocator disabled: heap-use-after-free in mysqlnd_result_buffered_zval free_result before, clean after, on both the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected. - The mysqlnd_ps.c hunk additionally releases the result's own connection reference on the prepare-EOF path. Before PHP 7.4 (upstream f365d0e00ed93b1c33e984ff3b4cc8677cbca193) free_result_contents() did not drop it, so that path leaked one reference. The sibling site in mysqlnd_stmt store_result() leaks the same reference but is not made reachable by this change and is left for a separate one. - CVE-2025-1218
CVEs fixed:
Updated packages:
  • alt-php71_7.1.33-115_amd64.deb
    sha:302eb4fede1a937fb3baaded33a7c9996f669d9b
  • alt-php71-bcmath_7.1.33-115_amd64.deb
    sha:9bc2a456674a37f7e0674b63b6bbdb1714bdfdf6
  • alt-php71-cli_7.1.33-115_amd64.deb
    sha:cc5e2d40a3857c57e7735f8d1b5263345597fb36
  • alt-php71-common_7.1.33-115_amd64.deb
    sha:1a4d156de7e860b128dbb4919f9468001be139dd
  • alt-php71-dba_7.1.33-115_amd64.deb
    sha:3f5d112c1069b86083c59c7bec89ca76da1eb3f1
  • alt-php71-dev_7.1.33-115_amd64.deb
    sha:cc7a465d2dcc2938f137efc908ca7a31e88dc1f6
  • alt-php71-enchant_7.1.33-115_amd64.deb
    sha:3135086ab6a59f08e4ad2376946dfd493207d325
  • alt-php71-firebird_7.1.33-115_amd64.deb
    sha:54b92bd93bc7abf66b69537cfa60cd99b21b04fb
  • alt-php71-gd_7.1.33-115_amd64.deb
    sha:14951ca96ba67651537337aa875f38ccb2865fa4
  • alt-php71-imap_7.1.33-115_amd64.deb
    sha:bb9d5ab4d8ad0540f143ba510bf9a6fdf34a2fde
  • alt-php71-intl_7.1.33-115_amd64.deb
    sha:ecf5109bf552fb4ed888960e247019241b393064
  • alt-php71-ldap_7.1.33-115_amd64.deb
    sha:c86bcbbef4c69d7d758de6b55b7645484787d0cb
  • alt-php71-mbstring_7.1.33-115_amd64.deb
    sha:ed766486b561415e222026578a475aa81e1d04b1
  • alt-php71-mcrypt_7.1.33-115_amd64.deb
    sha:dfe2694ff934ef752ad8d71c0dc1602e96a0c636
  • alt-php71-mysqlnd_7.1.33-115_amd64.deb
    sha:70deedd8cf9c61e337782b5bedf848c3e8c81698
  • alt-php71-odbc_7.1.33-115_amd64.deb
    sha:5ee387f3392126eeaf24338d4d20ae0fc92d451f
  • alt-php71-opcache_7.1.33-115_amd64.deb
    sha:2523b04f98c60189dd5ae485721a291458fd18c4
  • alt-php71-pdo_7.1.33-115_amd64.deb
    sha:cc7bdfbe004a6b1bac0a60160e1fd79ec27f9a1d
  • alt-php71-pgsql_7.1.33-115_amd64.deb
    sha:6394b746952f9503da0b92a7952c57d74bd66738
  • alt-php71-php-fpm_7.1.33-115_amd64.deb
    sha:455847c7c1ab59cdece1f677d5178a16a7372cdc
  • alt-php71-process_7.1.33-115_amd64.deb
    sha:29f3f9c288ccfda613b05eedc6ad7bb2aad0ad4a
  • alt-php71-pspell_7.1.33-115_amd64.deb
    sha:4e02e6b3df4c40f0363d31abbe442abc1bb8c82d
  • alt-php71-recode_7.1.33-115_amd64.deb
    sha:5b1cad9c7b0d55e378ec5bfa3bb09015b81e8a5f
  • alt-php71-snmp_7.1.33-115_amd64.deb
    sha:37925f12863a551ea614509f25120683d092580c
  • alt-php71-soap_7.1.33-115_amd64.deb
    sha:f35b610506a7c9e3115968e6af937de7236fc7f3
  • alt-php71-tidy_7.1.33-115_amd64.deb
    sha:60a135e788c326ce320fd66c4e560e25af2a6753
  • alt-php71-xml_7.1.33-115_amd64.deb
    sha:e358a742cc494ceed1d8b0ecd2d70349676f0bd7
  • alt-php71-xmlrpc_7.1.33-115_amd64.deb
    sha:03ca255748756bf946f855b5dcb2b94f1b88d177
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.