Release date:
2026-10-07 13:45:37 UTC
Description:
* SECURITY UPDATE: out-of-bounds reads in the mysqlnd wire-protocol parser
when a malicious or compromised MySQL server sends a truncated packet
- debian/patches/php-5.3-CVE-2025-1218.patch: re-implementation, against
the PHP 5.3 mysqlnd sources, of upstream commit
114dbb74368e6a6cd6e48ddb4a76dbe8728b84e2 (GHSA-r6x9-5r99-36j7, released
in php-8.2.34 / php-8.3.34). The upstream diff does not apply to 5.3 in
any form, so every bound was re-derived from 5.3's own bookkeeping.
BAIL_IF_NO_MORE_DATA only noticed an over-read after it had happened; it
is replaced by BAIL_PREMATURE_END / BAIL_IF_NOT_ENOUGH_DATA_EX(n), which
refuse the read up front. php_mysqlnd_net_field_length() and
php_mysqlnd_net_field_length_ll() are given the number of bytes still
left in the packet and report an unreadable length encoding instead of
reading it; all ten call sites in mysqlnd_wireprotocol.c and all five in
mysqlnd_ps_codec.c were converted. Memory-safety fixes: the greeting's
server version string, which was read with estrdup() off a 2048-byte
stack buffer with no terminator guarantee at all on this branch, is now
bounded with memchr()+estrndup(); the greeting's 31-byte fixed block and
the second half of its scramble are bounded; the OK and result-set
header packets' affected_rows, last_insert_id, server_status and
warning_count; the EOF packet's 4 trailing bytes; the in-row EOF marker,
which accepted a 2-byte row packet as a 5-byte EOF; the result-set field
metadata lengths, which were only rejected on MYSQLND_NULL_LENGTH and so
leaked heap bytes into user-visible column metadata; the text-protocol
row field lengths; and ps_fetch_time()/ps_fetch_date()/
ps_fetch_datetime(), which read fixed offsets regardless of the length
the server declared for the field. HARDENING ONLY, not memory safety:
the two new checks in php_mysqlnd_prepare_read() provably cannot fire
behind the existing PREPARE_RESPONSE_SIZE gate. The mysqlnd_ps.c change
is a memory LEAK fix on the prepare-EOF failure path, which the new
checks make reachable, not an over-read.
Large parts of the upstream commit have no counterpart on this branch
and are deliberately absent: php_mysqlnd_auth_response_read(),
php_mysqlnd_sha256_pk_request_response_read() and
php_mysqlnd_cached_sha2_result_read() do not exist at 5.3,
php_mysqlnd_chg_user_read() has no 0xFE auth-switch branch, and the
greeting reader has no MARIADB_RPL_VERSION_HACK, no auth_protocol and no
pluggable-auth scramble. The 38 upstream .phpt tests are not carried:
the fake_server.inc they drive needs PHP 8.0 syntax to run, and most of
them exercise packet types that do not exist here. The C fix ships
without tests.
- The same hunk also corrects that path's result free from mnd_efree() to
upstream's php-7.0 form, mnd_pefree(stmt->result,
stmt->result->persistent), since mysqlnd_result_init() allocates the
result with mnd_pecalloc(..., persistent) and a persistent connection
therefore gave the Zend allocator a malloc()ed block; before the change
a hostile prepare over p:127.0.0.1 aborts with "zend_mm_heap corrupted"
on a build with the Zend MM heap checks compiled in, after it the same
run completes
- Also fixes a pre-existing use-after-free on the row-reader failure path.
The CVE-2024-8929 backport added error loops in the binary- and
text-protocol row readers that zval_ptr_dtor() every field decoded so far
and return FAIL without clearing the zvals, so the result set frees the
same zvals again when it is torn down. The loops were already reachable
before this change; the new too-short TIME/DATE/DATETIME check adds a
second way in. All 2 sites now clear the zval after freeing it.
Confirmed under AddressSanitizer with the Zend allocator disabled:
heap-use-after-free in mysqlnd_result_buffered_zval free_result before,
clean after, on both the three new short-length tests and the nine
CVE-2024-8929 stmt-row tests. Upstream still carries the same loops
unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected.
- CVE-2025-1218
* mysqlnd: initialise every pre-allocated row field before decoding
- debian/patches/php-5.3.29-mysqlnd-rowp-init-fields.patch: the binary- and
text-protocol row readers pre-allocate a zval per column with
MAKE_STD_ZVAL(), which sets no type, and only type it when the decode
loop reaches that column. The CVE-2024-8929 error paths abandon a row
part-way, so every column past the failure point stays allocated but
never typed, and the result set still frees the whole row at teardown -
_zval_ptr_dtor() then branches on an uninitialised Z_TYPE. Each column is
now ZVAL_NULL()ed at allocation. Confirmed with valgrind under
USE_ZEND_ALLOC=0: the CVE-2024-8929 and CVE-2025-1218 stmt-row tests go
from 1 uninitialised-value error to 0. PHP 5 only - from PHP 7 the row is
a caller-owned array that mysqlnd_store_result() memset()s to zero. Kept
separate from the CVE patch because the defect predates it and is
reachable without it
Updated packages:
-
alt-php53_5.3.29-219_amd64.deb
sha:d1036012cb8ed78284af52cf6d8a632d708dcc03
-
alt-php53-bcmath_5.3.29-219_amd64.deb
sha:80240aecc7a9a64e703be29234a7ec37108addd2
-
alt-php53-cli_5.3.29-219_amd64.deb
sha:a2c50ad985b4074f8a223ff0152006c40904a700
-
alt-php53-common_5.3.29-219_amd64.deb
sha:75d59a208ce79bc666e30d80d57c6143594b4449
-
alt-php53-dba_5.3.29-219_amd64.deb
sha:a4084dc5142a5e8a3933c536e618717290fd6c2e
-
alt-php53-dbx_5.3.29-219_amd64.deb
sha:eb4c8d8b768190b3b0f16af3aa55213dc1629f12
-
alt-php53-dev_5.3.29-219_amd64.deb
sha:2b63d38fcd218a546911238a872cea422d589772
-
alt-php53-enchant_5.3.29-219_amd64.deb
sha:ec8920271b3ddeaf9639b365242c1a9bcaaf90e3
-
alt-php53-firebird_5.3.29-219_amd64.deb
sha:13133860afb112e1339d1f61b023b2c7dda93c8a
-
alt-php53-gd_5.3.29-219_amd64.deb
sha:1c1f852e381c1ecf0eb86c4e9c6346d5f1673511
-
alt-php53-imap_5.3.29-219_amd64.deb
sha:4e81fbcd1c65769bd966427fe29d74363dc62339
-
alt-php53-intl_5.3.29-219_amd64.deb
sha:de4045c338a70fbdec1d55876cc7e6ed196fa857
-
alt-php53-ldap_5.3.29-219_amd64.deb
sha:81cb5a2cc197e49e3e84764d5989b9995a7a80ae
-
alt-php53-mbstring_5.3.29-219_amd64.deb
sha:48655ec7c3d3022d478e457502d2e60afb699abb
-
alt-php53-mcrypt_5.3.29-219_amd64.deb
sha:d2d45b4b1f50924b566935cdfd78062bf8e0fd54
-
alt-php53-mssql_5.3.29-219_amd64.deb
sha:6cb3e3081d4b3dcbf1c6919c242f6a1b01670906
-
alt-php53-mysqlnd_5.3.29-219_amd64.deb
sha:900fc662c4fb3d066a83c3433c81792f3f30ca5f
-
alt-php53-odbc_5.3.29-219_amd64.deb
sha:bba16a7f4e9f60fd4e246af7f07896d3e04f24f0
-
alt-php53-pdo_5.3.29-219_amd64.deb
sha:655f6971de6eee2bf7690b9cdcae395f5b519bd9
-
alt-php53-pgsql_5.3.29-219_amd64.deb
sha:ebf7b4bf6e5b98e91a513c55b73b3ddc00378fc2
-
alt-php53-php-fpm_5.3.29-219_amd64.deb
sha:1052cde79a8e698fbdf2c42ebb413cb41d85ded0
-
alt-php53-process_5.3.29-219_amd64.deb
sha:29137d270114c75caec3b058f0610b8d48140e3f
-
alt-php53-pspell_5.3.29-219_amd64.deb
sha:f9294995b25194488ae0e958cff63c2ea26e9d0e
-
alt-php53-recode_5.3.29-219_amd64.deb
sha:54aaba9c0836dba3e89b0d7cf2caed1acd5f70b4
-
alt-php53-snmp_5.3.29-219_amd64.deb
sha:63196cae7a1f64125c58d0f5047246ded6c83ff0
-
alt-php53-soap_5.3.29-219_amd64.deb
sha:286966d71a047fb941110450a299f0908d0ff31a
-
alt-php53-sybase_5.3.29-219_amd64.deb
sha:7e933d75608b38b8bf51f089603f50d18825fc7c
-
alt-php53-tidy_5.3.29-219_amd64.deb
sha:2ed2f67bce28ed222ba8e54dbc50d82a68064eb3
-
alt-php53-xml_5.3.29-219_amd64.deb
sha:a3cff777dc9f5805fdfb4d3cd4252b53f103ebb2
-
alt-php53-xmlrpc_5.3.29-219_amd64.deb
sha:a1d2c8b046c4d94e00c7fbfd4128b569e2ff55b2
-
alt-php53_5.3.29-219_arm64.deb
sha:6d6699ff3cbd3e457934744f6ea4f9e92f94396f
-
alt-php53-bcmath_5.3.29-219_arm64.deb
sha:6dd432d342b420dee0f3c0eb5cc887ca9cde6773
-
alt-php53-cli_5.3.29-219_arm64.deb
sha:ee2d988f5fac8f8af340082bd0dfcfa6656d1752
-
alt-php53-common_5.3.29-219_arm64.deb
sha:c364b81ba27becdd12d50d7fbeefc504eadd32b1
-
alt-php53-dba_5.3.29-219_arm64.deb
sha:4aebaa0727747831764ac1bbbb379f4ac36e3e41
-
alt-php53-dbx_5.3.29-219_arm64.deb
sha:3358922627c3eb049d4d423c9e30196d66f4173b
-
alt-php53-dev_5.3.29-219_arm64.deb
sha:e52781cfe9c3617f52e690d14ee6cd53e69dcd46
-
alt-php53-enchant_5.3.29-219_arm64.deb
sha:78c1a3b7bd9f9f740ee981463c2a171538fa2da6
-
alt-php53-firebird_5.3.29-219_arm64.deb
sha:a00495d62862a6fa2363339247826c688c015c6f
-
alt-php53-gd_5.3.29-219_arm64.deb
sha:34b60ef34506f87c6e79092e76b6743f954ced5c
-
alt-php53-imap_5.3.29-219_arm64.deb
sha:1d8e3fb434d94439a50ff9e8aaa9363084c81925
-
alt-php53-intl_5.3.29-219_arm64.deb
sha:e59783f2972aa912adc896ce2710ba186265e9af
-
alt-php53-ldap_5.3.29-219_arm64.deb
sha:b8e6c0e2a84603dcf052bef4d415917595a40e5d
-
alt-php53-mbstring_5.3.29-219_arm64.deb
sha:68f9c1e6471f345cf8af26a07586a60dfb3b02c1
-
alt-php53-mcrypt_5.3.29-219_arm64.deb
sha:2f2935240e2e62609fc43d74d4a9df5eb22f2db8
-
alt-php53-mssql_5.3.29-219_arm64.deb
sha:968b058c16ed12236c6adf2c24a4769f712f9c64
-
alt-php53-mysqlnd_5.3.29-219_arm64.deb
sha:0dd94d6f1f2b07ae400d176018c4ea679fb96738
-
alt-php53-odbc_5.3.29-219_arm64.deb
sha:1d104a9fb9c5e01b76fab33f32554831acc2bad7
-
alt-php53-pdo_5.3.29-219_arm64.deb
sha:5f2db9864fefd7be01940024b1e5f2e55667c3f7
-
alt-php53-pgsql_5.3.29-219_arm64.deb
sha:ff230e9f0e03b7131bde86eef723772d5b218627
-
alt-php53-php-fpm_5.3.29-219_arm64.deb
sha:6ea3f5825ab79980fec9ca188e4923acf383af6c
-
alt-php53-process_5.3.29-219_arm64.deb
sha:755f55ce5a0a29c1eecb8f080ae2aaa46111d967
-
alt-php53-pspell_5.3.29-219_arm64.deb
sha:4b2f1255e8b605c6369d353f80422530af4ce324
-
alt-php53-recode_5.3.29-219_arm64.deb
sha:1c5747ff307c3517512b32b8e7452835557b3953
-
alt-php53-snmp_5.3.29-219_arm64.deb
sha:59c47f0a8016e40c8b6985592a7c604cab122f23
-
alt-php53-soap_5.3.29-219_arm64.deb
sha:a39ccbc52f3817c7963d5b22a532694f17f6c700
-
alt-php53-sybase_5.3.29-219_arm64.deb
sha:bc6a389d22882617d6e09902d26403731c790a56
-
alt-php53-tidy_5.3.29-219_arm64.deb
sha:71ca832a21b3bfb4f0654cf4cf69c6506b7a1c90
-
alt-php53-xml_5.3.29-219_arm64.deb
sha:82ed446b58cfbdcca71422e6ca53d72afd018bb6
-
alt-php53-xmlrpc_5.3.29-219_arm64.deb
sha:c56917fe9e54fbdf3b52c251cc20248cabf4046f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.