[CLSA-2026:1791380726] Fix CVE(s): CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-07 13:45:37 UTC
Description:
* SECURITY UPDATE: out-of-bounds reads in the mysqlnd wire-protocol parser when a malicious or compromised MySQL server sends a truncated packet - debian/patches/php-5.3-CVE-2025-1218.patch: re-implementation, against the PHP 5.3 mysqlnd sources, of upstream commit 114dbb74368e6a6cd6e48ddb4a76dbe8728b84e2 (GHSA-r6x9-5r99-36j7, released in php-8.2.34 / php-8.3.34). The upstream diff does not apply to 5.3 in any form, so every bound was re-derived from 5.3's own bookkeeping. BAIL_IF_NO_MORE_DATA only noticed an over-read after it had happened; it is replaced by BAIL_PREMATURE_END / BAIL_IF_NOT_ENOUGH_DATA_EX(n), which refuse the read up front. php_mysqlnd_net_field_length() and php_mysqlnd_net_field_length_ll() are given the number of bytes still left in the packet and report an unreadable length encoding instead of reading it; all ten call sites in mysqlnd_wireprotocol.c and all five in mysqlnd_ps_codec.c were converted. Memory-safety fixes: the greeting's server version string, which was read with estrdup() off a 2048-byte stack buffer with no terminator guarantee at all on this branch, is now bounded with memchr()+estrndup(); the greeting's 31-byte fixed block and the second half of its scramble are bounded; the OK and result-set header packets' affected_rows, last_insert_id, server_status and warning_count; the EOF packet's 4 trailing bytes; the in-row EOF marker, which accepted a 2-byte row packet as a 5-byte EOF; the result-set field metadata lengths, which were only rejected on MYSQLND_NULL_LENGTH and so leaked heap bytes into user-visible column metadata; the text-protocol row field lengths; and ps_fetch_time()/ps_fetch_date()/ ps_fetch_datetime(), which read fixed offsets regardless of the length the server declared for the field. HARDENING ONLY, not memory safety: the two new checks in php_mysqlnd_prepare_read() provably cannot fire behind the existing PREPARE_RESPONSE_SIZE gate. The mysqlnd_ps.c change is a memory LEAK fix on the prepare-EOF failure path, which the new checks make reachable, not an over-read. Large parts of the upstream commit have no counterpart on this branch and are deliberately absent: php_mysqlnd_auth_response_read(), php_mysqlnd_sha256_pk_request_response_read() and php_mysqlnd_cached_sha2_result_read() do not exist at 5.3, php_mysqlnd_chg_user_read() has no 0xFE auth-switch branch, and the greeting reader has no MARIADB_RPL_VERSION_HACK, no auth_protocol and no pluggable-auth scramble. The 38 upstream .phpt tests are not carried: the fake_server.inc they drive needs PHP 8.0 syntax to run, and most of them exercise packet types that do not exist here. The C fix ships without tests. - The same hunk also corrects that path's result free from mnd_efree() to upstream's php-7.0 form, mnd_pefree(stmt->result, stmt->result->persistent), since mysqlnd_result_init() allocates the result with mnd_pecalloc(..., persistent) and a persistent connection therefore gave the Zend allocator a malloc()ed block; before the change a hostile prepare over p:127.0.0.1 aborts with "zend_mm_heap corrupted" on a build with the Zend MM heap checks compiled in, after it the same run completes - Also fixes a pre-existing use-after-free on the row-reader failure path. The CVE-2024-8929 backport added error loops in the binary- and text-protocol row readers that zval_ptr_dtor() every field decoded so far and return FAIL without clearing the zvals, so the result set frees the same zvals again when it is torn down. The loops were already reachable before this change; the new too-short TIME/DATE/DATETIME check adds a second way in. All 2 sites now clear the zval after freeing it. Confirmed under AddressSanitizer with the Zend allocator disabled: heap-use-after-free in mysqlnd_result_buffered_zval free_result before, clean after, on both the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected. - CVE-2025-1218 * mysqlnd: initialise every pre-allocated row field before decoding - debian/patches/php-5.3.29-mysqlnd-rowp-init-fields.patch: the binary- and text-protocol row readers pre-allocate a zval per column with MAKE_STD_ZVAL(), which sets no type, and only type it when the decode loop reaches that column. The CVE-2024-8929 error paths abandon a row part-way, so every column past the failure point stays allocated but never typed, and the result set still frees the whole row at teardown - _zval_ptr_dtor() then branches on an uninitialised Z_TYPE. Each column is now ZVAL_NULL()ed at allocation. Confirmed with valgrind under USE_ZEND_ALLOC=0: the CVE-2024-8929 and CVE-2025-1218 stmt-row tests go from 1 uninitialised-value error to 0. PHP 5 only - from PHP 7 the row is a caller-owned array that mysqlnd_store_result() memset()s to zero. Kept separate from the CVE patch because the defect predates it and is reachable without it
CVEs fixed:
Updated packages:
  • alt-php53_5.3.29-219_amd64.deb
    sha:d1036012cb8ed78284af52cf6d8a632d708dcc03
  • alt-php53-bcmath_5.3.29-219_amd64.deb
    sha:80240aecc7a9a64e703be29234a7ec37108addd2
  • alt-php53-cli_5.3.29-219_amd64.deb
    sha:a2c50ad985b4074f8a223ff0152006c40904a700
  • alt-php53-common_5.3.29-219_amd64.deb
    sha:75d59a208ce79bc666e30d80d57c6143594b4449
  • alt-php53-dba_5.3.29-219_amd64.deb
    sha:a4084dc5142a5e8a3933c536e618717290fd6c2e
  • alt-php53-dbx_5.3.29-219_amd64.deb
    sha:eb4c8d8b768190b3b0f16af3aa55213dc1629f12
  • alt-php53-dev_5.3.29-219_amd64.deb
    sha:2b63d38fcd218a546911238a872cea422d589772
  • alt-php53-enchant_5.3.29-219_amd64.deb
    sha:ec8920271b3ddeaf9639b365242c1a9bcaaf90e3
  • alt-php53-firebird_5.3.29-219_amd64.deb
    sha:13133860afb112e1339d1f61b023b2c7dda93c8a
  • alt-php53-gd_5.3.29-219_amd64.deb
    sha:1c1f852e381c1ecf0eb86c4e9c6346d5f1673511
  • alt-php53-imap_5.3.29-219_amd64.deb
    sha:4e81fbcd1c65769bd966427fe29d74363dc62339
  • alt-php53-intl_5.3.29-219_amd64.deb
    sha:de4045c338a70fbdec1d55876cc7e6ed196fa857
  • alt-php53-ldap_5.3.29-219_amd64.deb
    sha:81cb5a2cc197e49e3e84764d5989b9995a7a80ae
  • alt-php53-mbstring_5.3.29-219_amd64.deb
    sha:48655ec7c3d3022d478e457502d2e60afb699abb
  • alt-php53-mcrypt_5.3.29-219_amd64.deb
    sha:d2d45b4b1f50924b566935cdfd78062bf8e0fd54
  • alt-php53-mssql_5.3.29-219_amd64.deb
    sha:6cb3e3081d4b3dcbf1c6919c242f6a1b01670906
  • alt-php53-mysqlnd_5.3.29-219_amd64.deb
    sha:900fc662c4fb3d066a83c3433c81792f3f30ca5f
  • alt-php53-odbc_5.3.29-219_amd64.deb
    sha:bba16a7f4e9f60fd4e246af7f07896d3e04f24f0
  • alt-php53-pdo_5.3.29-219_amd64.deb
    sha:655f6971de6eee2bf7690b9cdcae395f5b519bd9
  • alt-php53-pgsql_5.3.29-219_amd64.deb
    sha:ebf7b4bf6e5b98e91a513c55b73b3ddc00378fc2
  • alt-php53-php-fpm_5.3.29-219_amd64.deb
    sha:1052cde79a8e698fbdf2c42ebb413cb41d85ded0
  • alt-php53-process_5.3.29-219_amd64.deb
    sha:29137d270114c75caec3b058f0610b8d48140e3f
  • alt-php53-pspell_5.3.29-219_amd64.deb
    sha:f9294995b25194488ae0e958cff63c2ea26e9d0e
  • alt-php53-recode_5.3.29-219_amd64.deb
    sha:54aaba9c0836dba3e89b0d7cf2caed1acd5f70b4
  • alt-php53-snmp_5.3.29-219_amd64.deb
    sha:63196cae7a1f64125c58d0f5047246ded6c83ff0
  • alt-php53-soap_5.3.29-219_amd64.deb
    sha:286966d71a047fb941110450a299f0908d0ff31a
  • alt-php53-sybase_5.3.29-219_amd64.deb
    sha:7e933d75608b38b8bf51f089603f50d18825fc7c
  • alt-php53-tidy_5.3.29-219_amd64.deb
    sha:2ed2f67bce28ed222ba8e54dbc50d82a68064eb3
  • alt-php53-xml_5.3.29-219_amd64.deb
    sha:a3cff777dc9f5805fdfb4d3cd4252b53f103ebb2
  • alt-php53-xmlrpc_5.3.29-219_amd64.deb
    sha:a1d2c8b046c4d94e00c7fbfd4128b569e2ff55b2
  • alt-php53_5.3.29-219_arm64.deb
    sha:6d6699ff3cbd3e457934744f6ea4f9e92f94396f
  • alt-php53-bcmath_5.3.29-219_arm64.deb
    sha:6dd432d342b420dee0f3c0eb5cc887ca9cde6773
  • alt-php53-cli_5.3.29-219_arm64.deb
    sha:ee2d988f5fac8f8af340082bd0dfcfa6656d1752
  • alt-php53-common_5.3.29-219_arm64.deb
    sha:c364b81ba27becdd12d50d7fbeefc504eadd32b1
  • alt-php53-dba_5.3.29-219_arm64.deb
    sha:4aebaa0727747831764ac1bbbb379f4ac36e3e41
  • alt-php53-dbx_5.3.29-219_arm64.deb
    sha:3358922627c3eb049d4d423c9e30196d66f4173b
  • alt-php53-dev_5.3.29-219_arm64.deb
    sha:e52781cfe9c3617f52e690d14ee6cd53e69dcd46
  • alt-php53-enchant_5.3.29-219_arm64.deb
    sha:78c1a3b7bd9f9f740ee981463c2a171538fa2da6
  • alt-php53-firebird_5.3.29-219_arm64.deb
    sha:a00495d62862a6fa2363339247826c688c015c6f
  • alt-php53-gd_5.3.29-219_arm64.deb
    sha:34b60ef34506f87c6e79092e76b6743f954ced5c
  • alt-php53-imap_5.3.29-219_arm64.deb
    sha:1d8e3fb434d94439a50ff9e8aaa9363084c81925
  • alt-php53-intl_5.3.29-219_arm64.deb
    sha:e59783f2972aa912adc896ce2710ba186265e9af
  • alt-php53-ldap_5.3.29-219_arm64.deb
    sha:b8e6c0e2a84603dcf052bef4d415917595a40e5d
  • alt-php53-mbstring_5.3.29-219_arm64.deb
    sha:68f9c1e6471f345cf8af26a07586a60dfb3b02c1
  • alt-php53-mcrypt_5.3.29-219_arm64.deb
    sha:2f2935240e2e62609fc43d74d4a9df5eb22f2db8
  • alt-php53-mssql_5.3.29-219_arm64.deb
    sha:968b058c16ed12236c6adf2c24a4769f712f9c64
  • alt-php53-mysqlnd_5.3.29-219_arm64.deb
    sha:0dd94d6f1f2b07ae400d176018c4ea679fb96738
  • alt-php53-odbc_5.3.29-219_arm64.deb
    sha:1d104a9fb9c5e01b76fab33f32554831acc2bad7
  • alt-php53-pdo_5.3.29-219_arm64.deb
    sha:5f2db9864fefd7be01940024b1e5f2e55667c3f7
  • alt-php53-pgsql_5.3.29-219_arm64.deb
    sha:ff230e9f0e03b7131bde86eef723772d5b218627
  • alt-php53-php-fpm_5.3.29-219_arm64.deb
    sha:6ea3f5825ab79980fec9ca188e4923acf383af6c
  • alt-php53-process_5.3.29-219_arm64.deb
    sha:755f55ce5a0a29c1eecb8f080ae2aaa46111d967
  • alt-php53-pspell_5.3.29-219_arm64.deb
    sha:4b2f1255e8b605c6369d353f80422530af4ce324
  • alt-php53-recode_5.3.29-219_arm64.deb
    sha:1c5747ff307c3517512b32b8e7452835557b3953
  • alt-php53-snmp_5.3.29-219_arm64.deb
    sha:59c47f0a8016e40c8b6985592a7c604cab122f23
  • alt-php53-soap_5.3.29-219_arm64.deb
    sha:a39ccbc52f3817c7963d5b22a532694f17f6c700
  • alt-php53-sybase_5.3.29-219_arm64.deb
    sha:bc6a389d22882617d6e09902d26403731c790a56
  • alt-php53-tidy_5.3.29-219_arm64.deb
    sha:71ca832a21b3bfb4f0654cf4cf69c6506b7a1c90
  • alt-php53-xml_5.3.29-219_arm64.deb
    sha:82ed446b58cfbdcca71422e6ca53d72afd018bb6
  • alt-php53-xmlrpc_5.3.29-219_arm64.deb
    sha:c56917fe9e54fbdf3b52c251cc20248cabf4046f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.