Release date:
2026-10-08 06:28:59 UTC
Description:
* SECURITY UPDATE: various packet over-reads in the mysqlnd wire protocol
- debian/patches/php-5.5-CVE-2025-1218.patch: backport upstream commit
114dbb74368e6a6cd6e48ddb4a76dbe8728b84e2 to ext/mysqlnd. The packet
readers decoded fields out of a server response before checking that
the packet still held the bytes for them, so a malicious or
compromised MySQL server could make the client read past the end of
the packet buffer with a truncated packet. BAIL_IF_NO_MORE_DATA,
which only noticed an over-read after it happened, is replaced by
BAIL_IF_NOT_ENOUGH_DATA_EX(n), which checks before the read;
php_mysqlnd_net_field_length() and its _ll variant now take the
number of bytes left and refuse to decode a length whose payload is
not fully present; the auth-plugin-name branches in
auth_response_read, chg_user_read and cached_sha2_result_read use
memchr() instead of trusting a NUL terminator (chg_user_read and
cached_sha2_result_read read into buffers nothing zero-terminates,
so strlen() there could run off the end); the greeting's server
version string is read the same way; and the TIME, DATE and DATETIME
readers in mysqlnd_ps_codec.c stop decoding fixed offsets out of a
shorter declared length.
The mysqlnd_ps.c hunk is a leak fix, not a memory-safety one: it
releases the connection reference and the execute command buffer
before mysqlnd_stmt_prepare_read_eof() memsets the statement, a path
that only becomes reachable now that a short EOF packet is rejected.
The prepare_read and sha256_pk_request_response_read changes are
hardening rather than memory safety - prepare_read's new byte counts
provably cannot fire behind the PREPARE_RESPONSE_SIZE gate that
precedes them, and the sha256 one is a strictness change.
Two parts of the upstream fix have no call site on this branch:
MARIADB_RPL_VERSION_HACK does not exist here, and upstream's
two-byte look-ahead in cached_sha2_result_read guards a
"packet->result" read that the caching_sha2_password backport on
this branch never added - the one-byte read it does have is guarded
instead. The ps_codec helper trio and the text-row packet_end guard
that upstream only gained in 8.1.34 were already brought in by our
CVE-2024-8929 backport, so this patch extends them.
As a prerequisite, the bounded form of the greeting's auth plugin
name from php-8.1.34 is carried as well (upstream
d37a20c4a24a70dbbcfd8724cd2ad5f1b005bd2a, never backported here):
without it, deleting the NUL-terminating hack as upstream does would
turn that estrdup() into an unbounded read off a 2048 byte stack
buffer.
Upstream's 38 phpt tests are not carried - they need the PHP 8
ext/mysqli/tests/fake_server.inc, and the RPM test suite runs in the
build-cgi tree, which is configured without mysqli/mysqlnd,
so every ext/mysqli test skips there.
- The same hunk also corrects that path's result free from mnd_efree() to
upstream's php-7.0 form, mnd_pefree(stmt->result,
stmt->result->persistent), since mysqlnd_result_init() allocates the
result with mnd_pecalloc(..., persistent) and a persistent connection
therefore gave the Zend allocator a malloc()ed block; before the change
a hostile prepare over p:127.0.0.1 aborts with "zend_mm_heap corrupted"
on a build with the Zend MM heap checks compiled in, after it the same
run completes
- Also fixes a pre-existing use-after-free on the row-reader failure path.
The CVE-2024-8929 backport added error loops in the binary- and
text-protocol row readers that zval_ptr_dtor() every field decoded so far
and return FAIL without clearing the zvals, so the result set frees the
same zvals again when it is torn down. The loops were already reachable
before this change; the new too-short TIME/DATE/DATETIME check adds a
second way in. All 2 sites now clear the zval after freeing it.
Confirmed under AddressSanitizer with the Zend allocator disabled:
heap-use-after-free in mysqlnd_result_buffered_zval free_result before,
clean after, on both the three new short-length tests and the nine
CVE-2024-8929 stmt-row tests. Upstream still carries the same loops
unguarded in php-8.2.34 through php-8.5.11; php-8.1 is not affected.
- CVE-2025-1218
* mysqlnd: initialise every pre-allocated row field before decoding
- debian/patches/php-5.5.38-mysqlnd-rowp-init-fields.patch: the binary- and
text-protocol row readers pre-allocate a zval per column with
MAKE_STD_ZVAL(), which sets no type, and only type it when the decode
loop reaches that column. The CVE-2024-8929 error paths abandon a row
part-way, so every column past the failure point stays allocated but
never typed, and the result set still frees the whole row at teardown -
_zval_ptr_dtor() then branches on an uninitialised Z_TYPE. Each column is
now ZVAL_NULL()ed at allocation. Confirmed with valgrind under
USE_ZEND_ALLOC=0: the CVE-2024-8929 and CVE-2025-1218 stmt-row tests go
from 1 uninitialised-value error to 0. PHP 5 only - from PHP 7 the row is
a caller-owned array that mysqlnd_store_result() memset()s to zero. Kept
separate from the CVE patch because the defect predates it and is
reachable without it
Updated packages:
-
alt-php55_5.5.38-184_amd64.deb
sha:5d07b5da336b7c20352265d376c75901ce0a0afd
-
alt-php55-bcmath_5.5.38-184_amd64.deb
sha:347aa4a6f174cf7daa9575e1a13bd5adae7a5397
-
alt-php55-cli_5.5.38-184_amd64.deb
sha:f6b69ede3525658fbcde54472e4dd420fdd658ce
-
alt-php55-common_5.5.38-184_amd64.deb
sha:8931b53e335cc57163fe00328a64f4430b2d98ad
-
alt-php55-dba_5.5.38-184_amd64.deb
sha:00184d5a93fd17e15e5a4b75c417a3ca663e792d
-
alt-php55-dbx_5.5.38-184_amd64.deb
sha:d986f0a0348a58fdf8a35a5bec9b539d1b6efd87
-
alt-php55-dev_5.5.38-184_amd64.deb
sha:067edd11e7501d3e4d97be215ce4561020af46e0
-
alt-php55-enchant_5.5.38-184_amd64.deb
sha:1edf2ffc5908c9339fe7b9739a4637627f383f09
-
alt-php55-firebird_5.5.38-184_amd64.deb
sha:5d27060b8c6707f756fb39612f165ce3a55f820d
-
alt-php55-gd_5.5.38-184_amd64.deb
sha:71f0b3b9d735afdd5bdab47e9e3e8137db72ab6f
-
alt-php55-imap_5.5.38-184_amd64.deb
sha:ecc2e5528f11a2d9b9a981283532278cd3ff5577
-
alt-php55-intl_5.5.38-184_amd64.deb
sha:1a14545ee68dc43e480942569e1c6185f18517af
-
alt-php55-ldap_5.5.38-184_amd64.deb
sha:2a619460e400737fd66141b25f8b59759ea5b18c
-
alt-php55-mbstring_5.5.38-184_amd64.deb
sha:63912acd9cd5a61774e47f770187bcfc7cbd86ff
-
alt-php55-mcrypt_5.5.38-184_amd64.deb
sha:4da6d9dd30b1e03cef12b72b13a0494a2a3e36af
-
alt-php55-mssql_5.5.38-184_amd64.deb
sha:63180dffc73707674e6134da14b30e941e0ffee5
-
alt-php55-mysqlnd_5.5.38-184_amd64.deb
sha:e6d3caf516a715a86aaad3c114d523e350b0eb04
-
alt-php55-odbc_5.5.38-184_amd64.deb
sha:db9982f1587dee80ede1fa115eebd2de90b4bda5
-
alt-php55-pdo_5.5.38-184_amd64.deb
sha:7b561f6b2c009a336fba46f643003ad406e4d71d
-
alt-php55-pgsql_5.5.38-184_amd64.deb
sha:995ffcd8a784290a9509504c6375613c8d7be04a
-
alt-php55-php-fpm_5.5.38-184_amd64.deb
sha:ac2b40d86e0a531f6662d2f8ac90db8f0fd739f0
-
alt-php55-process_5.5.38-184_amd64.deb
sha:42e223de7dc77f46ae2a881f87234e377f2ac5f9
-
alt-php55-pspell_5.5.38-184_amd64.deb
sha:1cae4e47c0f083bce1c1d4ef0fc4305fabdace7b
-
alt-php55-recode_5.5.38-184_amd64.deb
sha:c514c3351f735663bad79933dbd7c81bce65204a
-
alt-php55-snmp_5.5.38-184_amd64.deb
sha:7e69d77095642042cd5efa2f3bd2d3140f9e2d80
-
alt-php55-soap_5.5.38-184_amd64.deb
sha:29fcd89c3e43b4cb8acd602f3f6ede1c9949cc1e
-
alt-php55-sybase_5.5.38-184_amd64.deb
sha:1903c195ec557cabdd519d330d42200e6558ac9e
-
alt-php55-tidy_5.5.38-184_amd64.deb
sha:c32f83d767a7fc833dc5c0e74ecb478de495b77a
-
alt-php55-xml_5.5.38-184_amd64.deb
sha:c60ec520632865d77866bfe541a908acf81a5917
-
alt-php55-xmlrpc_5.5.38-184_amd64.deb
sha:b03dd08e903229bec2e6c1d94bb7724c51abd956
-
alt-php55_5.5.38-184_arm64.deb
sha:b6c13bb5148183bf7e6500387a070452bfedcf84
-
alt-php55-bcmath_5.5.38-184_arm64.deb
sha:052b66fdc4ac018622636a1bdbe8eaf58224d6da
-
alt-php55-cli_5.5.38-184_arm64.deb
sha:8dc39db66c59e39e9d13d89c9b46305674a17a53
-
alt-php55-common_5.5.38-184_arm64.deb
sha:0404afde385328b74b1ec1c8213d80858fcae94a
-
alt-php55-dba_5.5.38-184_arm64.deb
sha:6fc53bbe82c0bb612ef4b4171530fcb9e0b1e9bc
-
alt-php55-dbx_5.5.38-184_arm64.deb
sha:a29148959fe7a2777febe7816aed8621627b6a4f
-
alt-php55-dev_5.5.38-184_arm64.deb
sha:b5b6143eb53133aaeaaa294dfc8cd01ed73d6026
-
alt-php55-enchant_5.5.38-184_arm64.deb
sha:505d1c8c9ee5215f7c17b4c0abc0b39bec8d551b
-
alt-php55-firebird_5.5.38-184_arm64.deb
sha:92034b066a39ddfa6ff58584a6b0f87271033da6
-
alt-php55-gd_5.5.38-184_arm64.deb
sha:170d37257f93941be8af1b16e0d4db04b5acee74
-
alt-php55-imap_5.5.38-184_arm64.deb
sha:b4a532d59b52c4e97460efebc632fb6507ec4312
-
alt-php55-intl_5.5.38-184_arm64.deb
sha:593070fdda522e48c29f1130b05452ebd9c6728c
-
alt-php55-ldap_5.5.38-184_arm64.deb
sha:0119afe1570e2b2d9716afd1d96b5b965f76d841
-
alt-php55-mbstring_5.5.38-184_arm64.deb
sha:49ccd6c98b898c2ddfd733e506b5b67264f556fc
-
alt-php55-mcrypt_5.5.38-184_arm64.deb
sha:4e42d9fe8cde0f4f611474bcad810eea0e5d5d31
-
alt-php55-mssql_5.5.38-184_arm64.deb
sha:2ed07579a798463fce5f580aea98947143f18d96
-
alt-php55-mysqlnd_5.5.38-184_arm64.deb
sha:38eba3c8a129f637e484370a84920149acbab503
-
alt-php55-odbc_5.5.38-184_arm64.deb
sha:19b3ea397405cb5e89623e6db028020ef696633d
-
alt-php55-pdo_5.5.38-184_arm64.deb
sha:596db4e0933350c00d3458f162131ca5668a2c31
-
alt-php55-pgsql_5.5.38-184_arm64.deb
sha:7a2331b9422117e2479d015a8904d8fa90033f97
-
alt-php55-php-fpm_5.5.38-184_arm64.deb
sha:ee8e5efcfd8b0e1946ac5f614afa0f6dc67b07f8
-
alt-php55-process_5.5.38-184_arm64.deb
sha:646d8fe32391923d857aec3b761eb83a3435be4c
-
alt-php55-pspell_5.5.38-184_arm64.deb
sha:1ad3d8ab842b3074d07f2e6dc3aeccbb892a488e
-
alt-php55-recode_5.5.38-184_arm64.deb
sha:312a940ac205bc4ae9c3d30df428090dc562f54b
-
alt-php55-snmp_5.5.38-184_arm64.deb
sha:2647e2645221aeee1442ee3995d428eda74914e4
-
alt-php55-soap_5.5.38-184_arm64.deb
sha:3ff4182c0ab79222e7d550edbd69425ab041c779
-
alt-php55-sybase_5.5.38-184_arm64.deb
sha:7df182dfa92a99575da1170e38c2f5c7adbcb5e5
-
alt-php55-tidy_5.5.38-184_arm64.deb
sha:53eb1d7a23136f14c0affdd465bc4c273d3dffe2
-
alt-php55-xml_5.5.38-184_arm64.deb
sha:ccf756eec9183cd5c2b655d911a51a60d86319ae
-
alt-php55-xmlrpc_5.5.38-184_arm64.deb
sha:d6a332d4440d89ec592cca269ed09232d81e48b9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.