Release date:
2026-10-08 07:17:00 UTC
Description:
- CVE-2025-1218: out-of-bounds reads in the mysqlnd wire-protocol parser. A
malicious or compromised MySQL server could send a truncated packet and make
the client read past the end of the packet buffer. Re-implementation, against
the PHP 5.3 mysqlnd sources, of upstream 114dbb74368e6a6cd6e48ddb4a76dbe8728b84e2
(GHSA-r6x9-5r99-36j7, php-8.2.34 / php-8.3.34); the upstream diff does not
apply to 5.3 in any form, so every bound was re-derived from 5.3's own
bookkeeping. BAIL_IF_NO_MORE_DATA, which only noticed an over-read after it
had happened, is replaced by BAIL_PREMATURE_END / BAIL_IF_NOT_ENOUGH_DATA_EX,
and php_mysqlnd_net_field_length()/_ll() are given the bytes still left in the
packet so a length encoding can no longer be read out of bounds. Memory-safety
fixes cover the greeting (its server version string ran estrdup() off a
2048-byte stack buffer with no terminator guarantee on this branch - strictly
worse here than on any later branch - plus the 31-byte fixed block and the
split scramble), the OK and result-set header packets, the EOF packet, the
in-row EOF marker, the result-set field metadata lengths (which leaked heap
bytes into user-visible column metadata), the text-protocol row field lengths
and ps_fetch_time/date/datetime. The two new checks in prepare_read are
HARDENING ONLY and provably cannot fire; the mysqlnd_ps.c change is a memory
leak fix on the newly reachable prepare-EOF failure path, not an over-read.
The auth-response, SHA256-public-key and caching-sha2 packet readers, the
change-user auth-switch branch and the pluggable-auth parts of the greeting
do not exist at 5.3, so those parts of the upstream fix have no target here.
The 38 upstream .phpt tests are not carried - the fake_server.inc they drive
needs PHP 8.0 syntax - so the C fix ships without tests
- The same mysqlnd_ps.c hunk also corrects that path's result free from
mnd_efree() to upstream's php-7.0 form, mnd_pefree(stmt->result,
stmt->result->persistent): mysqlnd_result_init() allocates the result with
mnd_pecalloc(..., persistent), so on a persistent connection the Zend
allocator was being handed a malloc()ed block. Before the change a hostile
prepare over p:127.0.0.1 aborts with "zend_mm_heap corrupted" on a build
with the Zend MM heap checks compiled in; after it the same run completes,
and a non-persistent connection is unaffected either way
- Also fixes a pre-existing use-after-free on the row-reader failure path: the
CVE-2024-8929 error loops free every field decoded so far without clearing
the zvals, and the result set frees them again at teardown. All 2 sites now
clear after freeing. Confirmed under AddressSanitizer with the Zend allocator
disabled - heap-use-after-free before, clean after, on the three new
short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still
carries the same loops unguarded in php-8.2.34 through php-8.5.11
- mysqlnd: initialise every pre-allocated row field before decoding
(php-5.3.29-mysqlnd-rowp-init-fields.patch). The row readers pre-allocate a
zval per column with MAKE_STD_ZVAL(), which sets no type, and only type it
when the decode loop reaches that column; the CVE-2024-8929 error paths
abandon a row part-way, leaving the rest allocated but never typed, and the
result set still frees the whole row at teardown. Each column is now
ZVAL_NULL()ed at allocation. Verified with valgrind under USE_ZEND_ALLOC=0.
PHP 5 only, and kept separate from the CVE patch because the defect predates
it and is reachable without it
Updated packages:
-
alt-php53-5.3.29-219.el10.x86_64.rpm
sha:15c810099d4bee313b74f0d204150437649606d723d74dde902bc73ea4efcd13
-
alt-php53-bcmath-5.3.29-219.el10.x86_64.rpm
sha:e230e06456c63b7432c5ffeba44eb2db89a0cd771d84642aec26c84de02278e3
-
alt-php53-cli-5.3.29-219.el10.x86_64.rpm
sha:eaeb02d55f514f0872065bf46b6b78a15e9dcaf93b066312b27145349617adce
-
alt-php53-common-5.3.29-219.el10.x86_64.rpm
sha:f99cb8e85996329c794d062693c05b11e76c29c3e57b6eec8494b7c792a48496
-
alt-php53-dba-5.3.29-219.el10.x86_64.rpm
sha:df7ad7d8b3bf05fe3981ba7beba83772fb8e8fa074885d079e4911806a4520e6
-
alt-php53-devel-5.3.29-219.el10.x86_64.rpm
sha:904c67f36891517f5e444988df6d2e76ffc0f2b49dd695bf938a00ebc1109d13
-
alt-php53-enchant-5.3.29-219.el10.x86_64.rpm
sha:63bf99d426f00cc9ed9a151e8e12b82c25a7f719b4a79219d4a5d278faff262b
-
alt-php53-gd-5.3.29-219.el10.x86_64.rpm
sha:23935a7a48cfa401151af039dd909bfb997325af3cbc23cd94a00695c788ed26
-
alt-php53-imap-5.3.29-219.el10.x86_64.rpm
sha:f9f0328da3af89b0567b8fbaba1fde7ed30b5a3b021019af44e000f24d5e343e
-
alt-php53-intl-5.3.29-219.el10.x86_64.rpm
sha:cc876ea39b4b55d1a00f8e9dbdbd004f614dc82f077990453d4e3da01d4d8fb2
-
alt-php53-ldap-5.3.29-219.el10.x86_64.rpm
sha:78fe869f62dc927e434fc5721cd7cadb0861e86f65ff32fe8735e3a9263d7feb
-
alt-php53-mbstring-5.3.29-219.el10.x86_64.rpm
sha:79e8aab893e8633376860db7a957c2da934115e5d4f0c02c4033dfb2f5307bf4
-
alt-php53-mcrypt-5.3.29-219.el10.x86_64.rpm
sha:2784addcf19d4f82d25e059035e1fe5af2af1f66d7f7213779518b5f7b496aa2
-
alt-php53-mssql-5.3.29-219.el10.x86_64.rpm
sha:9e37dcb140669c294faa9b39a55ec1c171f1f3daff0985fcfa2c5eef4b046d58
-
alt-php53-mysqlnd-5.3.29-219.el10.x86_64.rpm
sha:213c86801d1ddbc3972e789b8fe9705f3ea1b16ac81efe47b33a0be8455ffe1f
-
alt-php53-odbc-5.3.29-219.el10.x86_64.rpm
sha:169a805ee901125f07189c041180735699a207631067d1691abedd953d0a7092
-
alt-php53-pdo-5.3.29-219.el10.x86_64.rpm
sha:bc808533d40c5c6d8961b8b7783ad9d6137892450110891c456ad2f3fdd567eb
-
alt-php53-pgsql-5.3.29-219.el10.x86_64.rpm
sha:186f660ea36f491d0ce616a38845711d3f97b9c77c65a667081e3d30d4e6077e
-
alt-php53-php-fpm-5.3.29-219.el10.x86_64.rpm
sha:3ab89fe5bb5b4816a1978f971a37fbc34389458e6fcd95639ab938a82cf828a8
-
alt-php53-process-5.3.29-219.el10.x86_64.rpm
sha:f6fa619a2adffd4fd54993d0f4a3b3919ad8462cb6fba5e2e6d647cc02805b9f
-
alt-php53-pspell-5.3.29-219.el10.x86_64.rpm
sha:8640d42edcc1ff3b942104632af7684513e90053fd7cddf833dfe60e5487852f
-
alt-php53-recode-5.3.29-219.el10.x86_64.rpm
sha:f206eb7d71bcd958e9174b2cd5c3b58d4ed4789c490922347756efc1f908468b
-
alt-php53-snmp-5.3.29-219.el10.x86_64.rpm
sha:fb1ed652e2d3614da9f969af26ecd0bb869ef1a7637159e96b8eca7b7599fa3c
-
alt-php53-soap-5.3.29-219.el10.x86_64.rpm
sha:da950e1578d566c5a6facc0dea132b757f5d5225b5e94a59bf6ae2e6a976ac80
-
alt-php53-sqlite-5.3.29-219.el10.x86_64.rpm
sha:e4fb9e3d3ded6f9bf3cf34dd09edacd9446a8ec694487f28656f8b043332bd57
-
alt-php53-sybase-5.3.29-219.el10.x86_64.rpm
sha:a38492df143b08cc60eaa126fbff9e1f8b2360f454a3e17e492849062091a58b
-
alt-php53-tidy-5.3.29-219.el10.x86_64.rpm
sha:9b260bf41c30ce8e773ede2f453fcd2e896142c2e22e09c4728798e1cb18b541
-
alt-php53-xml-5.3.29-219.el10.x86_64.rpm
sha:ec988012299f62e5ef7180352d7937a6669b828e72d5b32ef55fc3fcb00d081b
-
alt-php53-xmlrpc-5.3.29-219.el10.x86_64.rpm
sha:cb524198c2f5a3135495612492ac05ebb60a3b0f06d315fb925032128fd2e429
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.