Release date:
2026-10-08 11:22:41 UTC
Description:
- CVE-2025-1218: packet over-reads in the mysqlnd wire-protocol parser - the greeting, auth response, OK, EOF, result-set header, result-set field, row and prepare readers decoded fields out of a server packet before checking that the packet still held enough bytes for them, so a malicious or compromised MySQL server could make the client read past the end of the packet buffer, leak heap bytes into user-visible result-set metadata, or allocate and copy a huge attacker-chosen length; php_mysqlnd_net_field_length() and its _ll variant now take the remaining packet size and refuse lengths whose payload is not present, the BAIL_IF_NO_MORE_DATA macro that only noticed an over-read after the fact is replaced by BAIL_IF_NOT_ENOUGH_DATA_EX(n), the unterminated auth-plugin-name branches use memchr() instead of trusting a NUL terminator, and the TIME/DATE/DATETIME prepared-statement readers stop decoding fixed offsets out of a shorter declared length (backport of upstream 114dbb74368e6a6cd6e48ddb4a76dbe8728b84e2, with upstream d37a20c4a24a70dbbcfd8724cd2ad5f1b005bd2a carried as a prerequisite because the fix removes the greeting buffer's NUL terminator; the php_mysqlnd_prepare_read() and php_mysqlnd_sha256_pk_request_response_read() hunks are hardening rather than memory-safety fixes, and the mysqlnd_ps.c hunk is a memory-leak fix on a newly reachable failure path)
- Also fixes a pre-existing use-after-free on the row-reader failure path: the
CVE-2024-8929 error loops free every field decoded so far without clearing
the zvals, and the result set frees them again at teardown. All 3 sites now
clear after freeing. Confirmed under AddressSanitizer with the Zend allocator
disabled - heap-use-after-free before, clean after, on the three new
short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still
carries the same loops unguarded in php-8.2.34 through php-8.5.11
- The mysqlnd_ps.c hunk additionally releases the result's own connection
reference on the prepare-EOF path: before PHP 7.4 (upstream f365d0e00ed9)
free_result_contents() did not drop it, so that path leaked one reference
Updated packages:
-
alt-php71-7.1.33-113.el10.x86_64.rpm
sha:d20f6b72d5bc38d30092c9d6d18353bd395d41bc35e6ee395f94540cb522c089
-
alt-php71-bcmath-7.1.33-113.el10.x86_64.rpm
sha:3c807a8c04d730c93831097e2ba5dbafa5e313e77ca42b1e4f53c2d52724fd03
-
alt-php71-cli-7.1.33-113.el10.x86_64.rpm
sha:8be9167268b5f71d6c562f142b03d78d9d3f9d43f1015fa53815e9aad273777e
-
alt-php71-common-7.1.33-113.el10.x86_64.rpm
sha:f0eaada7adbeba5c19754651c8b388b9adf7bd792fb9cdf9241ebfdc03d5ef0a
-
alt-php71-dba-7.1.33-113.el10.x86_64.rpm
sha:dc7365c33f6ef73dd2e9de90519bb22b7e74c37f2cb602d3979b7f5ea81e7ec5
-
alt-php71-devel-7.1.33-113.el10.x86_64.rpm
sha:370eb477244978c414c0fb7de566fd28019810bc57b39af4e568f1f510d4f25c
-
alt-php71-enchant-7.1.33-113.el10.x86_64.rpm
sha:70ee9e0e8efdd949a3f337401e9542b53d9f88961dd5da8f4a930162959c8c1f
-
alt-php71-firebird-7.1.33-113.el10.x86_64.rpm
sha:e7461b8c5759f5d4f52b362cea6f85e8885b3b751afadd891f6704d82e4bd7c0
-
alt-php71-gd-7.1.33-113.el10.x86_64.rpm
sha:73de33657f52a9775fa10a4d8d1562ecfec45af4a8d2438feb25a57bbe856004
-
alt-php71-imap-7.1.33-113.el10.x86_64.rpm
sha:1cde544e234800ece282c78127327a5c3ddef09f06aee35527b5af89a6070886
-
alt-php71-intl-7.1.33-113.el10.x86_64.rpm
sha:e7f1409bc93e0a60b57d93c35d7aac8d4ff95fc9bd859c14924902a77fc977dd
-
alt-php71-ldap-7.1.33-113.el10.x86_64.rpm
sha:89312e7baeec8ef6f7f89843f7b627f02ccd0c76f712a4786ce2e502d716d8d6
-
alt-php71-mbstring-7.1.33-113.el10.x86_64.rpm
sha:2dfe4426c7bdb49d30d5f15ed2163d97a3e7d8f9f103997ed5e1eaf0ef1aab19
-
alt-php71-mcrypt-7.1.33-113.el10.x86_64.rpm
sha:07ebf797b0001b69fcb1c4181814b8bfc1643f959c311a818c58461c6882f090
-
alt-php71-mysqlnd-7.1.33-113.el10.x86_64.rpm
sha:c30b370afd5fa1221dc4694f97eccafb0885323d812aa363fc16be985cfa95ab
-
alt-php71-odbc-7.1.33-113.el10.x86_64.rpm
sha:bd386a077b682ddb432d9357d5ffa1b8c2a7ea79d155ea5a8299350ba8ab9df7
-
alt-php71-opcache-7.1.33-113.el10.x86_64.rpm
sha:de73797747a18696198512b9e8bad5c015d364980bbadd70729851aa79070494
-
alt-php71-pdo-7.1.33-113.el10.x86_64.rpm
sha:b869c981c33f2aa5ee133c64a0b89f9f6614ad4b6636a400a4d125f31c816cd0
-
alt-php71-pgsql-7.1.33-113.el10.x86_64.rpm
sha:0058a347d36d0ac7809b9209486e7130130cebae90bccecc3e9ef15ffc1867df
-
alt-php71-php-fpm-7.1.33-113.el10.x86_64.rpm
sha:b83fff155d01ee42a8896d27c11c045f9d852772cf7512c8ea6768d8833f5174
-
alt-php71-process-7.1.33-113.el10.x86_64.rpm
sha:8a93cd4f5c2dfe67936c621065e300fffdaa3518bcacaff2b06ed5450e2da503
-
alt-php71-pspell-7.1.33-113.el10.x86_64.rpm
sha:52f1e481bf433cca4e084e4a62c24e22245228db8691deb10a48f41cb2f09884
-
alt-php71-recode-7.1.33-113.el10.x86_64.rpm
sha:cce17f30c2d7bf32e653995bc3c3311643f4a113c85acbb4e5f23e228f2455fc
-
alt-php71-snmp-7.1.33-113.el10.x86_64.rpm
sha:33cdf89780ddd07a3a7e24fabeae6001fc748becadb8cc31806d50063e40492a
-
alt-php71-soap-7.1.33-113.el10.x86_64.rpm
sha:c6f91934308e55be9101992d7c411c198025623d0933f6540f038dfeb69e7ce7
-
alt-php71-tidy-7.1.33-113.el10.x86_64.rpm
sha:e9e6bd8b23d750216be2b8a35259737b943cf8b40facc407b16e71f822a5c30c
-
alt-php71-xml-7.1.33-113.el10.x86_64.rpm
sha:685f2f837f0aa2aaccd0174bba0e5085119e69a84dcad4d6b95cc7db189f6eaf
-
alt-php71-xmlrpc-7.1.33-113.el10.x86_64.rpm
sha:da440f4557d4a950110151a8a4bd7ddef0314a5378038ecede31c5769a2b0753
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.