[CLSA-2026:1791462287] alt-php56: Fix of CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-09 06:14:22 UTC
Description:
- CVE-2025-1218: various out-of-bounds reads in the mysqlnd wire-protocol parser (ext/mysqlnd/mysqlnd_wireprotocol.c, mysqlnd_wireprotocol.h, mysqlnd_ps_codec.c, mysqlnd_ps.c; GHSA-r6x9-5r99-36j7). The parser read fields out of a server packet before checking that the packet still held enough bytes, so a malicious or compromised MySQL server could make the client read past the end of the packet buffer. Backport of upstream commit 114dbb74368e: BAIL_IF_NO_MORE_DATA, which noticed an over-read only after it had happened, is replaced by the BAIL_PREMATURE_END / BAIL_IF_NOT_ENOUGH_DATA_EX family; php_mysqlnd_net_field_length() and its _ll() variant take the remaining packet size and report MYSQLND_INVALID_NET_FIELD_LENGTH instead of blindly consuming 2, 3 or 8 bytes; the server version and the auth-switch plugin names are located with memchr() over the remaining bytes instead of strdup()/strlen(); and the greeting's fixed block and extended scramble, the result-set field metadata lengths, the in-row EOF marker, the text-protocol field lengths and the declared lengths of TIME/DATE/DATETIME all gain real bounds checks. - Prerequisite note: the CVE-2024-8929 backport already on this branch is what supplies the three mysqlnd_ps_codec.c over-read helpers, the packet_end guard and the fake_server.inc test harness that upstream's change builds on; none of it is in the 5.6.40 tarball. - php-5.6.40-caching-sha2-password.patch introduces php_mysqlnd_cached_sha2_result_read() here, so both of its over-reads are live and are fixed: an unbounded stack over-read of the auth-switch plugin name off a 2048-byte buffer that nothing NUL-terminates (whose result is handed to the caller, with a length that underflows into a large emalloc/memcpy), and a one-byte read past a one-byte packet for the second response code. This patch is therefore applied after the caching-sha2 patch, not alongside the other CVE patches. - The greeting's authentication plugin name is still read with an unbounded estrdup() on 5.6.40, so php-8.1.34's bounded form is carried as a prerequisite before upstream's removal of the "buf[header.size] = 0" hack, which on its own would have turned a terminated read into an unbounded one. - Honest scope: php_mysqlnd_prepare_read() and php_mysqlnd_sha256_pk_request_response_read() are hardening, not memory-safety fixes - behind the existing PREPARE_RESPONSE_SIZE gate the new prepare_read checks cannot fire - and the mysqlnd_ps.c hunk is a leak fix on the newly reachable failure path, not an over-read. - Not applicable on this branch: upstream's guard around MARIADB_RPL_VERSION_HACK, which does not exist here. Upstream's rejection of any "def" value in the result-set field packet is deliberately not taken, because COM_FIELD_LIST is still supported on 5.6; the existing def bounds check is kept and only given the remaining size. - Upstream's 38 regression tests are NOT carried: they drive the dynamic-port fake server upstream added in the same commit, while the harness this branch has (ext/mysqli/tests/fake_server.inc, from the CVE-2024-8929 backport) binds a fixed port, so carrying them means rewriting all 38 and dropping the address assertion. Nothing would run them either way - the spec runselftest toggle defaults to 0 and debian/rules runs no suite. They were run locally instead, on a tree built from this repository's own patch series, first patched and then with only the C hunks of this patch reversed out and rebuilt: 32 of 38 pass patched / 0 fail, against 8 of 38 pass unpatched / 24 fail. The 6 skips in both arms are the cached-sha2 and sha256-pk tests, which need an ext/openssl this build did not have, PHP 5.6's openssl extension not compiling against OpenSSL 3 - The same mysqlnd_ps.c hunk also corrects that path's result free from mnd_efree() to upstream's php-7.0 form, mnd_pefree(stmt->result, stmt->result->persistent): mysqlnd_result_init() allocates the result with mnd_pecalloc(..., persistent), so on a persistent connection the Zend allocator was being handed a malloc()ed block. Before the change a hostile prepare over p:127.0.0.1 aborts with "zend_mm_heap corrupted" on a build with the Zend MM heap checks compiled in; after it the same run completes, and a non-persistent connection is unaffected either way - Also fixes a pre-existing use-after-free on the row-reader failure path: the CVE-2024-8929 error loops free every field decoded so far without clearing the zvals, and the result set frees them again at teardown. All 2 sites now clear after freeing. Confirmed under AddressSanitizer with the Zend allocator disabled - heap-use-after-free before, clean after, on the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11 - The mysqlnd_ps.c hunk additionally releases the result's own connection reference on the prepare-EOF path: before PHP 7.4 (upstream f365d0e00ed9) free_result_contents() did not drop it, so that path leaked one reference - mysqlnd: initialise every pre-allocated row field before decoding (php-5.6.40-mysqlnd-rowp-init-fields.patch). The row readers pre-allocate a zval per column with MAKE_STD_ZVAL(), which sets no type, and only type it when the decode loop reaches that column; the CVE-2024-8929 error paths abandon a row part-way, leaving the rest allocated but never typed, and the result set still frees the whole row at teardown. Each column is now ZVAL_NULL()ed at allocation. Verified with valgrind under USE_ZEND_ALLOC=0. PHP 5 only, and kept separate from the CVE patch because the defect predates it and is reachable without it
CVEs fixed:
Updated packages:
  • alt-php56-5.6.40-146.el10.x86_64.rpm
    sha:80aa31af4541cae5b6c0d354e7886d59dcd716a455373b7198140c8ee14424be
  • alt-php56-bcmath-5.6.40-146.el10.x86_64.rpm
    sha:744f10896f1a227438d872aa65d54a6d1de0f665d6841ea1a546947423bea5fa
  • alt-php56-cli-5.6.40-146.el10.x86_64.rpm
    sha:2e5a32e816048f0de3b0a126282d538a0914b4ef371aefcd49c8a903ccad17cc
  • alt-php56-common-5.6.40-146.el10.x86_64.rpm
    sha:c86bc2bc6b5a146ee04fb0ca695bdf0b0cf852ae49d7eda810b00049dab9cd4b
  • alt-php56-dba-5.6.40-146.el10.x86_64.rpm
    sha:06bde709b9d733b12ff74a8c3789117e134c4500e49c00c1457f52283646ef18
  • alt-php56-dbx-5.6.40-146.el10.x86_64.rpm
    sha:28e5e2a75a89e6d476a343e50c6aec8b8d5c7bd5802b3d4d058a9b0ab43c9c44
  • alt-php56-devel-5.6.40-146.el10.x86_64.rpm
    sha:39127d6cf18fc0b915051837e3aaa639d7e4e75f3c3e947f1d904c3db7309126
  • alt-php56-enchant-5.6.40-146.el10.x86_64.rpm
    sha:195817d6f21e12d990abe199c1f05a2b779993d7cb956821a06a6db9e25548ea
  • alt-php56-firebird-5.6.40-146.el10.x86_64.rpm
    sha:63ff974018932345f9332b614b17a7760539218229af2aa3db71a33913bc4d98
  • alt-php56-gd-5.6.40-146.el10.x86_64.rpm
    sha:9433e7424c60d42a6101b65f7ec7a0e20d82e009d4d3052dad2594e43cebc30a
  • alt-php56-imap-5.6.40-146.el10.x86_64.rpm
    sha:640fa872470b263dc929f00c3b527d1f91725cab26be6eb14061261caa300f8e
  • alt-php56-intl-5.6.40-146.el10.x86_64.rpm
    sha:2620865396ad333512486b486ed84a6a09940292cb83ac22281bdca7ee88affe
  • alt-php56-ldap-5.6.40-146.el10.x86_64.rpm
    sha:67f27b2fb5d9f0e3c654566e3cf18c265c6564931288ac188c32af13c4bc8cf5
  • alt-php56-mbstring-5.6.40-146.el10.x86_64.rpm
    sha:b0002364ddd42f700816908ce72bcee49ca4e3311f77cc6d7b925c166755d721
  • alt-php56-mcrypt-5.6.40-146.el10.x86_64.rpm
    sha:ef5d2c2b8ea64a0a5215a39c7755e8ce57aa9839ad78dfea87112038ccb1b014
  • alt-php56-mssql-5.6.40-146.el10.x86_64.rpm
    sha:fe1d9ef34ed736f9d7a4e3103cc55df57479f5bb690fdfbfa2a22da1130c0dca
  • alt-php56-mysqlnd-5.6.40-146.el10.x86_64.rpm
    sha:62ddd8ab671596bd03f0f6d9bfcbe2869c47e32e243427273564018618c8e01c
  • alt-php56-odbc-5.6.40-146.el10.x86_64.rpm
    sha:13be9cf7fb6fc6d8664507364a073e45840ee49a0fc9e9906f63897ca6359a4c
  • alt-php56-opcache-5.6.40-146.el10.x86_64.rpm
    sha:f30ad129f69cddc0c4d65ca09fe02b777168553fa3ac4082111419bcfa650c29
  • alt-php56-pdo-5.6.40-146.el10.x86_64.rpm
    sha:2c6a845c879ee73954d5c2bba0764484be0afb49e5188d95712e2f41c8d385bd
  • alt-php56-pgsql-5.6.40-146.el10.x86_64.rpm
    sha:cf45e0879172e4b2ab911000ec023b82277f250e4b242186c45c240a013851ba
  • alt-php56-php-fpm-5.6.40-146.el10.x86_64.rpm
    sha:c79ca2d7c1d8fd59cc013c8d18178cfd7a422869a24c749f278ff91a6284e22c
  • alt-php56-process-5.6.40-146.el10.x86_64.rpm
    sha:046718fdbee10a8ec098c985dd5c19b311e82cf0d819af5a878f3e8ba8661fc2
  • alt-php56-pspell-5.6.40-146.el10.x86_64.rpm
    sha:0f3589304da673d96e6d19acf1cf468fac504fcda7e5c5e3ffb2829cd0bc0de0
  • alt-php56-recode-5.6.40-146.el10.x86_64.rpm
    sha:65fccb5e9bcc0792f902ace208b73b9cae9c831eec7c3c167420815e199a4075
  • alt-php56-snmp-5.6.40-146.el10.x86_64.rpm
    sha:076444de07e4c04493ded02dc99ea2d5fec3a2bbb9ceaf5bd16f71598b2fd223
  • alt-php56-soap-5.6.40-146.el10.x86_64.rpm
    sha:5b7d8e617efb482fc60d7ddafec0ab82bdc4a2ffc0a5eb6c6f15f4c08fbb913e
  • alt-php56-sybase-5.6.40-146.el10.x86_64.rpm
    sha:716c394558299686326192b16611ac2c36357557f64b1fd5d743328577956160
  • alt-php56-tidy-5.6.40-146.el10.x86_64.rpm
    sha:60acf978d9e602eab2d440833b58650dce8bcee35359ab05777cfe85c61cee87
  • alt-php56-xml-5.6.40-146.el10.x86_64.rpm
    sha:c04cab97570376360c2444823037cd1ab57e84fd1478e547c44353a964ba3546
  • alt-php56-xmlrpc-5.6.40-146.el10.x86_64.rpm
    sha:2eb8a0ce57493ae539f9cdd6ee14473668f7941c30e1bc617ac89db6654459c8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.