[CLSA-2026:1791545995] alt-php55: Fix of CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-09 11:40:04 UTC
Description:
- CVE-2025-1218: various packet over-reads in the mysqlnd wire protocol. The packet readers decoded fields out of a server response before checking that the packet still held the bytes for them, so a malicious or compromised MySQL server could make the client read past the end of the packet buffer with a truncated packet. BAIL_IF_NO_MORE_DATA, which only noticed an over-read after it had happened, is replaced by BAIL_IF_NOT_ENOUGH_DATA_EX(n), which checks before the read; php_mysqlnd_net_field_length() and its _ll variant now take the number of bytes left and refuse to decode a length whose payload is not fully present; the auth-plugin-name branches in auth_response_read, chg_user_read and cached_sha2_result_read use memchr() instead of trusting a NUL terminator (the latter two read into buffers nothing zero-terminates); the greeting's server version string is read the same way; and the TIME, DATE and DATETIME readers stop decoding fixed offsets out of a shorter declared length (GHSA-r6x9-5r99-36j7, upstream 114dbb7436). - The mysqlnd_ps.c hunk is a leak fix, not a memory-safety one: it releases the connection reference and the execute command buffer before mysqlnd_stmt_prepare_read_eof() memsets the statement, a path that only becomes reachable now that a short EOF packet is rejected. The prepare_read and sha256_pk_request_response_read changes are hardening rather than memory safety - prepare_read's new byte counts provably cannot fire behind the PREPARE_RESPONSE_SIZE gate in front of them, and the sha256 one is a strictness change. - Not applicable on 5.5: MARIADB_RPL_VERSION_HACK does not exist here, and upstream's two-byte look-ahead in cached_sha2_result_read guards a packet->result read that this branch's caching_sha2_password backport never added (the one-byte read it does have is guarded instead). The ps_codec helper trio and the text-row packet_end guard came in with our CVE-2024-8929 backport, so this patch extends them. As a prerequisite the bounded form of the greeting's auth plugin name from php-8.1.34 is carried too, without which dropping the NUL-terminating hack would make that estrdup() an unbounded read off a 2048 byte stack buffer. - Upstream's 38 phpt tests are not carried: they need the PHP 8 fake_server.inc, and the RPM test suite runs in the build-cgi tree, which is built without mysqli/mysqlnd, so every ext/mysqli test skips there. - The same mysqlnd_ps.c hunk also corrects that path's result free from mnd_efree() to upstream's php-7.0 form, mnd_pefree(stmt->result, stmt->result->persistent): mysqlnd_result_init() allocates the result with mnd_pecalloc(..., persistent), so on a persistent connection the Zend allocator was being handed a malloc()ed block. Before the change a hostile prepare over p:127.0.0.1 aborts with "zend_mm_heap corrupted" on a build with the Zend MM heap checks compiled in; after it the same run completes, and a non-persistent connection is unaffected either way - Also fixes a pre-existing use-after-free on the row-reader failure path: the CVE-2024-8929 error loops free every field decoded so far without clearing the zvals, and the result set frees them again at teardown. All 2 sites now clear after freeing. Confirmed under AddressSanitizer with the Zend allocator disabled - heap-use-after-free before, clean after, on the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11 - mysqlnd: initialise every pre-allocated row field before decoding (php-5.5.38-mysqlnd-rowp-init-fields.patch). The row readers pre-allocate a zval per column with MAKE_STD_ZVAL(), which sets no type, and only type it when the decode loop reaches that column; the CVE-2024-8929 error paths abandon a row part-way, leaving the rest allocated but never typed, and the result set still frees the whole row at teardown. Each column is now ZVAL_NULL()ed at allocation. Verified with valgrind under USE_ZEND_ALLOC=0. PHP 5 only, and kept separate from the CVE patch because the defect predates it and is reachable without it
CVEs fixed:
Updated packages:
  • alt-php55-5.5.38-182.el10.x86_64.rpm
    sha:459abb1d6d4e97a859b91dc9dcd4913200a5768d0b7494f777ddf480cd4c17b7
  • alt-php55-bcmath-5.5.38-182.el10.x86_64.rpm
    sha:68136a8960726cd4b5dd07ed0129ab94c7474db07df11e4c8e81cf54418435d2
  • alt-php55-cli-5.5.38-182.el10.x86_64.rpm
    sha:b98f8144db14fcebf60f8c772893f8cf149b4346a55928163c05172d9af94b7b
  • alt-php55-common-5.5.38-182.el10.x86_64.rpm
    sha:a95bea5d5e92b7b7728bd52f5d6fdfe79de20ff792f997f694c31e6c73bf3434
  • alt-php55-dba-5.5.38-182.el10.x86_64.rpm
    sha:dd5a3ad3e82f2d4ed2113b56dd7ef8b606e0011e83c55a124f2e1eb14faedf07
  • alt-php55-dbx-5.5.38-182.el10.x86_64.rpm
    sha:d26dfc4ca2c7330d2dd7038f52ae370774ca6dc0a488fba6e3b93d0828df9bcf
  • alt-php55-devel-5.5.38-182.el10.x86_64.rpm
    sha:4c3e1150138908269ea73b71aad81e29223823940d9c7b0daaf1ce65ef4edb16
  • alt-php55-enchant-5.5.38-182.el10.x86_64.rpm
    sha:50006163909c36c5d40034ed302a793c918c836d541cc17fe51bf8cc107367a3
  • alt-php55-firebird-5.5.38-182.el10.x86_64.rpm
    sha:721dd3cb256e0bcab4a6fefb6aa2a3af04a823b5e27863662b1f98f891d8a1fe
  • alt-php55-gd-5.5.38-182.el10.x86_64.rpm
    sha:bb0b1a8251f48d3a21e425d9fb9f62e8347b06c648629e5aa774b121a81e940c
  • alt-php55-imap-5.5.38-182.el10.x86_64.rpm
    sha:43455746956c00fa690bd2ccb7f1627230ee360005df7ceeb233974ea2fb9843
  • alt-php55-intl-5.5.38-182.el10.x86_64.rpm
    sha:94afbb6c604627ff8451794d0e39e7076408d31b706ab7d80abdc2efd2541b08
  • alt-php55-ldap-5.5.38-182.el10.x86_64.rpm
    sha:f924e3f0349d63686c2cf3d561918f50b884408e01bb2e2800f720183f0519c6
  • alt-php55-mbstring-5.5.38-182.el10.x86_64.rpm
    sha:62694171d844ec90a0a4546d5813a53d52d38bebb330aadff980362eea435ed8
  • alt-php55-mcrypt-5.5.38-182.el10.x86_64.rpm
    sha:cb8ec4b995b6495937e46feb397a703eb9af908b87b3065648140e81912bf61a
  • alt-php55-mssql-5.5.38-182.el10.x86_64.rpm
    sha:7736b712b0054fcfd700a86f9d81642647c968bd22d190b271d8fb02d174e0d6
  • alt-php55-mysqlnd-5.5.38-182.el10.x86_64.rpm
    sha:9385a76eb84c497ba5539a1fc9444296d8ad517ceb659c1fca8fb2d5f31f1566
  • alt-php55-odbc-5.5.38-182.el10.x86_64.rpm
    sha:fb799aed7551ad91829d8cc98960e7366225de74d7ab1fef956ab2e2f13fd3d2
  • alt-php55-opcache-5.5.38-182.el10.x86_64.rpm
    sha:055fc85f1e4cf9cac9e32214534c1b0487d3fb2c2c93b1a18d1978de3dd2ac86
  • alt-php55-pdo-5.5.38-182.el10.x86_64.rpm
    sha:e49559daac370f1202eebdaea0ec233da9da2872358a0b7f8b1e296f4f6f4604
  • alt-php55-pgsql-5.5.38-182.el10.x86_64.rpm
    sha:997db8d7c0c30d9e5dabde34fdb3648b18a1276df21601a8b1adb0cec41dbf16
  • alt-php55-php-fpm-5.5.38-182.el10.x86_64.rpm
    sha:c21d9d7a8df7660012bdbfff4c764993e6c5ff2f01a6d52d292d2a8906aa872e
  • alt-php55-process-5.5.38-182.el10.x86_64.rpm
    sha:4932dbe4639b132f6fd55dd5718aa6e44fc6fe4876c29ea28f83c40f0442cd40
  • alt-php55-pspell-5.5.38-182.el10.x86_64.rpm
    sha:8924e0c120230085a57532075b048ba04dd5df209732a06667986a1ad1893e6d
  • alt-php55-recode-5.5.38-182.el10.x86_64.rpm
    sha:5744cc1722d42af8486e5b73f274692d1469e70053f59bd428d20f03ec943f86
  • alt-php55-snmp-5.5.38-182.el10.x86_64.rpm
    sha:d3c0a0511efb11b425d982d103bc640dcddf1d821d25e6cff28e48f7e7f81926
  • alt-php55-soap-5.5.38-182.el10.x86_64.rpm
    sha:e981723fb586bd222bae0d34e767c75190a8bf22a4da8d03c073b63e14860b7d
  • alt-php55-sybase-5.5.38-182.el10.x86_64.rpm
    sha:7579bf511df3870f0d4a60a0c12460c14c260f810386c6be4c3a79fa44c08dd4
  • alt-php55-tidy-5.5.38-182.el10.x86_64.rpm
    sha:6ae7c3bf84160d6be4fb41fd111f1cfb2d1fe1fe78cda1b4c11871a84a117b1c
  • alt-php55-xml-5.5.38-182.el10.x86_64.rpm
    sha:9556b0d064743f6535134a9676aaf1562f2c242a13e67684d7b147d1650929ab
  • alt-php55-xmlrpc-5.5.38-182.el10.x86_64.rpm
    sha:1745ee55a1dd8301de12dfad07d6efd6a664ed461b1a086be09f1677fbdb724f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.