Release date:
2026-10-09 11:40:04 UTC
Description:
- CVE-2025-1218: various packet over-reads in the mysqlnd wire protocol. The
packet readers decoded fields out of a server response before checking that
the packet still held the bytes for them, so a malicious or compromised MySQL
server could make the client read past the end of the packet buffer with a
truncated packet. BAIL_IF_NO_MORE_DATA, which only noticed an over-read after
it had happened, is replaced by BAIL_IF_NOT_ENOUGH_DATA_EX(n), which checks
before the read; php_mysqlnd_net_field_length() and its _ll variant now take
the number of bytes left and refuse to decode a length whose payload is not
fully present; the auth-plugin-name branches in auth_response_read,
chg_user_read and cached_sha2_result_read use memchr() instead of trusting a
NUL terminator (the latter two read into buffers nothing zero-terminates);
the greeting's server version string is read the same way; and the TIME, DATE
and DATETIME readers stop decoding fixed offsets out of a shorter declared
length (GHSA-r6x9-5r99-36j7, upstream 114dbb7436).
- The mysqlnd_ps.c hunk is a leak fix, not a memory-safety one: it releases the
connection reference and the execute command buffer before
mysqlnd_stmt_prepare_read_eof() memsets the statement, a path that only
becomes reachable now that a short EOF packet is rejected. The prepare_read
and sha256_pk_request_response_read changes are hardening rather than memory
safety - prepare_read's new byte counts provably cannot fire behind the
PREPARE_RESPONSE_SIZE gate in front of them, and the sha256 one is a
strictness change.
- Not applicable on 5.5: MARIADB_RPL_VERSION_HACK does not exist here, and
upstream's two-byte look-ahead in cached_sha2_result_read guards a
packet->result read that this branch's caching_sha2_password backport never
added (the one-byte read it does have is guarded instead). The ps_codec
helper trio and the text-row packet_end guard came in with our CVE-2024-8929
backport, so this patch extends them. As a prerequisite the bounded form of
the greeting's auth plugin name from php-8.1.34 is carried too, without which
dropping the NUL-terminating hack would make that estrdup() an unbounded read
off a 2048 byte stack buffer.
- Upstream's 38 phpt tests are not carried: they need the PHP 8 fake_server.inc,
and the RPM test suite runs in the build-cgi tree, which is built without
mysqli/mysqlnd, so every ext/mysqli test skips there.
- The same mysqlnd_ps.c hunk also corrects that path's result free from
mnd_efree() to upstream's php-7.0 form, mnd_pefree(stmt->result,
stmt->result->persistent): mysqlnd_result_init() allocates the result with
mnd_pecalloc(..., persistent), so on a persistent connection the Zend
allocator was being handed a malloc()ed block. Before the change a hostile
prepare over p:127.0.0.1 aborts with "zend_mm_heap corrupted" on a build
with the Zend MM heap checks compiled in; after it the same run completes,
and a non-persistent connection is unaffected either way
- Also fixes a pre-existing use-after-free on the row-reader failure path: the
CVE-2024-8929 error loops free every field decoded so far without clearing
the zvals, and the result set frees them again at teardown. All 2 sites now
clear after freeing. Confirmed under AddressSanitizer with the Zend allocator
disabled - heap-use-after-free before, clean after, on the three new
short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still
carries the same loops unguarded in php-8.2.34 through php-8.5.11
- mysqlnd: initialise every pre-allocated row field before decoding
(php-5.5.38-mysqlnd-rowp-init-fields.patch). The row readers pre-allocate a
zval per column with MAKE_STD_ZVAL(), which sets no type, and only type it
when the decode loop reaches that column; the CVE-2024-8929 error paths
abandon a row part-way, leaving the rest allocated but never typed, and the
result set still frees the whole row at teardown. Each column is now
ZVAL_NULL()ed at allocation. Verified with valgrind under USE_ZEND_ALLOC=0.
PHP 5 only, and kept separate from the CVE patch because the defect predates
it and is reachable without it
Updated packages:
-
alt-php55-5.5.38-182.el10.x86_64.rpm
sha:459abb1d6d4e97a859b91dc9dcd4913200a5768d0b7494f777ddf480cd4c17b7
-
alt-php55-bcmath-5.5.38-182.el10.x86_64.rpm
sha:68136a8960726cd4b5dd07ed0129ab94c7474db07df11e4c8e81cf54418435d2
-
alt-php55-cli-5.5.38-182.el10.x86_64.rpm
sha:b98f8144db14fcebf60f8c772893f8cf149b4346a55928163c05172d9af94b7b
-
alt-php55-common-5.5.38-182.el10.x86_64.rpm
sha:a95bea5d5e92b7b7728bd52f5d6fdfe79de20ff792f997f694c31e6c73bf3434
-
alt-php55-dba-5.5.38-182.el10.x86_64.rpm
sha:dd5a3ad3e82f2d4ed2113b56dd7ef8b606e0011e83c55a124f2e1eb14faedf07
-
alt-php55-dbx-5.5.38-182.el10.x86_64.rpm
sha:d26dfc4ca2c7330d2dd7038f52ae370774ca6dc0a488fba6e3b93d0828df9bcf
-
alt-php55-devel-5.5.38-182.el10.x86_64.rpm
sha:4c3e1150138908269ea73b71aad81e29223823940d9c7b0daaf1ce65ef4edb16
-
alt-php55-enchant-5.5.38-182.el10.x86_64.rpm
sha:50006163909c36c5d40034ed302a793c918c836d541cc17fe51bf8cc107367a3
-
alt-php55-firebird-5.5.38-182.el10.x86_64.rpm
sha:721dd3cb256e0bcab4a6fefb6aa2a3af04a823b5e27863662b1f98f891d8a1fe
-
alt-php55-gd-5.5.38-182.el10.x86_64.rpm
sha:bb0b1a8251f48d3a21e425d9fb9f62e8347b06c648629e5aa774b121a81e940c
-
alt-php55-imap-5.5.38-182.el10.x86_64.rpm
sha:43455746956c00fa690bd2ccb7f1627230ee360005df7ceeb233974ea2fb9843
-
alt-php55-intl-5.5.38-182.el10.x86_64.rpm
sha:94afbb6c604627ff8451794d0e39e7076408d31b706ab7d80abdc2efd2541b08
-
alt-php55-ldap-5.5.38-182.el10.x86_64.rpm
sha:f924e3f0349d63686c2cf3d561918f50b884408e01bb2e2800f720183f0519c6
-
alt-php55-mbstring-5.5.38-182.el10.x86_64.rpm
sha:62694171d844ec90a0a4546d5813a53d52d38bebb330aadff980362eea435ed8
-
alt-php55-mcrypt-5.5.38-182.el10.x86_64.rpm
sha:cb8ec4b995b6495937e46feb397a703eb9af908b87b3065648140e81912bf61a
-
alt-php55-mssql-5.5.38-182.el10.x86_64.rpm
sha:7736b712b0054fcfd700a86f9d81642647c968bd22d190b271d8fb02d174e0d6
-
alt-php55-mysqlnd-5.5.38-182.el10.x86_64.rpm
sha:9385a76eb84c497ba5539a1fc9444296d8ad517ceb659c1fca8fb2d5f31f1566
-
alt-php55-odbc-5.5.38-182.el10.x86_64.rpm
sha:fb799aed7551ad91829d8cc98960e7366225de74d7ab1fef956ab2e2f13fd3d2
-
alt-php55-opcache-5.5.38-182.el10.x86_64.rpm
sha:055fc85f1e4cf9cac9e32214534c1b0487d3fb2c2c93b1a18d1978de3dd2ac86
-
alt-php55-pdo-5.5.38-182.el10.x86_64.rpm
sha:e49559daac370f1202eebdaea0ec233da9da2872358a0b7f8b1e296f4f6f4604
-
alt-php55-pgsql-5.5.38-182.el10.x86_64.rpm
sha:997db8d7c0c30d9e5dabde34fdb3648b18a1276df21601a8b1adb0cec41dbf16
-
alt-php55-php-fpm-5.5.38-182.el10.x86_64.rpm
sha:c21d9d7a8df7660012bdbfff4c764993e6c5ff2f01a6d52d292d2a8906aa872e
-
alt-php55-process-5.5.38-182.el10.x86_64.rpm
sha:4932dbe4639b132f6fd55dd5718aa6e44fc6fe4876c29ea28f83c40f0442cd40
-
alt-php55-pspell-5.5.38-182.el10.x86_64.rpm
sha:8924e0c120230085a57532075b048ba04dd5df209732a06667986a1ad1893e6d
-
alt-php55-recode-5.5.38-182.el10.x86_64.rpm
sha:5744cc1722d42af8486e5b73f274692d1469e70053f59bd428d20f03ec943f86
-
alt-php55-snmp-5.5.38-182.el10.x86_64.rpm
sha:d3c0a0511efb11b425d982d103bc640dcddf1d821d25e6cff28e48f7e7f81926
-
alt-php55-soap-5.5.38-182.el10.x86_64.rpm
sha:e981723fb586bd222bae0d34e767c75190a8bf22a4da8d03c073b63e14860b7d
-
alt-php55-sybase-5.5.38-182.el10.x86_64.rpm
sha:7579bf511df3870f0d4a60a0c12460c14c260f810386c6be4c3a79fa44c08dd4
-
alt-php55-tidy-5.5.38-182.el10.x86_64.rpm
sha:6ae7c3bf84160d6be4fb41fd111f1cfb2d1fe1fe78cda1b4c11871a84a117b1c
-
alt-php55-xml-5.5.38-182.el10.x86_64.rpm
sha:9556b0d064743f6535134a9676aaf1562f2c242a13e67684d7b147d1650929ab
-
alt-php55-xmlrpc-5.5.38-182.el10.x86_64.rpm
sha:1745ee55a1dd8301de12dfad07d6efd6a664ed461b1a086be09f1677fbdb724f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.