Release date:
2026-10-08 06:37:46 UTC
Description:
- CVE-2025-1218: out-of-bounds reads in the mysqlnd wire-protocol parser. A
malicious or compromised MySQL server could send a truncated packet and make
the client read past the end of the packet buffer. Re-implementation, against
the PHP 5.3 mysqlnd sources, of upstream 114dbb74368e6a6cd6e48ddb4a76dbe8728b84e2
(GHSA-r6x9-5r99-36j7, php-8.2.34 / php-8.3.34); the upstream diff does not
apply to 5.3 in any form, so every bound was re-derived from 5.3's own
bookkeeping. BAIL_IF_NO_MORE_DATA, which only noticed an over-read after it
had happened, is replaced by BAIL_PREMATURE_END / BAIL_IF_NOT_ENOUGH_DATA_EX,
and php_mysqlnd_net_field_length()/_ll() are given the bytes still left in the
packet so a length encoding can no longer be read out of bounds. Memory-safety
fixes cover the greeting (its server version string ran estrdup() off a
2048-byte stack buffer with no terminator guarantee on this branch - strictly
worse here than on any later branch - plus the 31-byte fixed block and the
split scramble), the OK and result-set header packets, the EOF packet, the
in-row EOF marker, the result-set field metadata lengths (which leaked heap
bytes into user-visible column metadata), the text-protocol row field lengths
and ps_fetch_time/date/datetime. The two new checks in prepare_read are
HARDENING ONLY and provably cannot fire; the mysqlnd_ps.c change is a memory
leak fix on the newly reachable prepare-EOF failure path, not an over-read.
The auth-response, SHA256-public-key and caching-sha2 packet readers, the
change-user auth-switch branch and the pluggable-auth parts of the greeting
do not exist at 5.3, so those parts of the upstream fix have no target here.
The 38 upstream .phpt tests are not carried - the fake_server.inc they drive
needs PHP 8.0 syntax - so the C fix ships without tests
- The same mysqlnd_ps.c hunk also corrects that path's result free from
mnd_efree() to upstream's php-7.0 form, mnd_pefree(stmt->result,
stmt->result->persistent): mysqlnd_result_init() allocates the result with
mnd_pecalloc(..., persistent), so on a persistent connection the Zend
allocator was being handed a malloc()ed block. Before the change a hostile
prepare over p:127.0.0.1 aborts with "zend_mm_heap corrupted" on a build
with the Zend MM heap checks compiled in; after it the same run completes,
and a non-persistent connection is unaffected either way
- Also fixes a pre-existing use-after-free on the row-reader failure path: the
CVE-2024-8929 error loops free every field decoded so far without clearing
the zvals, and the result set frees them again at teardown. All 2 sites now
clear after freeing. Confirmed under AddressSanitizer with the Zend allocator
disabled - heap-use-after-free before, clean after, on the three new
short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still
carries the same loops unguarded in php-8.2.34 through php-8.5.11
- mysqlnd: initialise every pre-allocated row field before decoding
(php-5.3.29-mysqlnd-rowp-init-fields.patch). The row readers pre-allocate a
zval per column with MAKE_STD_ZVAL(), which sets no type, and only type it
when the decode loop reaches that column; the CVE-2024-8929 error paths
abandon a row part-way, leaving the rest allocated but never typed, and the
result set still frees the whole row at teardown. Each column is now
ZVAL_NULL()ed at allocation. Verified with valgrind under USE_ZEND_ALLOC=0.
PHP 5 only, and kept separate from the CVE patch because the defect predates
it and is reachable without it
Updated packages:
-
alt-php53-5.3.29-219.el7.x86_64.rpm
sha:e0fa117f44f1736caeed71943902a2306563be0647b660efe0d51a0fb3b2557c
-
alt-php53-bcmath-5.3.29-219.el7.x86_64.rpm
sha:d20a7b41ce01c588e53d8b17752d5d094b2f3766c957809215261e7cf628ee49
-
alt-php53-cli-5.3.29-219.el7.x86_64.rpm
sha:79e5eb25d7d926d3dd0b7d3e64c0f62aa959bbb3dc46eab23fed15e8e8228f95
-
alt-php53-common-5.3.29-219.el7.x86_64.rpm
sha:9f71566b65350dcaf21e1165fd152e958ddd6d52ee156d897c25f7a50c2477dd
-
alt-php53-dba-5.3.29-219.el7.x86_64.rpm
sha:c44c013a66bef21719ab3b3d6adc8f40bf8e33d6fdc1c0072c78e088d03c5aba
-
alt-php53-dbx-5.3.29-219.el7.x86_64.rpm
sha:2063dac8b587fe048552ea178fbe92d4e4e61457ca58a67d66f2c7d251962ddb
-
alt-php53-devel-5.3.29-219.el7.x86_64.rpm
sha:fa0a56e29c23a10403487d321da8ccbfec70343e1cb49519745812b3e0861ae0
-
alt-php53-enchant-5.3.29-219.el7.x86_64.rpm
sha:81612f174adbfe213c993275d34eb632093e0f71ffae932063b003fc51ea5706
-
alt-php53-firebird-5.3.29-219.el7.x86_64.rpm
sha:836b7392dc142e62fb892919c1c5dc44066f0b24aaaf94b4bf80b570bdd88fd9
-
alt-php53-gd-5.3.29-219.el7.x86_64.rpm
sha:38f0b85e0ecc7ed62a4f82dcd8bd317231a01eaf96e5114cb7c86db2b5f2c639
-
alt-php53-imap-5.3.29-219.el7.x86_64.rpm
sha:a1443f9a598c57550e6453dc7f34531f30740910aeb0462b8efa5c1c4d01c110
-
alt-php53-intl-5.3.29-219.el7.x86_64.rpm
sha:183bf9988bc6b6b1aded48f4053103a3ba5c610e9fa41eba38cd4568f3625dea
-
alt-php53-ldap-5.3.29-219.el7.x86_64.rpm
sha:7b0e310eeb2057d4aaf5b8567454431f31f7598c179c22761630fc79a610db9a
-
alt-php53-mbstring-5.3.29-219.el7.x86_64.rpm
sha:8d505745f45322f53ee978058c42831542d7e463c89648c7a65d4454cd93f407
-
alt-php53-mcrypt-5.3.29-219.el7.x86_64.rpm
sha:58a05c708bb5a58b59fe6c0a5cd72af0bd4e44199ef2eaf12ff99273984be49c
-
alt-php53-mssql-5.3.29-219.el7.x86_64.rpm
sha:ac397d96812e03a0d113eef22c5297bdf038ebd8fbf9129052cedea69bb8c6bd
-
alt-php53-mysqlnd-5.3.29-219.el7.x86_64.rpm
sha:b96270679986495223f01018514432ef5c628c56083ce6c684a820461244abd6
-
alt-php53-odbc-5.3.29-219.el7.x86_64.rpm
sha:dd039c051e61d8a75a83ce5eaee7cc46fdf607a3f5e297bc04dafa38794c9b8b
-
alt-php53-pdo-5.3.29-219.el7.x86_64.rpm
sha:d8d75db263cca05add3a12320e7296dfedac43b31acb32ce74f5521bffd89364
-
alt-php53-pgsql-5.3.29-219.el7.x86_64.rpm
sha:5cddf9b5f21313fe3a906db04e7559cb8124b8fc9a891f00b132921e9e9f8a6b
-
alt-php53-php-fpm-5.3.29-219.el7.x86_64.rpm
sha:2e4f07bed1ddd8c514a0d28b362116d872fcc077fb4bccc894eb5a1790dd9d80
-
alt-php53-process-5.3.29-219.el7.x86_64.rpm
sha:49c7a894423673f143bccb7daacd3e465be3abac85d1fcc6a9907903793ce55a
-
alt-php53-pspell-5.3.29-219.el7.x86_64.rpm
sha:ee1b2b17b62ddf5163751bf28f68b7e5da872d4b25ad48f673f2f64760bb34d4
-
alt-php53-recode-5.3.29-219.el7.x86_64.rpm
sha:be4525cc6c7f4378b897aa2a37076ca90855622259f55ec2b8a85e0f7b75452c
-
alt-php53-snmp-5.3.29-219.el7.x86_64.rpm
sha:4528bab9407f4588141db013a2be4c620643f2b47f7c54628a174097b25b8c62
-
alt-php53-soap-5.3.29-219.el7.x86_64.rpm
sha:4490f3a814b4417de856051b7ff8302da0fc04cb1477f782d38c73bf964c3ca7
-
alt-php53-sqlite-5.3.29-219.el7.x86_64.rpm
sha:ef2d0a12b328fd4a3325aefd7641600a9b95c7119f9927b6a8376820149a43bc
-
alt-php53-sybase-5.3.29-219.el7.x86_64.rpm
sha:51dac80162224faa7b16a5d1ddf5c08b9b40acf30c1df36fcf294da51dd1efde
-
alt-php53-tidy-5.3.29-219.el7.x86_64.rpm
sha:69b97bffd7206790c9e7587f95463975e95f5cdb4207d64052937841ef0a741d
-
alt-php53-xml-5.3.29-219.el7.x86_64.rpm
sha:228cc51e3d5743699a9e5a9d6446d231063cb80012bd93068783d4d25d2322b2
-
alt-php53-xmlrpc-5.3.29-219.el7.x86_64.rpm
sha:2002f3e53e7fd537f199a27547dfaa19f89174f4b5c9928afed57356c5eb0a9f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.