[CLSA-2026:1791441453] alt-php53: Fix of CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-08 06:37:46 UTC
Description:
- CVE-2025-1218: out-of-bounds reads in the mysqlnd wire-protocol parser. A malicious or compromised MySQL server could send a truncated packet and make the client read past the end of the packet buffer. Re-implementation, against the PHP 5.3 mysqlnd sources, of upstream 114dbb74368e6a6cd6e48ddb4a76dbe8728b84e2 (GHSA-r6x9-5r99-36j7, php-8.2.34 / php-8.3.34); the upstream diff does not apply to 5.3 in any form, so every bound was re-derived from 5.3's own bookkeeping. BAIL_IF_NO_MORE_DATA, which only noticed an over-read after it had happened, is replaced by BAIL_PREMATURE_END / BAIL_IF_NOT_ENOUGH_DATA_EX, and php_mysqlnd_net_field_length()/_ll() are given the bytes still left in the packet so a length encoding can no longer be read out of bounds. Memory-safety fixes cover the greeting (its server version string ran estrdup() off a 2048-byte stack buffer with no terminator guarantee on this branch - strictly worse here than on any later branch - plus the 31-byte fixed block and the split scramble), the OK and result-set header packets, the EOF packet, the in-row EOF marker, the result-set field metadata lengths (which leaked heap bytes into user-visible column metadata), the text-protocol row field lengths and ps_fetch_time/date/datetime. The two new checks in prepare_read are HARDENING ONLY and provably cannot fire; the mysqlnd_ps.c change is a memory leak fix on the newly reachable prepare-EOF failure path, not an over-read. The auth-response, SHA256-public-key and caching-sha2 packet readers, the change-user auth-switch branch and the pluggable-auth parts of the greeting do not exist at 5.3, so those parts of the upstream fix have no target here. The 38 upstream .phpt tests are not carried - the fake_server.inc they drive needs PHP 8.0 syntax - so the C fix ships without tests - The same mysqlnd_ps.c hunk also corrects that path's result free from mnd_efree() to upstream's php-7.0 form, mnd_pefree(stmt->result, stmt->result->persistent): mysqlnd_result_init() allocates the result with mnd_pecalloc(..., persistent), so on a persistent connection the Zend allocator was being handed a malloc()ed block. Before the change a hostile prepare over p:127.0.0.1 aborts with "zend_mm_heap corrupted" on a build with the Zend MM heap checks compiled in; after it the same run completes, and a non-persistent connection is unaffected either way - Also fixes a pre-existing use-after-free on the row-reader failure path: the CVE-2024-8929 error loops free every field decoded so far without clearing the zvals, and the result set frees them again at teardown. All 2 sites now clear after freeing. Confirmed under AddressSanitizer with the Zend allocator disabled - heap-use-after-free before, clean after, on the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11 - mysqlnd: initialise every pre-allocated row field before decoding (php-5.3.29-mysqlnd-rowp-init-fields.patch). The row readers pre-allocate a zval per column with MAKE_STD_ZVAL(), which sets no type, and only type it when the decode loop reaches that column; the CVE-2024-8929 error paths abandon a row part-way, leaving the rest allocated but never typed, and the result set still frees the whole row at teardown. Each column is now ZVAL_NULL()ed at allocation. Verified with valgrind under USE_ZEND_ALLOC=0. PHP 5 only, and kept separate from the CVE patch because the defect predates it and is reachable without it
CVEs fixed:
Updated packages:
  • alt-php53-5.3.29-219.el7.x86_64.rpm
    sha:e0fa117f44f1736caeed71943902a2306563be0647b660efe0d51a0fb3b2557c
  • alt-php53-bcmath-5.3.29-219.el7.x86_64.rpm
    sha:d20a7b41ce01c588e53d8b17752d5d094b2f3766c957809215261e7cf628ee49
  • alt-php53-cli-5.3.29-219.el7.x86_64.rpm
    sha:79e5eb25d7d926d3dd0b7d3e64c0f62aa959bbb3dc46eab23fed15e8e8228f95
  • alt-php53-common-5.3.29-219.el7.x86_64.rpm
    sha:9f71566b65350dcaf21e1165fd152e958ddd6d52ee156d897c25f7a50c2477dd
  • alt-php53-dba-5.3.29-219.el7.x86_64.rpm
    sha:c44c013a66bef21719ab3b3d6adc8f40bf8e33d6fdc1c0072c78e088d03c5aba
  • alt-php53-dbx-5.3.29-219.el7.x86_64.rpm
    sha:2063dac8b587fe048552ea178fbe92d4e4e61457ca58a67d66f2c7d251962ddb
  • alt-php53-devel-5.3.29-219.el7.x86_64.rpm
    sha:fa0a56e29c23a10403487d321da8ccbfec70343e1cb49519745812b3e0861ae0
  • alt-php53-enchant-5.3.29-219.el7.x86_64.rpm
    sha:81612f174adbfe213c993275d34eb632093e0f71ffae932063b003fc51ea5706
  • alt-php53-firebird-5.3.29-219.el7.x86_64.rpm
    sha:836b7392dc142e62fb892919c1c5dc44066f0b24aaaf94b4bf80b570bdd88fd9
  • alt-php53-gd-5.3.29-219.el7.x86_64.rpm
    sha:38f0b85e0ecc7ed62a4f82dcd8bd317231a01eaf96e5114cb7c86db2b5f2c639
  • alt-php53-imap-5.3.29-219.el7.x86_64.rpm
    sha:a1443f9a598c57550e6453dc7f34531f30740910aeb0462b8efa5c1c4d01c110
  • alt-php53-intl-5.3.29-219.el7.x86_64.rpm
    sha:183bf9988bc6b6b1aded48f4053103a3ba5c610e9fa41eba38cd4568f3625dea
  • alt-php53-ldap-5.3.29-219.el7.x86_64.rpm
    sha:7b0e310eeb2057d4aaf5b8567454431f31f7598c179c22761630fc79a610db9a
  • alt-php53-mbstring-5.3.29-219.el7.x86_64.rpm
    sha:8d505745f45322f53ee978058c42831542d7e463c89648c7a65d4454cd93f407
  • alt-php53-mcrypt-5.3.29-219.el7.x86_64.rpm
    sha:58a05c708bb5a58b59fe6c0a5cd72af0bd4e44199ef2eaf12ff99273984be49c
  • alt-php53-mssql-5.3.29-219.el7.x86_64.rpm
    sha:ac397d96812e03a0d113eef22c5297bdf038ebd8fbf9129052cedea69bb8c6bd
  • alt-php53-mysqlnd-5.3.29-219.el7.x86_64.rpm
    sha:b96270679986495223f01018514432ef5c628c56083ce6c684a820461244abd6
  • alt-php53-odbc-5.3.29-219.el7.x86_64.rpm
    sha:dd039c051e61d8a75a83ce5eaee7cc46fdf607a3f5e297bc04dafa38794c9b8b
  • alt-php53-pdo-5.3.29-219.el7.x86_64.rpm
    sha:d8d75db263cca05add3a12320e7296dfedac43b31acb32ce74f5521bffd89364
  • alt-php53-pgsql-5.3.29-219.el7.x86_64.rpm
    sha:5cddf9b5f21313fe3a906db04e7559cb8124b8fc9a891f00b132921e9e9f8a6b
  • alt-php53-php-fpm-5.3.29-219.el7.x86_64.rpm
    sha:2e4f07bed1ddd8c514a0d28b362116d872fcc077fb4bccc894eb5a1790dd9d80
  • alt-php53-process-5.3.29-219.el7.x86_64.rpm
    sha:49c7a894423673f143bccb7daacd3e465be3abac85d1fcc6a9907903793ce55a
  • alt-php53-pspell-5.3.29-219.el7.x86_64.rpm
    sha:ee1b2b17b62ddf5163751bf28f68b7e5da872d4b25ad48f673f2f64760bb34d4
  • alt-php53-recode-5.3.29-219.el7.x86_64.rpm
    sha:be4525cc6c7f4378b897aa2a37076ca90855622259f55ec2b8a85e0f7b75452c
  • alt-php53-snmp-5.3.29-219.el7.x86_64.rpm
    sha:4528bab9407f4588141db013a2be4c620643f2b47f7c54628a174097b25b8c62
  • alt-php53-soap-5.3.29-219.el7.x86_64.rpm
    sha:4490f3a814b4417de856051b7ff8302da0fc04cb1477f782d38c73bf964c3ca7
  • alt-php53-sqlite-5.3.29-219.el7.x86_64.rpm
    sha:ef2d0a12b328fd4a3325aefd7641600a9b95c7119f9927b6a8376820149a43bc
  • alt-php53-sybase-5.3.29-219.el7.x86_64.rpm
    sha:51dac80162224faa7b16a5d1ddf5c08b9b40acf30c1df36fcf294da51dd1efde
  • alt-php53-tidy-5.3.29-219.el7.x86_64.rpm
    sha:69b97bffd7206790c9e7587f95463975e95f5cdb4207d64052937841ef0a741d
  • alt-php53-xml-5.3.29-219.el7.x86_64.rpm
    sha:228cc51e3d5743699a9e5a9d6446d231063cb80012bd93068783d4d25d2322b2
  • alt-php53-xmlrpc-5.3.29-219.el7.x86_64.rpm
    sha:2002f3e53e7fd537f199a27547dfaa19f89174f4b5c9928afed57356c5eb0a9f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.