[CLSA-2026:1791454042] alt-php55: Fix of CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-09 11:43:58 UTC
Description:
- CVE-2025-1218: various packet over-reads in the mysqlnd wire protocol. The packet readers decoded fields out of a server response before checking that the packet still held the bytes for them, so a malicious or compromised MySQL server could make the client read past the end of the packet buffer with a truncated packet. BAIL_IF_NO_MORE_DATA, which only noticed an over-read after it had happened, is replaced by BAIL_IF_NOT_ENOUGH_DATA_EX(n), which checks before the read; php_mysqlnd_net_field_length() and its _ll variant now take the number of bytes left and refuse to decode a length whose payload is not fully present; the auth-plugin-name branches in auth_response_read, chg_user_read and cached_sha2_result_read use memchr() instead of trusting a NUL terminator (the latter two read into buffers nothing zero-terminates); the greeting's server version string is read the same way; and the TIME, DATE and DATETIME readers stop decoding fixed offsets out of a shorter declared length (GHSA-r6x9-5r99-36j7, upstream 114dbb7436). - The mysqlnd_ps.c hunk is a leak fix, not a memory-safety one: it releases the connection reference and the execute command buffer before mysqlnd_stmt_prepare_read_eof() memsets the statement, a path that only becomes reachable now that a short EOF packet is rejected. The prepare_read and sha256_pk_request_response_read changes are hardening rather than memory safety - prepare_read's new byte counts provably cannot fire behind the PREPARE_RESPONSE_SIZE gate in front of them, and the sha256 one is a strictness change. - Not applicable on 5.5: MARIADB_RPL_VERSION_HACK does not exist here, and upstream's two-byte look-ahead in cached_sha2_result_read guards a packet->result read that this branch's caching_sha2_password backport never added (the one-byte read it does have is guarded instead). The ps_codec helper trio and the text-row packet_end guard came in with our CVE-2024-8929 backport, so this patch extends them. As a prerequisite the bounded form of the greeting's auth plugin name from php-8.1.34 is carried too, without which dropping the NUL-terminating hack would make that estrdup() an unbounded read off a 2048 byte stack buffer. - Upstream's 38 phpt tests are not carried: they need the PHP 8 fake_server.inc, and the RPM test suite runs in the build-cgi tree, which is built without mysqli/mysqlnd, so every ext/mysqli test skips there. - The same mysqlnd_ps.c hunk also corrects that path's result free from mnd_efree() to upstream's php-7.0 form, mnd_pefree(stmt->result, stmt->result->persistent): mysqlnd_result_init() allocates the result with mnd_pecalloc(..., persistent), so on a persistent connection the Zend allocator was being handed a malloc()ed block. Before the change a hostile prepare over p:127.0.0.1 aborts with "zend_mm_heap corrupted" on a build with the Zend MM heap checks compiled in; after it the same run completes, and a non-persistent connection is unaffected either way - Also fixes a pre-existing use-after-free on the row-reader failure path: the CVE-2024-8929 error loops free every field decoded so far without clearing the zvals, and the result set frees them again at teardown. All 2 sites now clear after freeing. Confirmed under AddressSanitizer with the Zend allocator disabled - heap-use-after-free before, clean after, on the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11 - mysqlnd: initialise every pre-allocated row field before decoding (php-5.5.38-mysqlnd-rowp-init-fields.patch). The row readers pre-allocate a zval per column with MAKE_STD_ZVAL(), which sets no type, and only type it when the decode loop reaches that column; the CVE-2024-8929 error paths abandon a row part-way, leaving the rest allocated but never typed, and the result set still frees the whole row at teardown. Each column is now ZVAL_NULL()ed at allocation. Verified with valgrind under USE_ZEND_ALLOC=0. PHP 5 only, and kept separate from the CVE patch because the defect predates it and is reachable without it
CVEs fixed:
Updated packages:
  • alt-php55-5.5.38-182.el7.x86_64.rpm
    sha:baf5094d3743992fbf19b5ba875648929fff6126b96ea8b6685abade9a5b4608
  • alt-php55-bcmath-5.5.38-182.el7.x86_64.rpm
    sha:636661597c839d58e550d07d6c4b24dd3760269c57bed0bb952def299ef6d940
  • alt-php55-cli-5.5.38-182.el7.x86_64.rpm
    sha:8fde9716a53bf0d68fa51cd61cd424f073b60ee4c276d75e70a3a73744771e3d
  • alt-php55-common-5.5.38-182.el7.x86_64.rpm
    sha:6a0b2295ef0cacbc5c520d4cdfdd53897c34a8756c62200c526145573504f600
  • alt-php55-dba-5.5.38-182.el7.x86_64.rpm
    sha:26ab08248fb061237c85ff90d13dcc0ee7dba9cb81fc887ef52dd1b4e0cc615e
  • alt-php55-dbx-5.5.38-182.el7.x86_64.rpm
    sha:d0c2cc6bbb692da38bfd6941904a5f020bae232ee0471b59ede23434473aaa65
  • alt-php55-devel-5.5.38-182.el7.x86_64.rpm
    sha:36140c6bde9d78c30fa53a7dbc6bdefa99010e2ffc02fea3632909c42f3b5c00
  • alt-php55-enchant-5.5.38-182.el7.x86_64.rpm
    sha:b8d3a343863422e8edbee479b3790ad55152905aa9b0cc2543128a60bd98bbd0
  • alt-php55-firebird-5.5.38-182.el7.x86_64.rpm
    sha:7b3354eb29158e505749f3077b7c93a922da8b0e437921ef169893b8a74ee7ac
  • alt-php55-gd-5.5.38-182.el7.x86_64.rpm
    sha:439e46b41fa0797a4efe3430233e48d686aa8486145786e7469882380e04c0e0
  • alt-php55-imap-5.5.38-182.el7.x86_64.rpm
    sha:b902f13aaa18189488ed1b23cea1c9bae1cd7a6bc96ef7b2cf0d1cd6989ad33e
  • alt-php55-intl-5.5.38-182.el7.x86_64.rpm
    sha:20c98f7e1583bbd4e00e6d134274e3da7ad0b98b0d9b96affc3f2cc307326faf
  • alt-php55-ldap-5.5.38-182.el7.x86_64.rpm
    sha:ab989de87299417779fd274579a0e120dce63f22a44840ceec41de7ee4209764
  • alt-php55-mbstring-5.5.38-182.el7.x86_64.rpm
    sha:1f72a4a70c0b42f043ce7510e5576050b5139c4947596c1742070df8aff42e09
  • alt-php55-mcrypt-5.5.38-182.el7.x86_64.rpm
    sha:2fdf20f8a057fcac7f508f4e3c043d5402c73cc0b6c1eaad30d9b2c96e7b5db5
  • alt-php55-mssql-5.5.38-182.el7.x86_64.rpm
    sha:7289c4af6ef41f129cd7ffa4ad43bc85ddff1a140a44385337c12911b28d438f
  • alt-php55-mysqlnd-5.5.38-182.el7.x86_64.rpm
    sha:9e9deb621a2717e28857a5464236b7f1c1aaf04243ec7950be6c392a509ffbee
  • alt-php55-odbc-5.5.38-182.el7.x86_64.rpm
    sha:8e36674999d7b0663ec33aa6a6213e8bdd671746045609db4026c080c4cf8421
  • alt-php55-opcache-5.5.38-182.el7.x86_64.rpm
    sha:1f8d8b14198c2c37a4a832066fbb5ca36963b796e3a8aef83b60209d130cb8a7
  • alt-php55-pdo-5.5.38-182.el7.x86_64.rpm
    sha:9bd1eadb5792b8241078a26c0a1162d5d943cf8651abc3874ca20b5a8225bffa
  • alt-php55-pgsql-5.5.38-182.el7.x86_64.rpm
    sha:a713fec3b6d3746a8a67d27579fe8ab85e1681516ac38dc50f2a1082991037ff
  • alt-php55-php-fpm-5.5.38-182.el7.x86_64.rpm
    sha:3b2ef833ea1df6bb813058d3df4890cba12737de10b11d0374485d62c174cd9a
  • alt-php55-process-5.5.38-182.el7.x86_64.rpm
    sha:03dc668bd34f053387eada6fd57715c8264912812fe63d7d8e1a83249d849e19
  • alt-php55-pspell-5.5.38-182.el7.x86_64.rpm
    sha:dd79ddccf15afd0896919180cdcb51b2032d7bf88ee41752025affb5829f427a
  • alt-php55-recode-5.5.38-182.el7.x86_64.rpm
    sha:7158524abd81de567db284b1e8fba0b10f56b2d5838d59c6465793c2af69f553
  • alt-php55-snmp-5.5.38-182.el7.x86_64.rpm
    sha:91b863085c553343c0ddee7d28273bd5a6512e1d17416b0931705f003c9a7505
  • alt-php55-soap-5.5.38-182.el7.x86_64.rpm
    sha:b7fa70238197102078ae82338338df3abb42cbf5b0dc0bae86dfd8e99bf7878d
  • alt-php55-sybase-5.5.38-182.el7.x86_64.rpm
    sha:5bb4241bf70700452ae9b133a2a0b84743fa87df93932d150dbaaa94805e73a5
  • alt-php55-tidy-5.5.38-182.el7.x86_64.rpm
    sha:135a6f0b2fcc78e57097e00f24513190fe30c723304a3bc6fed14a9cf33e000e
  • alt-php55-xml-5.5.38-182.el7.x86_64.rpm
    sha:a7b4f42316ae956ab4ba1911273587b1b6d82f315674bcf05aff1081c11810bd
  • alt-php55-xmlrpc-5.5.38-182.el7.x86_64.rpm
    sha:0b5017b396053331b4148719968e3e91df00c726ce60c7d9d91a39a943755f40
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.