Release date:
2026-10-09 06:07:12 UTC
Description:
- CVE-2025-1218: various out-of-bounds reads in the mysqlnd wire-protocol
parser (ext/mysqlnd/mysqlnd_wireprotocol.c, mysqlnd_wireprotocol.h,
mysqlnd_ps_codec.c, mysqlnd_ps.c; GHSA-r6x9-5r99-36j7). The parser read
fields out of a server packet before checking that the packet still held
enough bytes, so a malicious or compromised MySQL server could make the
client read past the end of the packet buffer. Backport of upstream commit
114dbb74368e: BAIL_IF_NO_MORE_DATA, which noticed an over-read only after
it had happened, is replaced by the BAIL_PREMATURE_END /
BAIL_IF_NOT_ENOUGH_DATA_EX family; php_mysqlnd_net_field_length() and its
_ll() variant take the remaining packet size and report
MYSQLND_INVALID_NET_FIELD_LENGTH instead of blindly consuming 2, 3 or 8
bytes; the server version and the auth-switch plugin names are located with
memchr() over the remaining bytes instead of strdup()/strlen(); and the
greeting's fixed block and extended scramble, the result-set field metadata
lengths, the in-row EOF marker, the text-protocol field lengths and the
declared lengths of TIME/DATE/DATETIME all gain real bounds checks.
- Prerequisite note: the CVE-2024-8929 backport already on this branch is
what supplies the three mysqlnd_ps_codec.c over-read helpers, the
packet_end guard and the fake_server.inc test harness that upstream's
change builds on; none of it is in the 5.6.40 tarball.
- php-5.6.40-caching-sha2-password.patch introduces
php_mysqlnd_cached_sha2_result_read() here, so both of its over-reads are
live and are fixed: an unbounded stack over-read of the auth-switch plugin
name off a 2048-byte buffer that nothing NUL-terminates (whose result is
handed to the caller, with a length that underflows into a large
emalloc/memcpy), and a one-byte read past a one-byte packet for the second
response code. This patch is therefore applied after the caching-sha2
patch, not alongside the other CVE patches.
- The greeting's authentication plugin name is still read with an unbounded
estrdup() on 5.6.40, so php-8.1.34's bounded form is carried as a
prerequisite before upstream's removal of the "buf[header.size] = 0" hack,
which on its own would have turned a terminated read into an unbounded one.
- Honest scope: php_mysqlnd_prepare_read() and
php_mysqlnd_sha256_pk_request_response_read() are hardening, not
memory-safety fixes - behind the existing PREPARE_RESPONSE_SIZE gate the
new prepare_read checks cannot fire - and the mysqlnd_ps.c hunk is a leak
fix on the newly reachable failure path, not an over-read.
- Not applicable on this branch: upstream's guard around
MARIADB_RPL_VERSION_HACK, which does not exist here. Upstream's rejection
of any "def" value in the result-set field packet is deliberately not
taken, because COM_FIELD_LIST is still supported on 5.6; the existing def
bounds check is kept and only given the remaining size.
- Upstream's 38 regression tests are NOT carried: they drive the dynamic-port
fake server upstream added in the same commit, while the harness this branch
has (ext/mysqli/tests/fake_server.inc, from the CVE-2024-8929 backport)
binds a fixed port, so carrying them means rewriting all 38 and dropping the
address assertion. Nothing would run them either way - the spec runselftest
toggle defaults to 0 and debian/rules runs no suite. They were run locally
instead, on a tree built from this repository's own patch series, first
patched and then with only the C hunks of this patch reversed out and
rebuilt: 32 of 38 pass patched / 0 fail, against 8 of 38 pass unpatched / 24
fail. The 6 skips in both arms are the cached-sha2 and sha256-pk tests,
which need an ext/openssl this build did not have, PHP 5.6's openssl
extension not compiling against OpenSSL 3
- The same mysqlnd_ps.c hunk also corrects that path's result free from
mnd_efree() to upstream's php-7.0 form, mnd_pefree(stmt->result,
stmt->result->persistent): mysqlnd_result_init() allocates the result with
mnd_pecalloc(..., persistent), so on a persistent connection the Zend
allocator was being handed a malloc()ed block. Before the change a hostile
prepare over p:127.0.0.1 aborts with "zend_mm_heap corrupted" on a build
with the Zend MM heap checks compiled in; after it the same run completes,
and a non-persistent connection is unaffected either way
- Also fixes a pre-existing use-after-free on the row-reader failure path: the
CVE-2024-8929 error loops free every field decoded so far without clearing
the zvals, and the result set frees them again at teardown. All 2 sites now
clear after freeing. Confirmed under AddressSanitizer with the Zend allocator
disabled - heap-use-after-free before, clean after, on the three new
short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still
carries the same loops unguarded in php-8.2.34 through php-8.5.11
- The mysqlnd_ps.c hunk additionally releases the result's own connection
reference on the prepare-EOF path: before PHP 7.4 (upstream f365d0e00ed9)
free_result_contents() did not drop it, so that path leaked one reference
- mysqlnd: initialise every pre-allocated row field before decoding
(php-5.6.40-mysqlnd-rowp-init-fields.patch). The row readers pre-allocate a
zval per column with MAKE_STD_ZVAL(), which sets no type, and only type it
when the decode loop reaches that column; the CVE-2024-8929 error paths
abandon a row part-way, leaving the rest allocated but never typed, and the
result set still frees the whole row at teardown. Each column is now
ZVAL_NULL()ed at allocation. Verified with valgrind under USE_ZEND_ALLOC=0.
PHP 5 only, and kept separate from the CVE patch because the defect predates
it and is reachable without it
Updated packages:
-
alt-php56-5.6.40-146.el7.x86_64.rpm
sha:f4ab1e3de06a960d26f3cfa0891b757d125a5e388480bb0733a0e5ec2c1ec8c6
-
alt-php56-bcmath-5.6.40-146.el7.x86_64.rpm
sha:64f447e51a23ef7f474d5aaa6d0914b41135253e066f8936bcb8678fa19bb777
-
alt-php56-cli-5.6.40-146.el7.x86_64.rpm
sha:6d6e8d00a52e1e51b6fe5deb0b85d549da2d4b2640ab4257058408df5218fedd
-
alt-php56-common-5.6.40-146.el7.x86_64.rpm
sha:b9fae7b0d39d2662c945b243ab4f8443234445c87a8748d9b8189556f5349a88
-
alt-php56-dba-5.6.40-146.el7.x86_64.rpm
sha:ce792c7ac38ae9502265f90dac3256190b6dfcde5882a7143b35fdb9ec116921
-
alt-php56-dbx-5.6.40-146.el7.x86_64.rpm
sha:8d75cb5416f090a5e6370f923b00d038d658ca520640e77e48ff05244dabc6dc
-
alt-php56-devel-5.6.40-146.el7.x86_64.rpm
sha:d99dab8f22a199050317b4325df7ef13199554e5f639649c0036ad659a5895fd
-
alt-php56-enchant-5.6.40-146.el7.x86_64.rpm
sha:c73adc820f246526a0dce1cb3ca3d2809271e5938d06c7395c1c1df997b07110
-
alt-php56-firebird-5.6.40-146.el7.x86_64.rpm
sha:fad887e3be3725eb89b5ef2d6f89ccb434a6e1d795855583b7370bbc1927a192
-
alt-php56-gd-5.6.40-146.el7.x86_64.rpm
sha:8d7fa3ebba624a0515aaa32a7c7b7886c8d582281b92350fcdfb328a20c3534a
-
alt-php56-imap-5.6.40-146.el7.x86_64.rpm
sha:2c83f8b21974d809110ab9b9133f0c59dee4e6a1ed4be29c9e55ef03a6dc1c0f
-
alt-php56-intl-5.6.40-146.el7.x86_64.rpm
sha:254db05c1c4e1c39490dbdf3209b2fac74ee0383a3720bebf30c990f37202a49
-
alt-php56-ldap-5.6.40-146.el7.x86_64.rpm
sha:1c51bdfa2b768bf115347c92ce6ef90b45a689c0d7e101da18b718be345fc407
-
alt-php56-mbstring-5.6.40-146.el7.x86_64.rpm
sha:76850e69086a4a61830a8476f261b3c162d416ad340df96403e99fbd2667e7a7
-
alt-php56-mcrypt-5.6.40-146.el7.x86_64.rpm
sha:0796fd4d644c8d124bd77c10ee12fd87b6e812b9abfa294cd0b99ca674a4485e
-
alt-php56-mssql-5.6.40-146.el7.x86_64.rpm
sha:693b7271a7fe7347075cbb58313fb0f34370fe862b16ce441c452efc370b080e
-
alt-php56-mysqlnd-5.6.40-146.el7.x86_64.rpm
sha:747acd26ec7580e08fcb4c071040ba48af006392e51283520289ebe4bc6da332
-
alt-php56-odbc-5.6.40-146.el7.x86_64.rpm
sha:81421b008468e23016b750a516c84a50ea965ff4364cbd5fa86ecc6a21f34525
-
alt-php56-opcache-5.6.40-146.el7.x86_64.rpm
sha:a4c0484a60999787a238a472ee9a672da786c03e9663830d40e7249e5c069f86
-
alt-php56-pdo-5.6.40-146.el7.x86_64.rpm
sha:fe2f631ed9283555b1bd8e1b614fec2bfd667e848df9e2f33e79d478a467c472
-
alt-php56-pgsql-5.6.40-146.el7.x86_64.rpm
sha:f84526f450c605b107d48d90cb24694071dbda1918e25c303ac2d3d8ba529547
-
alt-php56-php-fpm-5.6.40-146.el7.x86_64.rpm
sha:414650b904ccd496e3cf11870b53d4f2d67e5c8c1e6e9e86a7eb327c8aaf73c8
-
alt-php56-process-5.6.40-146.el7.x86_64.rpm
sha:c731613128a60bfad1d02d8700fc02801bbc85d9a48c3e42e303313594d7faac
-
alt-php56-pspell-5.6.40-146.el7.x86_64.rpm
sha:c5c2261708a07f0edfbdc42d2c160e3e13f27fb373e791a939b96d3604b78abe
-
alt-php56-recode-5.6.40-146.el7.x86_64.rpm
sha:8917548d8f03da4d4102f2259c4abc1ee9813b74342f3175d099700831bea10f
-
alt-php56-snmp-5.6.40-146.el7.x86_64.rpm
sha:5dc08ce2a38530c7c555909843cf072b0c8b470b34742877025ebdfb166e6281
-
alt-php56-soap-5.6.40-146.el7.x86_64.rpm
sha:d7725d3e021e7eb118e853819eddd918b277249b61d79c5e68b55df86e029315
-
alt-php56-sybase-5.6.40-146.el7.x86_64.rpm
sha:87bab6de8f9c377ad15f1833e3967f406e932c1822f0f65366240b46f26c9305
-
alt-php56-tidy-5.6.40-146.el7.x86_64.rpm
sha:883544519b22d17f586014922cb39c5a8f407fc0833dbc07e9eb3e51e67d5602
-
alt-php56-xml-5.6.40-146.el7.x86_64.rpm
sha:152d96c33d4438f342afc28688b99813c3128f643a585108445507cd16623b8f
-
alt-php56-xmlrpc-5.6.40-146.el7.x86_64.rpm
sha:52f7eb5f68187a8788d0ca2cb032b8b4e71fb9cf6ef5b4d50b657dad5c002948
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.