[CLSA-2026:1791462081] alt-php56: Fix of CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-09 06:07:12 UTC
Description:
- CVE-2025-1218: various out-of-bounds reads in the mysqlnd wire-protocol parser (ext/mysqlnd/mysqlnd_wireprotocol.c, mysqlnd_wireprotocol.h, mysqlnd_ps_codec.c, mysqlnd_ps.c; GHSA-r6x9-5r99-36j7). The parser read fields out of a server packet before checking that the packet still held enough bytes, so a malicious or compromised MySQL server could make the client read past the end of the packet buffer. Backport of upstream commit 114dbb74368e: BAIL_IF_NO_MORE_DATA, which noticed an over-read only after it had happened, is replaced by the BAIL_PREMATURE_END / BAIL_IF_NOT_ENOUGH_DATA_EX family; php_mysqlnd_net_field_length() and its _ll() variant take the remaining packet size and report MYSQLND_INVALID_NET_FIELD_LENGTH instead of blindly consuming 2, 3 or 8 bytes; the server version and the auth-switch plugin names are located with memchr() over the remaining bytes instead of strdup()/strlen(); and the greeting's fixed block and extended scramble, the result-set field metadata lengths, the in-row EOF marker, the text-protocol field lengths and the declared lengths of TIME/DATE/DATETIME all gain real bounds checks. - Prerequisite note: the CVE-2024-8929 backport already on this branch is what supplies the three mysqlnd_ps_codec.c over-read helpers, the packet_end guard and the fake_server.inc test harness that upstream's change builds on; none of it is in the 5.6.40 tarball. - php-5.6.40-caching-sha2-password.patch introduces php_mysqlnd_cached_sha2_result_read() here, so both of its over-reads are live and are fixed: an unbounded stack over-read of the auth-switch plugin name off a 2048-byte buffer that nothing NUL-terminates (whose result is handed to the caller, with a length that underflows into a large emalloc/memcpy), and a one-byte read past a one-byte packet for the second response code. This patch is therefore applied after the caching-sha2 patch, not alongside the other CVE patches. - The greeting's authentication plugin name is still read with an unbounded estrdup() on 5.6.40, so php-8.1.34's bounded form is carried as a prerequisite before upstream's removal of the "buf[header.size] = 0" hack, which on its own would have turned a terminated read into an unbounded one. - Honest scope: php_mysqlnd_prepare_read() and php_mysqlnd_sha256_pk_request_response_read() are hardening, not memory-safety fixes - behind the existing PREPARE_RESPONSE_SIZE gate the new prepare_read checks cannot fire - and the mysqlnd_ps.c hunk is a leak fix on the newly reachable failure path, not an over-read. - Not applicable on this branch: upstream's guard around MARIADB_RPL_VERSION_HACK, which does not exist here. Upstream's rejection of any "def" value in the result-set field packet is deliberately not taken, because COM_FIELD_LIST is still supported on 5.6; the existing def bounds check is kept and only given the remaining size. - Upstream's 38 regression tests are NOT carried: they drive the dynamic-port fake server upstream added in the same commit, while the harness this branch has (ext/mysqli/tests/fake_server.inc, from the CVE-2024-8929 backport) binds a fixed port, so carrying them means rewriting all 38 and dropping the address assertion. Nothing would run them either way - the spec runselftest toggle defaults to 0 and debian/rules runs no suite. They were run locally instead, on a tree built from this repository's own patch series, first patched and then with only the C hunks of this patch reversed out and rebuilt: 32 of 38 pass patched / 0 fail, against 8 of 38 pass unpatched / 24 fail. The 6 skips in both arms are the cached-sha2 and sha256-pk tests, which need an ext/openssl this build did not have, PHP 5.6's openssl extension not compiling against OpenSSL 3 - The same mysqlnd_ps.c hunk also corrects that path's result free from mnd_efree() to upstream's php-7.0 form, mnd_pefree(stmt->result, stmt->result->persistent): mysqlnd_result_init() allocates the result with mnd_pecalloc(..., persistent), so on a persistent connection the Zend allocator was being handed a malloc()ed block. Before the change a hostile prepare over p:127.0.0.1 aborts with "zend_mm_heap corrupted" on a build with the Zend MM heap checks compiled in; after it the same run completes, and a non-persistent connection is unaffected either way - Also fixes a pre-existing use-after-free on the row-reader failure path: the CVE-2024-8929 error loops free every field decoded so far without clearing the zvals, and the result set frees them again at teardown. All 2 sites now clear after freeing. Confirmed under AddressSanitizer with the Zend allocator disabled - heap-use-after-free before, clean after, on the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11 - The mysqlnd_ps.c hunk additionally releases the result's own connection reference on the prepare-EOF path: before PHP 7.4 (upstream f365d0e00ed9) free_result_contents() did not drop it, so that path leaked one reference - mysqlnd: initialise every pre-allocated row field before decoding (php-5.6.40-mysqlnd-rowp-init-fields.patch). The row readers pre-allocate a zval per column with MAKE_STD_ZVAL(), which sets no type, and only type it when the decode loop reaches that column; the CVE-2024-8929 error paths abandon a row part-way, leaving the rest allocated but never typed, and the result set still frees the whole row at teardown. Each column is now ZVAL_NULL()ed at allocation. Verified with valgrind under USE_ZEND_ALLOC=0. PHP 5 only, and kept separate from the CVE patch because the defect predates it and is reachable without it
CVEs fixed:
Updated packages:
  • alt-php56-5.6.40-146.el7.x86_64.rpm
    sha:f4ab1e3de06a960d26f3cfa0891b757d125a5e388480bb0733a0e5ec2c1ec8c6
  • alt-php56-bcmath-5.6.40-146.el7.x86_64.rpm
    sha:64f447e51a23ef7f474d5aaa6d0914b41135253e066f8936bcb8678fa19bb777
  • alt-php56-cli-5.6.40-146.el7.x86_64.rpm
    sha:6d6e8d00a52e1e51b6fe5deb0b85d549da2d4b2640ab4257058408df5218fedd
  • alt-php56-common-5.6.40-146.el7.x86_64.rpm
    sha:b9fae7b0d39d2662c945b243ab4f8443234445c87a8748d9b8189556f5349a88
  • alt-php56-dba-5.6.40-146.el7.x86_64.rpm
    sha:ce792c7ac38ae9502265f90dac3256190b6dfcde5882a7143b35fdb9ec116921
  • alt-php56-dbx-5.6.40-146.el7.x86_64.rpm
    sha:8d75cb5416f090a5e6370f923b00d038d658ca520640e77e48ff05244dabc6dc
  • alt-php56-devel-5.6.40-146.el7.x86_64.rpm
    sha:d99dab8f22a199050317b4325df7ef13199554e5f639649c0036ad659a5895fd
  • alt-php56-enchant-5.6.40-146.el7.x86_64.rpm
    sha:c73adc820f246526a0dce1cb3ca3d2809271e5938d06c7395c1c1df997b07110
  • alt-php56-firebird-5.6.40-146.el7.x86_64.rpm
    sha:fad887e3be3725eb89b5ef2d6f89ccb434a6e1d795855583b7370bbc1927a192
  • alt-php56-gd-5.6.40-146.el7.x86_64.rpm
    sha:8d7fa3ebba624a0515aaa32a7c7b7886c8d582281b92350fcdfb328a20c3534a
  • alt-php56-imap-5.6.40-146.el7.x86_64.rpm
    sha:2c83f8b21974d809110ab9b9133f0c59dee4e6a1ed4be29c9e55ef03a6dc1c0f
  • alt-php56-intl-5.6.40-146.el7.x86_64.rpm
    sha:254db05c1c4e1c39490dbdf3209b2fac74ee0383a3720bebf30c990f37202a49
  • alt-php56-ldap-5.6.40-146.el7.x86_64.rpm
    sha:1c51bdfa2b768bf115347c92ce6ef90b45a689c0d7e101da18b718be345fc407
  • alt-php56-mbstring-5.6.40-146.el7.x86_64.rpm
    sha:76850e69086a4a61830a8476f261b3c162d416ad340df96403e99fbd2667e7a7
  • alt-php56-mcrypt-5.6.40-146.el7.x86_64.rpm
    sha:0796fd4d644c8d124bd77c10ee12fd87b6e812b9abfa294cd0b99ca674a4485e
  • alt-php56-mssql-5.6.40-146.el7.x86_64.rpm
    sha:693b7271a7fe7347075cbb58313fb0f34370fe862b16ce441c452efc370b080e
  • alt-php56-mysqlnd-5.6.40-146.el7.x86_64.rpm
    sha:747acd26ec7580e08fcb4c071040ba48af006392e51283520289ebe4bc6da332
  • alt-php56-odbc-5.6.40-146.el7.x86_64.rpm
    sha:81421b008468e23016b750a516c84a50ea965ff4364cbd5fa86ecc6a21f34525
  • alt-php56-opcache-5.6.40-146.el7.x86_64.rpm
    sha:a4c0484a60999787a238a472ee9a672da786c03e9663830d40e7249e5c069f86
  • alt-php56-pdo-5.6.40-146.el7.x86_64.rpm
    sha:fe2f631ed9283555b1bd8e1b614fec2bfd667e848df9e2f33e79d478a467c472
  • alt-php56-pgsql-5.6.40-146.el7.x86_64.rpm
    sha:f84526f450c605b107d48d90cb24694071dbda1918e25c303ac2d3d8ba529547
  • alt-php56-php-fpm-5.6.40-146.el7.x86_64.rpm
    sha:414650b904ccd496e3cf11870b53d4f2d67e5c8c1e6e9e86a7eb327c8aaf73c8
  • alt-php56-process-5.6.40-146.el7.x86_64.rpm
    sha:c731613128a60bfad1d02d8700fc02801bbc85d9a48c3e42e303313594d7faac
  • alt-php56-pspell-5.6.40-146.el7.x86_64.rpm
    sha:c5c2261708a07f0edfbdc42d2c160e3e13f27fb373e791a939b96d3604b78abe
  • alt-php56-recode-5.6.40-146.el7.x86_64.rpm
    sha:8917548d8f03da4d4102f2259c4abc1ee9813b74342f3175d099700831bea10f
  • alt-php56-snmp-5.6.40-146.el7.x86_64.rpm
    sha:5dc08ce2a38530c7c555909843cf072b0c8b470b34742877025ebdfb166e6281
  • alt-php56-soap-5.6.40-146.el7.x86_64.rpm
    sha:d7725d3e021e7eb118e853819eddd918b277249b61d79c5e68b55df86e029315
  • alt-php56-sybase-5.6.40-146.el7.x86_64.rpm
    sha:87bab6de8f9c377ad15f1833e3967f406e932c1822f0f65366240b46f26c9305
  • alt-php56-tidy-5.6.40-146.el7.x86_64.rpm
    sha:883544519b22d17f586014922cb39c5a8f407fc0833dbc07e9eb3e51e67d5602
  • alt-php56-xml-5.6.40-146.el7.x86_64.rpm
    sha:152d96c33d4438f342afc28688b99813c3128f643a585108445507cd16623b8f
  • alt-php56-xmlrpc-5.6.40-146.el7.x86_64.rpm
    sha:52f7eb5f68187a8788d0ca2cb032b8b4e71fb9cf6ef5b4d50b657dad5c002948
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.