[CLSA-2026:1791545067] alt-php71: Fix of CVE-2025-1218
Type:
security
Severity:
Important
Release date:
2026-10-09 11:24:41 UTC
Description:
- CVE-2025-1218: packet over-reads in the mysqlnd wire-protocol parser - the greeting, auth response, OK, EOF, result-set header, result-set field, row and prepare readers decoded fields out of a server packet before checking that the packet still held enough bytes for them, so a malicious or compromised MySQL server could make the client read past the end of the packet buffer, leak heap bytes into user-visible result-set metadata, or allocate and copy a huge attacker-chosen length; php_mysqlnd_net_field_length() and its _ll variant now take the remaining packet size and refuse lengths whose payload is not present, the BAIL_IF_NO_MORE_DATA macro that only noticed an over-read after the fact is replaced by BAIL_IF_NOT_ENOUGH_DATA_EX(n), the unterminated auth-plugin-name branches use memchr() instead of trusting a NUL terminator, and the TIME/DATE/DATETIME prepared-statement readers stop decoding fixed offsets out of a shorter declared length (backport of upstream 114dbb74368e6a6cd6e48ddb4a76dbe8728b84e2, with upstream d37a20c4a24a70dbbcfd8724cd2ad5f1b005bd2a carried as a prerequisite because the fix removes the greeting buffer's NUL terminator; the php_mysqlnd_prepare_read() and php_mysqlnd_sha256_pk_request_response_read() hunks are hardening rather than memory-safety fixes, and the mysqlnd_ps.c hunk is a memory-leak fix on a newly reachable failure path) - Also fixes a pre-existing use-after-free on the row-reader failure path: the CVE-2024-8929 error loops free every field decoded so far without clearing the zvals, and the result set frees them again at teardown. All 3 sites now clear after freeing. Confirmed under AddressSanitizer with the Zend allocator disabled - heap-use-after-free before, clean after, on the three new short-length tests and the nine CVE-2024-8929 stmt-row tests. Upstream still carries the same loops unguarded in php-8.2.34 through php-8.5.11 - The mysqlnd_ps.c hunk additionally releases the result's own connection reference on the prepare-EOF path: before PHP 7.4 (upstream f365d0e00ed9) free_result_contents() did not drop it, so that path leaked one reference
CVEs fixed:
Updated packages:
  • alt-php71-7.1.33-113.el7.x86_64.rpm
    sha:294267f18f1d06f193b614e923e260dc33a11e88e96e8991b1ae467564bddf30
  • alt-php71-bcmath-7.1.33-113.el7.x86_64.rpm
    sha:e4d828ebc0b654f89b8829b4802f358b3f90c836642dc91d6c4aa8546ba00fb1
  • alt-php71-cli-7.1.33-113.el7.x86_64.rpm
    sha:3ee4e242978877d5237eae57f344bccbaf37569583c4f76a4d47170ba8eaf0bf
  • alt-php71-common-7.1.33-113.el7.x86_64.rpm
    sha:6d5f992f96b014981e454190ea12585f6ad6a90f71451d404b160fc9452a2ae3
  • alt-php71-dba-7.1.33-113.el7.x86_64.rpm
    sha:897c64ce658c41f430b48e4cbdd2c0b39a1584ab4a28ef2abfa7a9fefda4f171
  • alt-php71-devel-7.1.33-113.el7.x86_64.rpm
    sha:53096ff03d694dfeef9edc28d8c1c980536b09980a5b3ef880a3d59fb628396c
  • alt-php71-enchant-7.1.33-113.el7.x86_64.rpm
    sha:03a85a87dfd343446c31057d90b58bb8ed6e280ca90417693db3267b43a5fdc1
  • alt-php71-firebird-7.1.33-113.el7.x86_64.rpm
    sha:21e9f605a978d723da5526a1e1195bec92ef051063e939d6c31a388e81aa0276
  • alt-php71-gd-7.1.33-113.el7.x86_64.rpm
    sha:fc2328a1eca33497a3f4f458583c1d31277b4cb1b5e5a261f5b4ec38191c2abe
  • alt-php71-imap-7.1.33-113.el7.x86_64.rpm
    sha:3f90a07b9dc826fe614459f77c0c9e145717b252a0780a34e7b84dfcb83dd06e
  • alt-php71-intl-7.1.33-113.el7.x86_64.rpm
    sha:92d903e7e8f644d2e50a18ac797c96e77888c6d8d43e0efd9f368784d1052183
  • alt-php71-ldap-7.1.33-113.el7.x86_64.rpm
    sha:eb6a39bac287627f31a3583adf6a84661b2a479ab0eb05b2b01714edc3cf7896
  • alt-php71-mbstring-7.1.33-113.el7.x86_64.rpm
    sha:ee0f34954887e2761c26e542dc3ba30cc0cbba1abc1f88ac7db19c3c4b84fd48
  • alt-php71-mcrypt-7.1.33-113.el7.x86_64.rpm
    sha:c53cc2162e8f048fd41f9967e279802f5fb87be1b94c214a037757359bcd263b
  • alt-php71-mysqlnd-7.1.33-113.el7.x86_64.rpm
    sha:102d317b89d2290fb2f7c31bb1105cda59a5efc1b1e332c2641ceb3845f3a395
  • alt-php71-odbc-7.1.33-113.el7.x86_64.rpm
    sha:74be06fdf940300dada334817da2d1e7ed89dd9fea56ca67bef50101682e0ae5
  • alt-php71-opcache-7.1.33-113.el7.x86_64.rpm
    sha:0ee2284c25aebf99f01cec6b33966839ff482a2022391b67bfb46f12a1c73696
  • alt-php71-pdo-7.1.33-113.el7.x86_64.rpm
    sha:13f344fa49547ff926de22cad063ff9bb7cb840351d01e79dcb8c7d6b10ea779
  • alt-php71-pgsql-7.1.33-113.el7.x86_64.rpm
    sha:75d564706c23478fc006b2cd9203fc0cb3a2f3b3223f3abff0b6e96408585cd5
  • alt-php71-php-fpm-7.1.33-113.el7.x86_64.rpm
    sha:ff0c8c03f7afa544aa95aa4535e1f3cb2be22919faf936aaef85157856160ca6
  • alt-php71-process-7.1.33-113.el7.x86_64.rpm
    sha:7fc8fec3da59a03852ce1aa788840d57600fb3436c5d01b4149b6f6da05984c8
  • alt-php71-pspell-7.1.33-113.el7.x86_64.rpm
    sha:8e8d552cf55e6f46d8c5251d697558093cc1bc8fd429382d0a6067ad92e1b7af
  • alt-php71-recode-7.1.33-113.el7.x86_64.rpm
    sha:0e8acc40155455116d21d47572a95ce0fe9cb16bfe9fb0328d6546311b2b757f
  • alt-php71-snmp-7.1.33-113.el7.x86_64.rpm
    sha:03f4e3580aaf3b399932f813d967af2248834e0b321eae3dfb1fd1335847c067
  • alt-php71-soap-7.1.33-113.el7.x86_64.rpm
    sha:06bde357f29bdb4645a56de036e5eb84ee7db1a974f3e6b2dfc506bffea66270
  • alt-php71-tidy-7.1.33-113.el7.x86_64.rpm
    sha:147268591d89e7a77b8a86b0a8b89eaf2631b4d1f3e688821818d4cc65a1c878
  • alt-php71-xml-7.1.33-113.el7.x86_64.rpm
    sha:5e7a41816981a894ef93ce696ce61a242203c35553315d3fd94fccdb67f02db6
  • alt-php71-xmlrpc-7.1.33-113.el7.x86_64.rpm
    sha:cb585f2c539630e6876e4917bbfc4af7b726e053f607cb34d5bd8f89ee44509d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.