Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6x9-5r99-36j7

Опубликовано: 24 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

Various packet overreads in mysqlnd_writeprotocol.c

Summary

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.

Details

BAIL_IF_NO_MORE_DATA only guarantees that a single byte remains, but several call sites then read two or more bytes before re-checking. For example, the 2-byte read here happens before the over-read is detected:

https://github.com/php/php-src/blob/8b682743196e765debb5056e56a97a67304f5e62/ext/mysqlnd/mysqlnd_wireprotocol.c#L871-L877

The same pattern occurs in the greeting, OK, EOF, auth-switch, cached-sha2, change-user, result-set header, prepared-statement response and row packet handlers. In addition, php_mysqlnd_net_field_length() and php_mysqlnd_net_field_length_ll() decode a length-encoded integer whose first byte selects a 3, 4 or 9 byte form, and read that many bytes without confirming they are present, so they can read 1 to 9 bytes out of bounds.

The fix replaces the single-byte guard with BAIL_IF_NOT_ENOUGH_DATA_EX(n), which checks the exact number of bytes each read needs, and gives both field-length helpers a remaining_size argument so they return MYSQLND_INVALID_NET_FIELD_LENGTH instead of reading beyond the packet.

PoC

The regression tests added with the fix drive a fake MySQL server that emits truncated packets for each affected handler, for example ext/mysqli/tests/ghsa-r6x9-5r99-36j7-greet-packet.phpt and ext/mysqli/tests/ghsa-r6x9-5r99-36j7-ok-packet-affected-rows.phpt. Running them against an unpatched build under AddressSanitizer reports the out-of-bounds reads.

Impact

Applications connecting to an untrusted or compromised MySQL server can be crashed, giving a denial of service. The bytes read past the buffer influence parsed field values but are not returned to the server, and the reads stay within the process heap. Applications that only connect to trusted database servers are not exposed.

Пакеты

Наименование

php

php
Затронутые версииВерсия исправления

>=8.2.0, <8.2.34

8.2.34

Наименование

php

php
Затронутые версииВерсия исправления

>=8.3.0, <8.3.35

8.3.35

Наименование

php

php
Затронутые версииВерсия исправления

>=8.4.0, <8.4.26

8.4.26

Наименование

php

php
Затронутые версииВерсия исправления

>=8.5.0, <8.5.11

8.5.11

EPSS

Процентиль: 7%
0.00182
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.4
ubuntu
9 дней назад

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.

CVSS3: 3.7
redhat
9 дней назад

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.

CVSS3: 3.4
nvd
9 дней назад

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.

CVSS3: 3.4
msrc
6 дней назад

Various packet overreads in mysqlnd_writeprotocol.c

CVSS3: 3.4
debian
9 дней назад

The mysqlnd wire protocol parser reads fields out of server packets be ...

EPSS

Процентиль: 7%
0.00182
Низкий

3.1 Low

CVSS3