Описание
Various packet overreads in mysqlnd_writeprotocol.c
Summary
The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.
Details
BAIL_IF_NO_MORE_DATA only guarantees that a single byte remains, but several call sites then read two or more bytes before re-checking. For example, the 2-byte read here happens before the over-read is detected:
The same pattern occurs in the greeting, OK, EOF, auth-switch, cached-sha2, change-user, result-set header, prepared-statement response and row packet handlers. In addition, php_mysqlnd_net_field_length() and php_mysqlnd_net_field_length_ll() decode a length-encoded integer whose first byte selects a 3, 4 or 9 byte form, and read that many bytes without confirming they are present, so they can read 1 to 9 bytes out of bounds.
The fix replaces the single-byte guard with BAIL_IF_NOT_ENOUGH_DATA_EX(n), which checks the exact number of bytes each read needs, and gives both field-length helpers a remaining_size argument so they return MYSQLND_INVALID_NET_FIELD_LENGTH instead of reading beyond the packet.
PoC
The regression tests added with the fix drive a fake MySQL server that emits truncated packets for each affected handler, for example ext/mysqli/tests/ghsa-r6x9-5r99-36j7-greet-packet.phpt and ext/mysqli/tests/ghsa-r6x9-5r99-36j7-ok-packet-affected-rows.phpt. Running them against an unpatched build under AddressSanitizer reports the out-of-bounds reads.
Impact
Applications connecting to an untrusted or compromised MySQL server can be crashed, giving a denial of service. The bytes read past the buffer influence parsed field values but are not returned to the server, and the reads stay within the process heap. Applications that only connect to trusted database servers are not exposed.
Пакеты
php
>=8.2.0, <8.2.34
8.2.34
php
>=8.3.0, <8.3.35
8.3.35
php
>=8.4.0, <8.4.26
8.4.26
php
>=8.5.0, <8.5.11
8.5.11
Связанные уязвимости
The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.
The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.
The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.
The mysqlnd wire protocol parser reads fields out of server packets be ...