Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-1218

Опубликовано: 25 сент. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.

A flaw was found in PHP. The MySQL Native Driver (mysqlnd) wire protocol parser fails to verify that an incoming packet contains enough bytes before reading its fields. A malicious or compromised database server can send a truncated packet, causing the client application to read past the buffer boundary. This issue can lead to a process crash, resulting in a Denial of Service (DoS), or potentially leak sensitive memory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10phpFix deferred
Red Hat Enterprise Linux 10php8.4Fix deferred
Red Hat Enterprise Linux 6phpOut of support scope
Red Hat Enterprise Linux 7phpFix deferred
Red Hat Enterprise Linux 8php:7.4/phpFix deferred
Red Hat Enterprise Linux 8php:8.2/phpFix deferred
Red Hat Enterprise Linux 9phpFix deferred
Red Hat Enterprise Linux 9php:8.2/phpFix deferred
Red Hat Enterprise Linux 9php:8.3/phpFix deferred
Red Hat Enterprise Linux 9php:8.4/phpFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2541655php: php: Denial of Service via out-of-bounds read in mysqlnd wire protocol parser

EPSS

Процентиль: 7%
0.00182
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.4
ubuntu
9 дней назад

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.

CVSS3: 3.4
nvd
9 дней назад

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.

CVSS3: 3.4
msrc
6 дней назад

Various packet overreads in mysqlnd_writeprotocol.c

CVSS3: 3.4
debian
9 дней назад

The mysqlnd wire protocol parser reads fields out of server packets be ...

CVSS3: 3.1
github
10 дней назад

Various packet overreads in mysqlnd_writeprotocol.c

EPSS

Процентиль: 7%
0.00182
Низкий

3.7 Low

CVSS3