CVE-2025-1218

Summary

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.

Affected Software

VendorProductVersion RangeStatus
PHP GroupPHP8.2.* < 8.2.34affected
PHP GroupPHP8.3.* < 8.3.35affected
PHP GroupPHP8.4.* < 8.4.26affected
PHP GroupPHP8.5.* < 8.5.11affected

Weaknesses

  • CWE-122: CWE-122 Heap-based buffer overflow

References