{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-1218","assignerOrgId":"dd77f84a-d19a-4638-8c3d-a322d820ed2b","state":"PUBLISHED","assignerShortName":"php","dateReserved":"2025-02-11T04:49:52.603Z","datePublished":"2026-09-25T20:48:21.777Z","dateUpdated":"2026-09-28T13:31:31.774Z"},"containers":{"cna":{"providerMetadata":{"orgId":"dd77f84a-d19a-4638-8c3d-a322d820ed2b","shortName":"php","dateUpdated":"2026-09-25T20:48:21.777Z"},"title":"Various packet overreads in mysqlnd_writeprotocol.c","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-122","description":"CWE-122 Heap-based buffer overflow","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-100","descriptions":[{"lang":"en","value":"CAPEC-100 Overflow Buffers"}]}],"affected":[{"vendor":"PHP Group","product":"PHP","packageName":"ext-mysqlnd","versions":[{"status":"affected","version":"8.2.*","lessThan":"8.2.34","versionType":"semver"},{"status":"affected","version":"8.3.*","lessThan":"8.3.35","versionType":"semver"},{"status":"affected","version":"8.4.*","lessThan":"8.4.26","versionType":"semver"},{"status":"affected","version":"8.5.*","lessThan":"8.5.11","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.</p>"}]}],"references":[{"url":"https://github.com/php/php-src/security/advisories/GHSA-r6x9-5r99-36j7","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseSeverity":"LOW","baseScore":3.4,"vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N"}}],"credits":[{"lang":"en","value":"Nora Dossche","type":"reporter"},{"lang":"en","value":"@bao00065 (GitHub)","type":"reporter"},{"lang":"en","value":"@cxxz16 (GitHub)","type":"reporter"},{"lang":"en","value":"@TristanInSec (GitHub)","type":"reporter"},{"lang":"en","value":"@OSTIF-Derek (GitHub)","type":"reporter"},{"lang":"en","value":"@HO-9 (GitHub)","type":"reporter"},{"lang":"en","value":"Jakub Zelenka","type":"remediation developer"},{"lang":"en","value":"Nora Dossche","type":"remediation developer"},{"lang":"en","value":"Alexandre Daubois","type":"analyst"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2025-1218","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-09-28T12:56:30.325753Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-28T13:31:31.774Z"}}]}}