Leak partial content of the heap through heap buffer over-read in mysqlnd
Published Nov 22, 2024
5.8
MEDIUMCVSS 3.1
EPSS 2.24%
Description
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.
Affected products
-
- Version 8.1.*StatusaffectedConstraints<8.1.31
- Version 8.2.*StatusaffectedConstraints<8.2.24
- Version 8.3.*StatusaffectedConstraints<8.3.14
- Version
-
- Version 8.1.0StatusaffectedConstraints<8.1.31
- Version 8.2.0StatusaffectedConstraints<8.2.24
- Version 8.3.0StatusaffectedConstraints<8.3.14
- Version
Red Hat Enterprise Linux 8
php:7.4-8100020260119075152.f7998665
Fixed · RHSA-2026:2470
Red Hat Enterprise Linux 8
php:8.2-8100020250903052702.f7998665
Fixed · RHSA-2025:15687
Red Hat Enterprise Linux 9
php-0:8.0.30-2.el9
Fixed · RHSA-2025:7315
Red Hat Enterprise Linux 9
php:8.1-9050020250423093228.9
Fixed · RHSA-2025:4263
Red Hat Enterprise Linux 9
php:8.2-9060020250428130539.9
Fixed · RHSA-2025:7432
Red Hat Enterprise Linux 7
php
Out of support scope
Red Hat Enterprise Linux 8
php:8.0/php
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | php:7.4-8100020260119075152.f7998665 | Fixed | RHSA-2026:2470 |
| Red Hat Enterprise Linux 8 | php:8.2-8100020250903052702.f7998665 | Fixed | RHSA-2025:15687 |
| Red Hat Enterprise Linux 9 | php-0:8.0.30-2.el9 | Fixed | RHSA-2025:7315 |
| Red Hat Enterprise Linux 9 | php:8.1-9050020250423093228.9 | Fixed | RHSA-2025:4263 |
| Red Hat Enterprise Linux 9 | php:8.2-9060020250428130539.9 | Fixed | RHSA-2025:7432 |
| Red Hat Enterprise Linux 7 | php | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | php:8.0/php | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2024-8929 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2327960 Issue Tracking
- https://github.com/php/php-src/security/advisories/GHSA-h35g-vwh6-m678 ExploitVendor Advisory
- https://lists.debian.org/debian-lts-announce/2024/12/msg00007.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-8929
- https://security.netapp.com/advisory/ntap-20250110-0008/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-8929
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-8929 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2327960 | Issue Tracking | |
| https://github.com/php/php-src/security/advisories/GHSA-h35g-vwh6-m678 | ExploitVendor Advisory | |
| https://lists.debian.org/debian-lts-announce/2024/12/msg00007.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2024-8929 | ||
| https://security.netapp.com/advisory/ntap-20250110-0008/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2024-8929 |
Change history (0)
No recorded changes yet.