PT-2026-98273 · Php · Php

·

CVE-2025-1218

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v3.1

3.4

Low

VectorAV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions php (affected versions not specified)
Description The mysqlnd wire protocol parser reads fields from server packets without first verifying if the packet contains sufficient bytes. This allows a malicious or compromised MySQL server to send a truncated packet, causing the client to read beyond the packet buffer. This undefined behavior can lead to a process crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1218
OPENSUSE-SU-2026:11901-1

Affected Products

Php