Skip to content

CVE-2024-8929 mysqlnd: Leak partial content of the heap through heap buffer over-read #26

@remicollet

Description

@remicollet

Fix not backported from 8.1.31

The fix did not apply safely, need some adaptations, and raise segfault in test suite, so more work needed.

Notice: this security flaw requires a specially crafted answer from the server, so is very unlikely to be exploitable in a sane env (using a trusted server)/

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions