Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-14181

Опубликовано: 25 сент. 2026
Источник: debian

Описание

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make the client allocate a buffer far smaller than the data it then writes into it, producing a heap buffer overflow.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.4fixed8.4.26-1package
php8.2removedpackage

Примечания

  • https://github.com/php/php-src/security/advisories/GHSA-cj93-vc83-wgqv

  • https://github.com/php/php-src/blob/php-8.4.26/NEWS

Связанные уязвимости

CVSS3: 6.5
ubuntu
8 дней назад

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make the client allocate a buffer far smaller than the data it then writes into it, producing a heap buffer overflow.

CVSS3: 6.5
redhat
8 дней назад

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make the client allocate a buffer far smaller than the data it then writes into it, producing a heap buffer overflow.

CVSS3: 6.5
nvd
8 дней назад

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make the client allocate a buffer far smaller than the data it then writes into it, producing a heap buffer overflow.

CVSS3: 6.5
msrc
4 дня назад

Integer overflow to buffer overflow in soap HTTP parsing

CVSS3: 6.5
github
9 дней назад

Integer overflow to buffer overflow in soap HTTP parsing