Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-17544

Опубликовано: 30 июл. 2026
Источник: debian

Описание

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.4fixed8.4.24-1package
php8.2not-affectedpackage
php7.4not-affectedpackage

Примечания

  • https://github.com/php/php-src/security/advisories/GHSA-x692-q9x7-8c3f

  • Fixed by: https://github.com/php/php-src/commit/fa18dab73f9340448c0d5c0a1d75d3fec844b358 (php-8.4.24)

  • Introduced with: https://github.com/php/php-src/commit/063c3c852236ecbe45ab23c0fb271b6292ce82c3 (php-8.4.3RC1)

Связанные уязвимости

CVSS3: 9.8
ubuntu
18 дней назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 8.1
redhat
18 дней назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 9.8
nvd
18 дней назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

github
18 дней назад

Out-of-bounds write in bccomp() via crafted operand and scale

suse-cvrf
13 дней назад

Security update for php8