Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-13295

Опубликовано: 10 мая 2026
Источник: fstec
CVSS3: 8.2
CVSS2: 8.5
EPSS Низкий

Описание

Уязвимость функций mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables() и mb_detect_order() интерпретатора языка программирования PHP связана с чтением за границами буфера. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, вызвать аварийное завершение работы приложения

Вендор

ООО «Ред Софт»
Red Hat, Inc.
Сообщество свободного программного обеспечения
PHP Group

Наименование ПО

РЕД ОС
Red Hat Enterprise Linux
Debian GNU/Linux
PHP

Версия ПО

7.3 (РЕД ОС)
10 (Red Hat Enterprise Linux)
13 (Debian GNU/Linux)
8.0 (РЕД ОС)
от 8.4.0 до 8.4.21 (PHP)
от 8.5.0 до 8.5.6 (PHP)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 7.3
Red Hat, Inc. Red Hat Enterprise Linux 10
Сообщество свободного программного обеспечения Debian GNU/Linux 13
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 8,5)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 8,2)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для интерпретатора языка программирования PHP:
https://github.com/php/php-src/security/advisories/GHSA-74r9-qxhc-fx53
Для Red Hat Inc. :
https://access.redhat.com/security/cve/cve-2026-6104
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6104.json
Для программных продуктов Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2026-6104
Для Ред ОС: http://repo.red-soft.ru/redos/7.3c/x86_64/updates/
Для Ред ОС: http://repo.red-soft.ru/redos/8.0/x86_64/updates/

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 39%
0.00469
Низкий

8.2 High

CVSS3

8.5 High

CVSS2

Связанные уязвимости

CVSS3: 9.1
ubuntu
4 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.

CVSS3: 8.2
redhat
4 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.

CVSS3: 9.1
nvd
4 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.

CVSS3: 9.1
debian
4 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an en ...

CVSS3: 7.2
redos
15 дней назад

Уязвимость php 8.5

EPSS

Процентиль: 39%
0.00469
Низкий

8.2 High

CVSS3

8.5 High

CVSS2