Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhmq-mmqj-2v39

Опубликовано: 02 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.2

Описание

Failure to setup TLS with a remote server can result in a remote DoS

Summary

In php_stream_url_wrap_http_ex, when TLS crypto setup fails (via php_stream_xport_crypto_setup or php_stream_xport_crypto_enable), the stream is closed and reset to NULL. However, the subsequent peer name cleanup block unconditionally tries to reset the peer name. This is triggerable via a failure to validate the peer name or an expired certificate.

As demonstrated by https://github.com/php/php-src/issues/21468 this is triggerable without requiring specially-crafted code, and with a remote server.

Details

Patch available via https://github.com/php/php-src/pull/21031

Impact

The impact is a remotely-triggerable DoS bringing the entire fpm process down with all its workers.

Additional Information

This was first discovered by a hybrid static-dynamic analyzer I'm developing.

Пакеты

Наименование

php

php
Затронутые версииВерсия исправления

< 8.3.32

8.3.32

Наименование

php

php
Затронутые версииВерсия исправления

< 8.4.21

8.4.21

Наименование

php

php
Затронутые версииВерсия исправления

< 8.5.6

8.5.6

8.2 High

CVSS4

Связанные уязвимости

ubuntu
28 дней назад

PHP: Failure to setup TLS with a remote server can result in a remote DoS

debian

[PHP: Failure to setup TLS with a remote server can result in a remote DoS]

suse-cvrf
18 дней назад

Security update for php8

suse-cvrf
9 дней назад

Security update for php8

8.2 High

CVSS4