Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-17544

Опубликовано: 30 июл. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 8.4.0 (включая) до 8.4.24 (исключая)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 8.5.0 (включая) до 8.5.9 (исключая)

EPSS

Процентиль: 42%
0.00522
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.8
ubuntu
18 дней назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 8.1
redhat
18 дней назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 9.8
debian
18 дней назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...

github
18 дней назад

Out-of-bounds write in bccomp() via crafted operand and scale

suse-cvrf
13 дней назад

Security update for php8

EPSS

Процентиль: 42%
0.00522
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787