Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-47750

Опубликовано: 02 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-47750: php:7.4 security, bug fix, and enhancement update (LOW)

libzip php [7.4.33-5]

  • Fix Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD CVE-2026-14355

php-pear php-pecl-apcu php-pecl-rrd php-pecl-xdebug php-pecl-zip

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module php:7.4 is enabled

apcu-panel

5.1.18-1.module+el8.10.0+90472+f810484b

libzip

1.6.1-1.module+el8.10.0+90472+f810484b

libzip-devel

1.6.1-1.module+el8.10.0+90472+f810484b

libzip-tools

1.6.1-1.module+el8.10.0+90472+f810484b

php

7.4.33-5.module+el8.10.0+90978+e272feb1

php-bcmath

7.4.33-5.module+el8.10.0+90978+e272feb1

php-cli

7.4.33-5.module+el8.10.0+90978+e272feb1

php-common

7.4.33-5.module+el8.10.0+90978+e272feb1

php-dba

7.4.33-5.module+el8.10.0+90978+e272feb1

php-dbg

7.4.33-5.module+el8.10.0+90978+e272feb1

php-devel

7.4.33-5.module+el8.10.0+90978+e272feb1

php-embedded

7.4.33-5.module+el8.10.0+90978+e272feb1

php-enchant

7.4.33-5.module+el8.10.0+90978+e272feb1

php-ffi

7.4.33-5.module+el8.10.0+90978+e272feb1

php-fpm

7.4.33-5.module+el8.10.0+90978+e272feb1

php-gd

7.4.33-5.module+el8.10.0+90978+e272feb1

php-gmp

7.4.33-5.module+el8.10.0+90978+e272feb1

php-intl

7.4.33-5.module+el8.10.0+90978+e272feb1

php-json

7.4.33-5.module+el8.10.0+90978+e272feb1

php-ldap

7.4.33-5.module+el8.10.0+90978+e272feb1

php-mbstring

7.4.33-5.module+el8.10.0+90978+e272feb1

php-mysqlnd

7.4.33-5.module+el8.10.0+90978+e272feb1

php-odbc

7.4.33-5.module+el8.10.0+90978+e272feb1

php-opcache

7.4.33-5.module+el8.10.0+90978+e272feb1

php-pdo

7.4.33-5.module+el8.10.0+90978+e272feb1

php-pear

1.10.13-1.module+el8.10.0+90472+f810484b

php-pecl-apcu

5.1.18-1.module+el8.10.0+90472+f810484b

php-pecl-apcu-devel

5.1.18-1.module+el8.10.0+90472+f810484b

php-pecl-rrd

2.0.1-1.module+el8.10.0+90472+f810484b

php-pecl-xdebug

2.9.5-1.module+el8.10.0+90472+f810484b

php-pecl-zip

1.18.2-1.module+el8.10.0+90472+f810484b

php-pgsql

7.4.33-5.module+el8.10.0+90978+e272feb1

php-process

7.4.33-5.module+el8.10.0+90978+e272feb1

php-snmp

7.4.33-5.module+el8.10.0+90978+e272feb1

php-soap

7.4.33-5.module+el8.10.0+90978+e272feb1

php-xml

7.4.33-5.module+el8.10.0+90978+e272feb1

php-xmlrpc

7.4.33-5.module+el8.10.0+90978+e272feb1

Oracle Linux x86_64

Module php:7.4 is enabled

apcu-panel

5.1.18-1.module+el8.10.0+90472+f810484b

libzip

1.6.1-1.module+el8.10.0+90472+f810484b

libzip-devel

1.6.1-1.module+el8.10.0+90472+f810484b

libzip-tools

1.6.1-1.module+el8.10.0+90472+f810484b

php

7.4.33-5.module+el8.10.0+90978+e272feb1

php-bcmath

7.4.33-5.module+el8.10.0+90978+e272feb1

php-cli

7.4.33-5.module+el8.10.0+90978+e272feb1

php-common

7.4.33-5.module+el8.10.0+90978+e272feb1

php-dba

7.4.33-5.module+el8.10.0+90978+e272feb1

php-dbg

7.4.33-5.module+el8.10.0+90978+e272feb1

php-devel

7.4.33-5.module+el8.10.0+90978+e272feb1

php-embedded

7.4.33-5.module+el8.10.0+90978+e272feb1

php-enchant

7.4.33-5.module+el8.10.0+90978+e272feb1

php-ffi

7.4.33-5.module+el8.10.0+90978+e272feb1

php-fpm

7.4.33-5.module+el8.10.0+90978+e272feb1

php-gd

7.4.33-5.module+el8.10.0+90978+e272feb1

php-gmp

7.4.33-5.module+el8.10.0+90978+e272feb1

php-intl

7.4.33-5.module+el8.10.0+90978+e272feb1

php-json

7.4.33-5.module+el8.10.0+90978+e272feb1

php-ldap

7.4.33-5.module+el8.10.0+90978+e272feb1

php-mbstring

7.4.33-5.module+el8.10.0+90978+e272feb1

php-mysqlnd

7.4.33-5.module+el8.10.0+90978+e272feb1

php-odbc

7.4.33-5.module+el8.10.0+90978+e272feb1

php-opcache

7.4.33-5.module+el8.10.0+90978+e272feb1

php-pdo

7.4.33-5.module+el8.10.0+90978+e272feb1

php-pear

1.10.13-1.module+el8.10.0+90472+f810484b

php-pecl-apcu

5.1.18-1.module+el8.10.0+90472+f810484b

php-pecl-apcu-devel

5.1.18-1.module+el8.10.0+90472+f810484b

php-pecl-rrd

2.0.1-1.module+el8.10.0+90472+f810484b

php-pecl-xdebug

2.9.5-1.module+el8.10.0+90472+f810484b

php-pecl-zip

1.18.2-1.module+el8.10.0+90472+f810484b

php-pgsql

7.4.33-5.module+el8.10.0+90978+e272feb1

php-process

7.4.33-5.module+el8.10.0+90978+e272feb1

php-snmp

7.4.33-5.module+el8.10.0+90978+e272feb1

php-soap

7.4.33-5.module+el8.10.0+90978+e272feb1

php-xml

7.4.33-5.module+el8.10.0+90978+e272feb1

php-xmlrpc

7.4.33-5.module+el8.10.0+90978+e272feb1

Связанные CVE

Связанные уязвимости

CVSS3: 5.6
ubuntu
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
redhat
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
nvd
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
msrc
2 месяца назад

ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD

CVSS3: 5.6
debian
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...