Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-49914

Опубликовано: 04 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-49914: php8.4 security, bug fix, and enhancement update (LOW)

[8.4.23-1]

  • rebase to 8.4.23

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

php8.4

8.4.23-1.el10_2

php8.4-bcmath

8.4.23-1.el10_2

php8.4-cli

8.4.23-1.el10_2

php8.4-common

8.4.23-1.el10_2

php8.4-dba

8.4.23-1.el10_2

php8.4-dbg

8.4.23-1.el10_2

php8.4-devel

8.4.23-1.el10_2

php8.4-embedded

8.4.23-1.el10_2

php8.4-enchant

8.4.23-1.el10_2

php8.4-ffi

8.4.23-1.el10_2

php8.4-fpm

8.4.23-1.el10_2

php8.4-gd

8.4.23-1.el10_2

php8.4-gmp

8.4.23-1.el10_2

php8.4-intl

8.4.23-1.el10_2

php8.4-ldap

8.4.23-1.el10_2

php8.4-mbstring

8.4.23-1.el10_2

php8.4-mysqlnd

8.4.23-1.el10_2

php8.4-odbc

8.4.23-1.el10_2

php8.4-opcache

8.4.23-1.el10_2

php8.4-pdo

8.4.23-1.el10_2

php8.4-pgsql

8.4.23-1.el10_2

php8.4-process

8.4.23-1.el10_2

php8.4-snmp

8.4.23-1.el10_2

php8.4-soap

8.4.23-1.el10_2

php8.4-xml

8.4.23-1.el10_2

Oracle Linux x86_64

php8.4

8.4.23-1.el10_2

php8.4-bcmath

8.4.23-1.el10_2

php8.4-cli

8.4.23-1.el10_2

php8.4-common

8.4.23-1.el10_2

php8.4-dba

8.4.23-1.el10_2

php8.4-dbg

8.4.23-1.el10_2

php8.4-devel

8.4.23-1.el10_2

php8.4-embedded

8.4.23-1.el10_2

php8.4-enchant

8.4.23-1.el10_2

php8.4-ffi

8.4.23-1.el10_2

php8.4-fpm

8.4.23-1.el10_2

php8.4-gd

8.4.23-1.el10_2

php8.4-gmp

8.4.23-1.el10_2

php8.4-intl

8.4.23-1.el10_2

php8.4-ldap

8.4.23-1.el10_2

php8.4-mbstring

8.4.23-1.el10_2

php8.4-mysqlnd

8.4.23-1.el10_2

php8.4-odbc

8.4.23-1.el10_2

php8.4-opcache

8.4.23-1.el10_2

php8.4-pdo

8.4.23-1.el10_2

php8.4-pgsql

8.4.23-1.el10_2

php8.4-process

8.4.23-1.el10_2

php8.4-snmp

8.4.23-1.el10_2

php8.4-soap

8.4.23-1.el10_2

php8.4-xml

8.4.23-1.el10_2

Связанные CVE

Связанные уязвимости

CVSS3: 5.6
ubuntu
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
redhat
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
nvd
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
msrc
2 месяца назад

ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD

CVSS3: 5.6
debian
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...