Описание
In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.
A flaw was found in PHP. The vulnerability occurs due to the malformed php_filter_float() function and leads to a use-after-free vulnerability. This flaw allows an attacker to inject a malicious file, leading to a crash or a Segmentation fault.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | php | Not affected | ||
Red Hat Enterprise Linux 7 | php | Not affected | ||
Red Hat Software Collections | rh-php73-php | Not affected | ||
Red Hat Enterprise Linux 8 | php | Fixed | RHSA-2022:7624 | 08.11.2022 |
Red Hat Enterprise Linux 8 | php | Fixed | RHSA-2022:7628 | 08.11.2022 |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | php | Fixed | RHSA-2025:3076 | 20.03.2025 |
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | php | Fixed | RHSA-2025:3076 | 20.03.2025 |
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | php | Fixed | RHSA-2025:3076 | 20.03.2025 |
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | php | Fixed | RHSA-2025:3016 | 18.03.2025 |
Red Hat Enterprise Linux 8.6 Telecommunications Update Service | php | Fixed | RHSA-2025:3016 | 18.03.2025 |
Показывать по
Дополнительная информация
Статус:
9.8 Critical
CVSS3
Связанные уязвимости
In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.
In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.
In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x belo ...
9.8 Critical
CVSS3