Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14355

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 5.6

Описание

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

A flaw was found in the OpenSSL extension of PHP. The AES-WRAP-PAD algorithm implementation uses the size of the plaintext length without accounting for the RFC 5649 expansion to allocate the output buffer for the AES key-wrap-with-padding operation. This may lead to an undersized memory allocation and subsequently a heap-based buffer overflow, causing memory corruption that later is surfaced as an application abort that results in a denial of service.

Отчет

To exploit this issue, an attacker needs to find an application using the AES-WRAP-PAD algorithm. This algorithm is rarely used, limiting the exposure of this vulnerability. Additionally, the memory allocator can detect the heap-based buffer overflow and will abort the process with no other security impact. For these reasons, this issue has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, do not use the AES-WRAP-PAD algorithm, by switching to a secure alternative.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Enterprise Linux 9phpFix deferred
Red Hat Enterprise Linux 9php:8.4/phpNot affected
Red Hat Enterprise Linux 10phpFixedRHSA-2026:4817029.07.2026
Red Hat Enterprise Linux 10php8.4FixedRHSA-2026:4991404.08.2026
Red Hat Enterprise Linux 8phpFixedRHSA-2026:4774930.07.2026
Red Hat Enterprise Linux 8phpFixedRHSA-2026:4775030.07.2026
Red Hat Enterprise Linux 9phpFixedRHSA-2026:4041616.07.2026
Red Hat Enterprise Linux 9phpFixedRHSA-2026:4819731.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2496971php: ext/openssl: memory corruption in openssl_encrypt with AES-WRAP-PAD

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
ubuntu
около 2 месяцев назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
nvd
около 2 месяцев назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

msrc
около 1 месяца назад

ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD

CVSS3: 5.6
debian
около 2 месяцев назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...

suse-cvrf
28 дней назад

Security update for php7

5.6 Medium

CVSS3