Описание
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
A flaw was found in PHP. A remote attacker could exploit this vulnerability by providing specially crafted inputs to the bccomp() function. This could lead to an out-of-bounds write, resulting in stack and heap corruption. Such memory corruption can enable arbitrary code execution, allowing the attacker to take control of the affected system.
Отчет
This is an Important flaw in PHP that could lead to arbitrary code execution due to an out-of-bounds write in the bccomp() function. While exploitation requires high attack complexity, a successful attack could result in stack and heap corruption, potentially compromising the system. This affects PHP 8.4 and 8.5 streams in Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS 2.0.z.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | php | Not affected | ||
| Red Hat Enterprise Linux 10 | php8.4 | Affected | ||
| Red Hat Enterprise Linux 6 | php | Out of support scope | ||
| Red Hat Enterprise Linux 7 | php | Not affected | ||
| Red Hat Enterprise Linux 8 | php:7.4/php | Not affected | ||
| Red Hat Enterprise Linux 8 | php:8.2/php | Not affected | ||
| Red Hat Enterprise Linux 9 | php | Not affected | ||
| Red Hat Enterprise Linux 9 | php:8.2/php | Not affected | ||
| Red Hat Enterprise Linux 9 | php:8.3/php | Not affected | ||
| Red Hat Hardened Images | php-main-8.5.9-1.hum1 | Fixed | RHSA-2026:47200 | 28.07.2026 |
Показывать по
Дополнительная информация
Статус:
8.1 High
CVSS3
Связанные уязвимости
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...
8.1 High
CVSS3