Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-17544

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 8.1

Описание

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

A flaw was found in PHP. A remote attacker could exploit this vulnerability by providing specially crafted inputs to the bccomp() function. This could lead to an out-of-bounds write, resulting in stack and heap corruption. Such memory corruption can enable arbitrary code execution, allowing the attacker to take control of the affected system.

Отчет

This is an Important flaw in PHP that could lead to arbitrary code execution due to an out-of-bounds write in the bccomp() function. While exploitation requires high attack complexity, a successful attack could result in stack and heap corruption, potentially compromising the system. This affects PHP 8.4 and 8.5 streams in Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS 2.0.z.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10phpNot affected
Red Hat Enterprise Linux 10php8.4Affected
Red Hat Enterprise Linux 6phpOut of support scope
Red Hat Enterprise Linux 7phpNot affected
Red Hat Enterprise Linux 8php:7.4/phpNot affected
Red Hat Enterprise Linux 8php:8.2/phpNot affected
Red Hat Enterprise Linux 9phpNot affected
Red Hat Enterprise Linux 9php:8.2/phpNot affected
Red Hat Enterprise Linux 9php:8.3/phpNot affected
Red Hat Hardened Imagesphp-main-8.5.9-1.hum1FixedRHSA-2026:4720028.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2509256php: PHP: Arbitrary code execution via out-of-bounds write in bccomp()

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
18 дней назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 9.8
nvd
18 дней назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 9.8
debian
18 дней назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...

github
18 дней назад

Out-of-bounds write in bccomp() via crafted operand and scale

suse-cvrf
12 дней назад

Security update for php8

8.1 High

CVSS3