Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6722

Опубликовано: 10 мая 2026
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

A flaw was found in PHP's SOAP extension. This vulnerability allows a remote attacker to execute arbitrary code on the affected system. The issue stems from a use-after-free error in the object deduplication mechanism, which can be triggered by sending a specially crafted SOAP request. This allows an attacker to manipulate memory and achieve remote code execution.

Отчет

Red Hat systems which are operating as documented will not be running a PHP application in the root user context and so they will restrict the code execution to the context of the current working user. The host system may be affected by resource allocation induced by an attacker, but the impact will not be total.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6phpOut of support scope
Red Hat Enterprise Linux 7phpAffected
Red Hat Enterprise Linux 10php8.4FixedRHSA-2026:2264902.06.2026
Red Hat Enterprise Linux 10phpFixedRHSA-2026:2338804.06.2026
Red Hat Enterprise Linux 8phpFixedRHSA-2026:2230501.06.2026
Red Hat Enterprise Linux 8phpFixedRHSA-2026:3435401.07.2026
Red Hat Enterprise Linux 9phpFixedRHSA-2026:2214201.06.2026
Red Hat Enterprise Linux 9phpFixedRHSA-2026:2214301.06.2026
Red Hat Enterprise Linux 9phpFixedRHSA-2026:3344930.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2468560php: php-soap: php-src: PHP SOAP extension: Remote Code Execution via use-after-free vulnerability

EPSS

Процентиль: 56%
0.00894
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

CVSS3: 9.8
nvd
3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

msrc
2 месяца назад

Use-After-Free in SOAP using Apache map

CVSS3: 9.8
debian
3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

github
3 месяца назад

Use-After-Free in SOAP using Apache map with Remote Code Execution

EPSS

Процентиль: 56%
0.00894
Низкий

7.7 High

CVSS3