Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7259

Опубликовано: 10 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding().

A flaw was found in PHP. When an attacker input can influence the encoding passed to mb_regex_encoding() and the application subsequently uses mbregex search APIs, a NULL pointer dereference can occur due to a mismatch between the Oniguruma and mbfl encoding support. This issue can cause a crash in the PHP process, resulting in a denial of service.

Отчет

To exploit this issue, an attacker needs to be able to influence the encoding passed to mb_regex_encoding() in a way that triggers a mismatch between the Oniguruma and mbfl encoding support. Also, the application must use the mbregex search APIs, allowing the attacker to cause a NULL pointer dereference. Due to these reasons, this flaw has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, implement an encoding validation mechanism to reject the specific encodings and aliases that cause the mismatch between Oniguruma and mbfl. The following encodings and aliases are known to trigger this issue: iso-8859-11 and ISO8859-11, UJIS (EUC-JP alias), GB-2312 (EUC-CN alias), KOI-8R (KOI8 alias), and US_ASCII or ISO646 (ASCII aliases).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10php8.4Fix deferred
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Enterprise Linux 8php:7.4/phpNot affected
Red Hat Enterprise Linux 8php:8.2/phpFix deferred
Red Hat Enterprise Linux 9php:8.2/phpFix deferred
Red Hat Enterprise Linux 9php:8.3/phpFix deferred
Red Hat Hardened ImagesphpNot affected
Red Hat Enterprise Linux 10phpFixedRHSA-2026:2338804.06.2026
Red Hat Enterprise Linux 9phpFixedRHSA-2026:3344930.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2468564php: NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()

EPSS

Процентиль: 10%
0.00202
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding().

CVSS3: 6.5
nvd
3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding().

msrc
около 2 месяцев назад

Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()

CVSS3: 6.5
debian
3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

github
3 месяца назад

Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()

EPSS

Процентиль: 10%
0.00202
Низкий

6.5 Medium

CVSS3