Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7260

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

A flaw was found in PHP. When processing a specially crafted PHP Archive (phar) file containing circular symbolic links, the PHP process can enter an uncontrolled loop. This unbounded recursion exhausts the program's memory stack, causing the PHP application to crash. This vulnerability could allow an attacker to trigger a Denial of Service (DoS) condition, making the affected PHP service unavailable.

Отчет

This Moderate impact flaw in PHP allows a local attacker to trigger a denial of service by providing a specially crafted phar archive containing circular symbolic links. Successful exploitation exhausts the C stack, leading to a PHP process crash, which can disrupt services utilizing PHP for archive processing.

Меры по смягчению последствий

To mitigate this issue, avoid processing phar archives from untrusted sources. If the phar extension is not essential for your application, consider disabling it in the PHP configuration. Disabling the phar extension may impact applications that rely on it for legitimate archive handling.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10phpFix deferred
Red Hat Enterprise Linux 10php8.4Fix deferred
Red Hat Enterprise Linux 6phpFix deferred
Red Hat Enterprise Linux 7phpFix deferred
Red Hat Enterprise Linux 8php:7.4/phpFix deferred
Red Hat Enterprise Linux 9phpFix deferred
Red Hat Enterprise Linux 9php:8.2/phpFix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9Fix deferred
Red Hat OpenShift Dev Spacesdevspaces/code-rhel9Fix deferred
Red Hat Enterprise Linux 8phpFixedRHSA-2026:5757420.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2509255php: PHP: Denial of Service via circular symbolic links in phar archives

EPSS

Процентиль: 2%
0.00114
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 5.5
nvd
около 2 месяцев назад

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 5.5
msrc
около 1 месяца назад

Stack overflow in phar with circular symlinks

CVSS3: 5.5
debian
около 2 месяцев назад

Circular symbolic links in phar archives could lead to unbounded recur ...

CVSS3: 5.5
github
около 2 месяцев назад

Stack overflow in phar with circular symlinks

EPSS

Процентиль: 2%
0.00114
Низкий

5.5 Medium

CVSS3