Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91767

Опубликовано: 25 сент. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.

A flaw was found in PHP. When validating secure connections using Transport Layer Security (TLS), an error in how wildcard domain names in server certificates are verified can lead to an out-of-bounds memory read. A malicious server presenting a specially crafted certificate can exploit this issue against a connecting PHP client. This flaw primarily leads to information disclosure, potentially exposing sensitive data stored in application memory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10phpFix deferred
Red Hat Enterprise Linux 10php8.4Fix deferred
Red Hat Enterprise Linux 6phpOut of support scope
Red Hat Enterprise Linux 7phpFix deferred
Red Hat Enterprise Linux 8php:7.4/phpFix deferred
Red Hat Enterprise Linux 8php:8.2/phpFix deferred
Red Hat Enterprise Linux 9phpFix deferred
Red Hat Enterprise Linux 9php:8.2/phpFix deferred
Red Hat Enterprise Linux 9php:8.3/phpFix deferred
Red Hat Enterprise Linux 9php:8.4/phpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2541652php: php: Information disclosure via crafted TLS server certificate

EPSS

Процентиль: 4%
0.00154
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
9 дней назад

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.

CVSS3: 6.5
nvd
9 дней назад

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.

CVSS3: 6.5
msrc
7 дней назад

Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN

CVSS3: 6.5
debian
9 дней назад

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows ...

CVSS3: 6.5
github
10 дней назад

Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN

EPSS

Процентиль: 4%
0.00154
Низкий

6.5 Medium

CVSS3