Описание
The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.
A flaw was found in PHP. The access control check for Internet Protocol version 6 (IPv6) addresses in the FastCGI implementation compares only the first 12 bytes of a 16-byte address instead of the complete address. An attacker on an adjacent network with an address sharing the first 96 bits with an authorized client can bypass network access restrictions to reach the FastCGI endpoint, potentially leading to unauthorized information disclosure.
Отчет
This vulnerability is rated as having a Moderate impact because exploitation requires PHP-FPM to be configured to listen on an IPv6 network socket, whereas Red Hat Enterprise Linux configurations typically use local UNIX domain sockets or loopback interfaces. Furthermore, an attacker must be located on an adjacent network capable of sourcing an IPv6 address sharing the first 96 bits with an authorized client. Systems communicating strictly through local UNIX sockets or isolated via network filtering are not exposed to unauthorized FastCGI access.
Меры по смягчению последствий
Configure PHP-FPM to communicate over a local UNIX domain socket or enforce IPv6 access controls using host-based firewall rules.
- Local UNIX domain socket configuration (for deployments where the web server and PHP-FPM reside on the same host):
Edit
/etc/php-fpm.d/www.confto set: listen = /run/php-fpm/www.sock Configure the upstream web server (such as Apache HTTP Server or NGINX) to route FastCGI requests via the UNIX socket path instead of TCP. Apply the configuration by restarting the service: systemctl restart php-fpm - Firewall filtering (if PHP-FPM must listen over a TCP network port): Restrict access to the FastCGI port using firewalld to ensure exact 128-bit IPv6 address matching: firewall-cmd --permanent --add-rich-rule='rule family="ipv6" source address="<ALLOWED_IPV6_HOST>/128" port port="9000" protocol="tcp" accept' firewall-cmd --reload Caveats: Switching to a UNIX domain socket requires aligning FastCGI proxy parameters in the upstream web server. Applying firewall rules may block legitimate traffic if authorized client IPv6 addresses change dynamically. Warning: Restarting php-fpm will terminate active FastCGI connections and temporarily disrupt processing of PHP requests.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | php | Fix deferred | ||
| Red Hat Enterprise Linux 10 | php8.4 | Fix deferred | ||
| Red Hat Enterprise Linux 6 | php | Out of support scope | ||
| Red Hat Enterprise Linux 7 | php | Fix deferred | ||
| Red Hat Enterprise Linux 8 | php:7.4/php | Fix deferred | ||
| Red Hat Enterprise Linux 8 | php:8.2/php | Fix deferred | ||
| Red Hat Enterprise Linux 9 | php | Fix deferred | ||
| Red Hat Enterprise Linux 9 | php:8.2/php | Fix deferred | ||
| Red Hat Enterprise Linux 9 | php:8.3/php | Fix deferred | ||
| Red Hat Enterprise Linux 9 | php:8.4/php | Fix deferred |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.
The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.
IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)
The IPv6 branch of the FastCGI client access check compares only the f ...
IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)
6.5 Medium
CVSS3