Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91768

Опубликовано: 25 сент. 2026
Источник: redhat
CVSS3: 6.5

Описание

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.

A flaw was found in PHP. The access control check for Internet Protocol version 6 (IPv6) addresses in the FastCGI implementation compares only the first 12 bytes of a 16-byte address instead of the complete address. An attacker on an adjacent network with an address sharing the first 96 bits with an authorized client can bypass network access restrictions to reach the FastCGI endpoint, potentially leading to unauthorized information disclosure.

Отчет

This vulnerability is rated as having a Moderate impact because exploitation requires PHP-FPM to be configured to listen on an IPv6 network socket, whereas Red Hat Enterprise Linux configurations typically use local UNIX domain sockets or loopback interfaces. Furthermore, an attacker must be located on an adjacent network capable of sourcing an IPv6 address sharing the first 96 bits with an authorized client. Systems communicating strictly through local UNIX sockets or isolated via network filtering are not exposed to unauthorized FastCGI access.

Меры по смягчению последствий

Configure PHP-FPM to communicate over a local UNIX domain socket or enforce IPv6 access controls using host-based firewall rules.

  1. Local UNIX domain socket configuration (for deployments where the web server and PHP-FPM reside on the same host): Edit /etc/php-fpm.d/www.conf to set: listen = /run/php-fpm/www.sock Configure the upstream web server (such as Apache HTTP Server or NGINX) to route FastCGI requests via the UNIX socket path instead of TCP. Apply the configuration by restarting the service: systemctl restart php-fpm
  2. Firewall filtering (if PHP-FPM must listen over a TCP network port): Restrict access to the FastCGI port using firewalld to ensure exact 128-bit IPv6 address matching: firewall-cmd --permanent --add-rich-rule='rule family="ipv6" source address="<ALLOWED_IPV6_HOST>/128" port port="9000" protocol="tcp" accept' firewall-cmd --reload Caveats: Switching to a UNIX domain socket requires aligning FastCGI proxy parameters in the upstream web server. Applying firewall rules may block legitimate traffic if authorized client IPv6 addresses change dynamically. Warning: Restarting php-fpm will terminate active FastCGI connections and temporarily disrupt processing of PHP requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10phpFix deferred
Red Hat Enterprise Linux 10php8.4Fix deferred
Red Hat Enterprise Linux 6phpOut of support scope
Red Hat Enterprise Linux 7phpFix deferred
Red Hat Enterprise Linux 8php:7.4/phpFix deferred
Red Hat Enterprise Linux 8php:8.2/phpFix deferred
Red Hat Enterprise Linux 9phpFix deferred
Red Hat Enterprise Linux 9php:8.2/phpFix deferred
Red Hat Enterprise Linux 9php:8.3/phpFix deferred
Red Hat Enterprise Linux 9php:8.4/phpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-940
https://bugzilla.redhat.com/show_bug.cgi?id=2541660php: php: Access control bypass via partial IPv6 address comparison

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
9 дней назад

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.

CVSS3: 6.5
nvd
9 дней назад

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.

CVSS3: 6.5
msrc
6 дней назад

IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)

CVSS3: 6.5
debian
9 дней назад

The IPv6 branch of the FastCGI client access check compares only the f ...

CVSS3: 6.5
github
10 дней назад

IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)

6.5 Medium

CVSS3