Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-92842

Опубликовано: 25 сент. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.

A flaw was found in PHP. When processing certain conversion stream filters with line-break settings containing a null byte, the filter duplicates the string but retains the original length rather than the truncated size. An attacker who can influence filter options could exploit this out-of-bounds read, leading to information disclosure by leaking sensitive heap memory contents into the output stream.

Отчет

This vulnerability is rated as Moderate severity because exploitation requires an application to process untrusted input that controls specific stream filter configuration parameters, namely line-break character options containing null bytes. In standard Red Hat Enterprise Linux deployments, applications rarely expose filter instantiation parameters directly to unauthenticated external users. While an out-of-bounds read can leak adjacent memory data into the processed stream, it does not enable arbitrary code execution or system modification.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10phpFix deferred
Red Hat Enterprise Linux 10php8.4Fix deferred
Red Hat Enterprise Linux 6phpOut of support scope
Red Hat Enterprise Linux 7phpFix deferred
Red Hat Enterprise Linux 8php:7.4/phpFix deferred
Red Hat Enterprise Linux 8php:8.2/phpFix deferred
Red Hat Enterprise Linux 9phpFix deferred
Red Hat Enterprise Linux 9php:8.2/phpFix deferred
Red Hat Enterprise Linux 9php:8.3/phpFix deferred
Red Hat Enterprise Linux 9php:8.4/phpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2541662php: php: Information disclosure via out-of-bounds read in stream filters

EPSS

Процентиль: 27%
0.00357
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
8 дней назад

The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.

CVSS3: 5.9
nvd
8 дней назад

The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.

CVSS3: 5.9
msrc
5 дней назад

OOB read / info leak in convert.* stream filters when line-break-chars contains NUL

CVSS3: 5.9
debian
8 дней назад

The convert.base64-encode, convert.quoted-printable-encode and convert ...

CVSS3: 5.9
github
9 дней назад

OOB read / info leak in convert.* stream filters when line-break-chars contains NUL

EPSS

Процентиль: 27%
0.00357
Низкий

5.9 Medium

CVSS3