Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:40416

Опубликовано: 14 авг. 2026
Источник: rocky
Оценка: Low

Описание

Low: php:8.2 security, bug fix, and enhancement update

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.

Security Fix(es):

  • php: PHP OpenSSL extension: Denial of Service due to buffer allocation flaw in AES-WRAP-PAD (CVE-2026-14355)

Bug Fix(es) and Enhancement(s):

  • Rebase PHP to 8.2.32 for CVE-2026-14355 in 9.8.z (JIRA:Rocky Linux-192622)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
apcu-panelnoarch1.module+el9.7.0+40004+bf50a568apcu-panel-5.1.23-1.module+el9.7.0+40004+bf50a568.noarch.rpm
apcu-panelnoarch1.module+el9.7.0+40005+715283ecapcu-panel-5.1.23-1.module+el9.7.0+40005+715283ec.noarch.rpm
phpaarch641.module+el9.8.0+40254+a2d3a842php-8.2.32-1.module+el9.8.0+40254+a2d3a842.aarch64.rpm
php-bcmathaarch641.module+el9.8.0+40254+a2d3a842php-bcmath-8.2.32-1.module+el9.8.0+40254+a2d3a842.aarch64.rpm
php-cliaarch641.module+el9.8.0+40254+a2d3a842php-cli-8.2.32-1.module+el9.8.0+40254+a2d3a842.aarch64.rpm
php-commonaarch641.module+el9.8.0+40254+a2d3a842php-common-8.2.32-1.module+el9.8.0+40254+a2d3a842.aarch64.rpm
php-dbaaarch641.module+el9.8.0+40254+a2d3a842php-dba-8.2.32-1.module+el9.8.0+40254+a2d3a842.aarch64.rpm
php-dbgaarch641.module+el9.8.0+40254+a2d3a842php-dbg-8.2.32-1.module+el9.8.0+40254+a2d3a842.aarch64.rpm
php-develaarch641.module+el9.8.0+40254+a2d3a842php-devel-8.2.32-1.module+el9.8.0+40254+a2d3a842.aarch64.rpm
php-embeddedaarch641.module+el9.8.0+40254+a2d3a842php-embedded-8.2.32-1.module+el9.8.0+40254+a2d3a842.aarch64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.6
ubuntu
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
redhat
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
nvd
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
msrc
2 месяца назад

ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD

CVSS3: 5.6
debian
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...