Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-14355

Опубликовано: 03 июл. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.6

Описание

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/xenial

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

released

8.1.2-1ubuntu2.25
noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

released

8.3.6-0ubuntu0.24.04.10
questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

DNE

questing

ignored

end of life, was needs-triage
resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

pending

8.5.4-0ubuntu4
jammy

DNE

noble

DNE

questing

DNE

resolute

released

8.5.4-0ubuntu1.2
upstream

released

8.5.8

Показывать по

EPSS

Процентиль: 20%
0.00279
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
nvd
27 дней назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

msrc
24 дня назад

ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD

CVSS3: 5.6
debian
27 дней назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...

suse-cvrf
9 дней назад

Security update for php7

CVSS3: 4.8
github
28 дней назад

ext/openssl: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD

EPSS

Процентиль: 20%
0.00279
Низкий

5.6 Medium

CVSS3