Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-17544

Опубликовано: 30 июл. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.8

Описание

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

not-affected

code not present
jammy

DNE

noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/xenial

not-affected

code not present
jammy

DNE

noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

not-affected

code not present
jammy

DNE

noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

not-affected

code not present
jammy

DNE

noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

not-affected

code not present
noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

needs-triage

resolute

DNE

upstream

not-affected

code not present

Показывать по

РелизСтатусПримечание
devel

needed

jammy

DNE

noble

DNE

resolute

needed

upstream

needs-triage

Показывать по

EPSS

Процентиль: 42%
0.00522
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
18 дней назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 9.8
nvd
18 дней назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 9.8
debian
18 дней назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...

github
18 дней назад

Out-of-bounds write in bccomp() via crafted operand and scale

suse-cvrf
13 дней назад

Security update for php8

EPSS

Процентиль: 42%
0.00522
Низкий

9.8 Critical

CVSS3