Количество 22
Количество 22
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
CVE-2026-14355
ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...
SUSE-SU-2026:3165-1
Security update for php7
RLSA-2026:49914
Low: php8.4 security, bug fix, and enhancement update
RLSA-2026:48197
Low: php:8.3 security, bug fix, and enhancement update
RLSA-2026:48170
Low: php security, bug fix, and enhancement update
RLSA-2026:47750
Low: php:7.4 security, bug fix, and enhancement update
RLSA-2026:47749
Low: php:8.2 security, bug fix, and enhancement update
RLSA-2026:40416
Low: php:8.2 security, bug fix, and enhancement update
GHSA-7jrw-539f-x6vr
ext/openssl: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD
ELSA-2026-49914
ELSA-2026-49914: php8.4 security, bug fix, and enhancement update (LOW)
ELSA-2026-48197
ELSA-2026-48197: php:8.3 security, bug fix, and enhancement update (LOW)
ELSA-2026-48170
ELSA-2026-48170: php security, bug fix, and enhancement update (LOW)
ELSA-2026-47750
ELSA-2026-47750: php:7.4 security, bug fix, and enhancement update (LOW)
ELSA-2026-47749
ELSA-2026-47749: php:8.2 security, bug fix, and enhancement update (LOW)
ELSA-2026-40416
ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW)
openSUSE-SU-2026:21308-1
Security update for php8
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ... | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
SUSE-SU-2026:3165-1 Security update for php7 | 0% Низкий | около 2 месяцев назад | ||
RLSA-2026:49914 Low: php8.4 security, bug fix, and enhancement update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:48197 Low: php:8.3 security, bug fix, and enhancement update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:48170 Low: php security, bug fix, and enhancement update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:47750 Low: php:7.4 security, bug fix, and enhancement update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:47749 Low: php:8.2 security, bug fix, and enhancement update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:40416 Low: php:8.2 security, bug fix, and enhancement update | 0% Низкий | около 1 месяца назад | ||
GHSA-7jrw-539f-x6vr ext/openssl: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD | CVSS3: 4.8 | 0% Низкий | 2 месяца назад | |
ELSA-2026-49914 ELSA-2026-49914: php8.4 security, bug fix, and enhancement update (LOW) | 0% Низкий | около 1 месяца назад | ||
ELSA-2026-48197 ELSA-2026-48197: php:8.3 security, bug fix, and enhancement update (LOW) | 0% Низкий | около 1 месяца назад | ||
ELSA-2026-48170 ELSA-2026-48170: php security, bug fix, and enhancement update (LOW) | 0% Низкий | около 2 месяцев назад | ||
ELSA-2026-47750 ELSA-2026-47750: php:7.4 security, bug fix, and enhancement update (LOW) | 0% Низкий | около 1 месяца назад | ||
ELSA-2026-47749 ELSA-2026-47749: php:8.2 security, bug fix, and enhancement update (LOW) | 0% Низкий | около 1 месяца назад | ||
ELSA-2026-40416 ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW) | 0% Низкий | около 2 месяцев назад | ||
openSUSE-SU-2026:21308-1 Security update for php8 | 2 месяца назад |
Уязвимостей на страницу