Количество 9
Количество 9
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
CVE-2026-14355
ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...
SUSE-SU-2026:3165-1
Security update for php7
GHSA-7jrw-539f-x6vr
ext/openssl: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD
ELSA-2026-40416
ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW)
openSUSE-SU-2026:21308-1
Security update for php8
SUSE-SU-2026:3164-1
Security update for php8
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. | CVSS3: 5.6 | 0% Низкий | 27 дней назад | |
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. | CVSS3: 5.6 | 0% Низкий | 27 дней назад | |
CVE-2026-14355 ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD | 0% Низкий | 24 дня назад | ||
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ... | CVSS3: 5.6 | 0% Низкий | 27 дней назад | |
SUSE-SU-2026:3165-1 Security update for php7 | 0% Низкий | 9 дней назад | ||
GHSA-7jrw-539f-x6vr ext/openssl: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD | CVSS3: 4.8 | 0% Низкий | 28 дней назад | |
ELSA-2026-40416 ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW) | 14 дней назад | |||
openSUSE-SU-2026:21308-1 Security update for php8 | 18 дней назад | |||
SUSE-SU-2026:3164-1 Security update for php8 | 9 дней назад |
Уязвимостей на страницу