Количество 59
Количество 59
RLSA-2026:61259
Low: php security, bug fix, and enhancement update
ELSA-2026-61259-0
ELSA-2026-61259-0: php security, bug fix, and enhancement update (LOW)
SUSE-SU-2026:3514-1
Security update for php8
RLSA-2026:62614
Important: php security, bug fix, and enhancement update
RLSA-2026:62334
Important: php:7.4 security, bug fix, and enhancement update
RLSA-2026:61903
Important: php:8.2 security, bug fix, and enhancement update
RLSA-2026:57574
Important: php:8.2 security, bug fix, and enhancement update
RLSA-2026:57539
Important: php:8.3 security, bug fix, and enhancement update
ELSA-2026-62614-0
ELSA-2026-62614-0: php security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-62334-0
ELSA-2026-62334-0: php:7.4 security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-61903-0
ELSA-2026-61903-0: php:8.2 security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-57574
ELSA-2026-57574: php:8.2 security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-57539
ELSA-2026-57539: php:8.3 security, bug fix, and enhancement update (IMPORTANT)
SUSE-SU-2026:3513-1
Security update for php8
SUSE-SU-2026:3510-1
Security update for php7
SUSE-SU-2026:3509-1
Security update for php8
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
CVE-2026-14355
ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:61259 Low: php security, bug fix, and enhancement update | 14 дней назад | |||
ELSA-2026-61259-0 ELSA-2026-61259-0: php security, bug fix, and enhancement update (LOW) | 11 дней назад | |||
SUSE-SU-2026:3514-1 Security update for php8 | около 1 месяца назад | |||
RLSA-2026:62614 Important: php security, bug fix, and enhancement update | 11 дней назад | |||
RLSA-2026:62334 Important: php:7.4 security, bug fix, and enhancement update | 13 дней назад | |||
RLSA-2026:61903 Important: php:8.2 security, bug fix, and enhancement update | 13 дней назад | |||
RLSA-2026:57574 Important: php:8.2 security, bug fix, and enhancement update | 25 дней назад | |||
RLSA-2026:57539 Important: php:8.3 security, bug fix, and enhancement update | 25 дней назад | |||
ELSA-2026-62614-0 ELSA-2026-62614-0: php security, bug fix, and enhancement update (IMPORTANT) | 13 дней назад | |||
ELSA-2026-62334-0 ELSA-2026-62334-0: php:7.4 security, bug fix, and enhancement update (IMPORTANT) | 13 дней назад | |||
ELSA-2026-61903-0 ELSA-2026-61903-0: php:8.2 security, bug fix, and enhancement update (IMPORTANT) | 13 дней назад | |||
ELSA-2026-57574 ELSA-2026-57574: php:8.2 security, bug fix, and enhancement update (IMPORTANT) | 25 дней назад | |||
ELSA-2026-57539 ELSA-2026-57539: php:8.3 security, bug fix, and enhancement update (IMPORTANT) | 25 дней назад | |||
SUSE-SU-2026:3513-1 Security update for php8 | около 1 месяца назад | |||
SUSE-SU-2026:3510-1 Security update for php7 | около 1 месяца назад | |||
SUSE-SU-2026:3509-1 Security update for php8 | около 1 месяца назад | |||
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD | CVSS3: 5.6 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу