CVE-2025-14177

Published Dec 27, 2025

Last updated 2 months ago

Overview

Description
In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.
Source
security@php.net
NVD status
Analyzed
Products
php

Risk scores

CVSS 4.0

Type
Secondary
Base score
6.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

security@php.net
CWE-125

Social media

Hype score
Not currently trending
  1. 🔐 Critical PHP vulnerabilities disclosed in #Ubuntu (USN-7953-1). Affects PHP 7.2-8.4. Can lead to DoS & info disclosure (CVE-2025-14177, -14178, -14180). Read more: 👉 https://t.co/mQvut1U8xr #Security https://t.co/egG6nZrXcT

    @Cezar_H_Linux

    12 Jan 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. After analyzing 92% of vulnerabilities from past week, CVE-2025-14177 has 8 articles published from different internet sources, no other cve has these many articles. More information here: https://t.co/SyyDujjO8C #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    @stooee_

    3 Jan 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. ⚠️ Vulnerabilidades en PHP ❗ CVE-2025-14180 ❗ CVE-2025-14178 ❗ CVE-2025-14177 ➡️ Más info: https://t.co/froC0Srbx0 https://t.co/SqVOorvsPd

    @CERTpy

    24 Dec 2025

    106 Impressions

    2 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. kusanagi-php84 Module Update 8.4.16-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.4.16-1 This update includes support for vulnerability(CVE-2025-14180, CVE-2025-14178, CVE-2025-14177). The module update can... https://t.co/XHrMr8ucpT

    @kusanagi_saya

    22 Dec 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. kusanagi-php85 モジュール更新情報 8.5.1-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.5.1-1

    @kusanagi_saya

    22 Dec 2025

    86 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. URGENT: #Mageia 9 security advisory MGASA-2025-0330 patches high-severity PHP flaws (CVE-2025-14177/78/80). Read more: 👉 https://t.co/i8XBPDb5R6 #Security https://t.co/puT6nk5JJw

    @Cezar_H_Linux

    21 Dec 2025

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.