- Description
- In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
- Source
- security@php.net
- NVD status
- Analyzed
- Products
- php, debian_linux
CVSS 3.1
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity
- MEDIUM
- security@php.net
- CWE-122
- Hype score
- Not currently trending
Two PHP flaws are patched. CVE-2026-12184 is a PHP remote DoS that crashes PHP-FPM, and CVE-2026-14355 causes memory corruption. Update PHP now. #PHP #RemoteDoS #DoS #PHPFPM #CyberSecurity #Vulnerability #InfoSec https://t.co/ZfqYjpq9pL
@Daily_CyberSec
6 Jul 2026
611 Impressions
2 Retweets
4 Likes
1 Bookmark
0 Replies
1 Quote
🔒 #CyberSecurity CVE-2026-14355: Debian 12 PHP 8.2 Buffer Overflow — Detection and Remediation G… "A critical memory corruption vulnerability has been identified in the PHP 8.2 package…" 🔗 https://t.co/Syg1i5ACWw #CyberSecurity #ThreatIntel #cve #zeroday #patchtue
@SecurityAr58409
4 Jul 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
"matchCriteriaId": "84838FE7-7252-4A91-B533-6DF96F7638E4",
"versionEndExcluding": "8.2.32",
"versionStartIncluding": "8.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BDE92322-4655-4D52-8130-0CEB76EE18B3",
"versionEndExcluding": "8.3.32",
"versionStartIncluding": "8.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7069BD62-FE98-468E-8BBE-6EE4AAA1770E",
"versionEndExcluding": "8.4.23",
"versionStartIncluding": "8.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
"matchCriteriaId": "594B2AC2-D4EE-47A0-A522-F64240A10583",
"versionEndExcluding": "8.5.8",
"versionStartIncluding": "8.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*",
"matchCriteriaId": "46D69DCC-AE4D-4EA5-861C-D60951444C6C",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]