Opened 2 months ago
Closed 2 months ago
#23607 closed enhancement (fixed)
php-8.5.8
| Reported by: | Joe Locash | Owned by: | Bruce Dubbs |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version. Fixes CVE-2026-14355. See https://www.php.net/ChangeLog-8.php for changes.
Change History (4)
comment:1 by , 2 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 2 months ago
comment:3 by , 2 months ago
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
NIST CVSS Base Score: 5.3 MEDIUM
comment:4 by , 2 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at commits
0f21bc3a63 Update to php-8.5.8. Advisory sa-13.0-142. e2f5bfb1e4 Update to xfsprogs-7.1.1.
Note:
See TracTickets
for help on using tickets.

02 Jul 2026, PHP 8.5.8