PT-2026-105146 · Bitnami · Php-Min

Published

2026-10-01

·

Updated

2026-10-01

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
php openssl matches wildcard name() in ext/openssl/xp ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify peer name is enabled by default.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-PHP-MIN-2026-91767

Affected Products

Php-Min