PT-2026-55488 · Php+4 · Php+4

·

CVE-2026-14355

·

Published

2026-07-02

·

Updated

2026-09-02

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PHP versions 8.2.0 through 8.2.31 PHP versions 8.3.0 through 8.3.31 PHP versions 8.4.0 through 8.4.22 PHP versions 8.5.0 through 8.5.7
Description The OpenSSL extension contains a buffer allocation flaw in the AES-WRAP-PAD algorithm implementation. The output buffer for the AES key-wrap-with-padding operation is sized based on the plaintext length but fails to account for RFC 5649 expansion. This can lead to writing beyond the allocated memory, which corrupts heap metadata and may cause the application to abort. This issue occurs within the openssl encrypt() function.
Recommendations Update PHP version 8.2.x to 8.2.32 Update PHP version 8.3.x to 8.3.32 Update PHP version 8.4.x to 8.4.23 Update PHP version 8.5.x to 8.5.8

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:40416
ALSA-2026:47749
ALSA-2026:47750
ALSA-2026:48170
ALSA-2026:48197
ALSA-2026:49914
ALSA-2026:61259
AZL-92001
BIT-LIBPHP-2026-14355
BIT-PHP-2026-14355
BIT-PHP-MIN-2026-14355
CVE-2026-14355
OESA-2026-3048
OESA-2026-3049
OESA-2026-3050
OESA-2026-3051
OESA-2026-3052
OPENSUSE-SU-2026:11269-1
OPENSUSE-SU-2026:21308-1
RHSA-2026:34164
RHSA-2026:40416
RHSA-2026:47749
RHSA-2026:47750
RHSA-2026:48170
RHSA-2026:48197
RHSA-2026:49914
RHSA-2026:61259
SUSE-SU-2026:22635-1
SUSE-SU-2026:3164-1
SUSE-SU-2026:3165-1
SUSE-SU-2026:3514-1
USN-8564-1

Affected Products

Linuxmint
Php
Red Os
Rocky Linux
Ubuntu