PT-2026-66458 · Php · Php

·

CVE-2026-17544

·

Published

2026-07-30

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions 8.4.0 through 8.4.23 PHP versions 8.5.0 through 8.5.8
Description Attacker-provided inputs to the bccomp() function can lead to an out-of-bounds write, resulting in stack and heap corruption. An out-of-bounds write occurs when a program writes data past the end of the intended buffer, potentially overwriting adjacent memory.
Recommendations Update PHP versions 8.4.0 through 8.4.23 to version 8.4.24. Update PHP versions 8.5.0 through 8.5.8 to version 8.5.9. As a temporary workaround, restrict the use of the bccomp() function until the updates are applied.

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:56969
BIT-LIBPHP-2026-17544
BIT-PHP-2026-17544
BIT-PHP-MIN-2026-17544
CVE-2026-17544
OPENSUSE-SU-2026:11418-1
OPENSUSE-SU-2026:21532-1
SUSE-SU-2026:23121-1
SUSE-SU-2026:23144-1
USN-8743-1

Affected Products

Php