CVE-2026-14355

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

History

08 Jul 2026, 20:11

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
References () https://github.com/php/php-src/security/advisories/GHSA-7jrw-539f-x6vr - () https://github.com/php/php-src/security/advisories/GHSA-7jrw-539f-x6vr - Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2026/07/msg00010.html - () https://lists.debian.org/debian-lts-announce/2026/07/msg00010.html - Mailing List, Third Party Advisory
First Time Php php
Debian
Debian debian Linux
Php

04 Jul 2026, 16:17

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2026/07/msg00010.html -

03 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-03 21:16

Updated : 2026-07-08 20:11


NVD link : CVE-2026-14355

Mitre link : CVE-2026-14355

CVE.ORG link : CVE-2026-14355


JSON object : View

Products Affected

debian

  • debian_linux

php

  • php
CWE
CWE-122

Heap-based Buffer Overflow