CVE-2022-4900: Potential buffer overflow in php_cli_server_startup_workers
A vulnerability was found in PHP where setting the environment variable PHPCLISERVERWORKERS to a large value leads to a heap buffer overflow.
Other sources
A vulnerability was found in PHP, where by setting the environment variable PHPCLISERVERWORKERS to a large value leads to a heap buffer overflow.
References: https://github.com/php/php-src/issues/8989
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-4900.
What is the severity of CVE-2022-4900?
The severity of CVE-2022-4900 is medium with a CVSS score of 6.2.
How does the vulnerability in PHP occur?
The vulnerability in PHP occurs when the environment variable PHP_CLI_SERVER_WORKERS is set to a large value, leading to a heap buffer overflow.
Which versions of PHP are affected by CVE-2022-4900?
PHP versions up to and excluding 8.0.22 are affected by CVE-2022-4900.
Where can I find more information about CVE-2022-4900?
You can find more information about CVE-2022-4900 at the following references: [https://access.redhat.com/security/cve/CVE-2022-4900](https://access.redhat.com/security/cve/CVE-2022-4900), [https://bugzilla.redhat.com/show_bug.cgi?id=2179880](https://bugzilla.redhat.com/show_bug.cgi?id=2179880), [https://github.com/php/php-src/issues/8989](https://github.com/php/php-src/issues/8989).