CVE-2024-11235: Reference counting in php_request_shutdown causes Use-After-Free
Published Mar 13, 2025
·Updated
Fixed (Reference counting in phprequestshutdown causes Use-After-Free). (CVE-2024-11235)
Other sources
In PHP versions 8.3. before 8.3.19 and 8.4. before 8.4.5, a code seq ...
— Debian
Affected Software
4 affected componentsFixes available
PHP PHP<8.4.5
8.4.5
debian/php8.4
8.4.5-1
PHP PHP>=8.3.0<8.3.19
PHP PHP>=8.4.0<8.4.5
Event History
Mar 13, 2025
CVE Published
via PHP·12:00 AM
Mar 31, 2025
Data Sourced
via Ubuntu·11:16 PM
RemedyDescriptionSeverityAffected Software
Apr 4, 2025
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
DescriptionWeakness
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-11235?
CVE-2024-11235 has been classified as a critical vulnerability due to its potential for causing use-after-free errors.
2
How do I fix CVE-2024-11235?
To fix CVE-2024-11235, upgrade PHP to version 8.3.19 or later.
3
What causes the vulnerability CVE-2024-11235?
The vulnerability CVE-2024-11235 is caused by improper reference counting during the php_request_shutdown process.
4
Which versions of PHP are affected by CVE-2024-11235?
CVE-2024-11235 affects all PHP versions prior to 8.3.19.
5
Is there a workaround for CVE-2024-11235?
There is no known workaround for CVE-2024-11235; upgrading to a fixed version is the only solution.