First published: Thu Sep 26 2024(Updated: )
Fixed bug (Logs from childrens may be altered). (CVE-2024-9026)
Credit: security@php.net security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
debian/php7.4 | <=7.4.33-1+deb11u5 | 7.4.33-1+deb11u7 |
debian/php8.2 | 8.2.26-1~deb12u1 8.2.27-1 | |
PHP | <8.3.12 | 8.3.12 |
Ubuntu PHP-FPM | >=8.1.0<8.1.30 | |
Ubuntu PHP-FPM | >=8.2.0<8.2.24 | |
Ubuntu PHP-FPM | >=8.3.0<8.3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9026 has a medium severity rating due to the potential for log pollution in PHP-FPM configurations.
To fix CVE-2024-9026, upgrade PHP-FPM to versions 8.1.30, 8.2.24, or 8.3.12 or higher.
CVE-2024-9026 affects PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, and 8.3.* before 8.3.12.
The primary issue of CVE-2024-9026 is the potential alteration and pollution of logs when using PHP-FPM with catch_workers_output enabled.
The recommended remediation steps for CVE-2024-9026 include upgrading to the latest, patched versions of PHP-FPM.