REDHAT-BUG-2468572: High severity PHP PHP vulnerability
In PHP versions 8.4. before 8.4.21 and 8.5. before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2468572?
The severity of REDHAT-BUG-2468572 is high with a score of 7.
How do I fix REDHAT-BUG-2468572?
To fix REDHAT-BUG-2468572, you should update PHP to version 8.4.21 or 8.5.6 or later.
What versions of PHP are affected by REDHAT-BUG-2468572?
PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6 are affected by REDHAT-BUG-2468572.
What impact does REDHAT-BUG-2468572 have on PHP applications?
REDHAT-BUG-2468572 may cause a denial of service due to an infinite loop during XML document processing.
Is there a workaround for REDHAT-BUG-2468572?
There is no official workaround for REDHAT-BUG-2468572; upgrading to the fixed versions is recommended.