Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92001.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92001
Upstream
  • CVE-2026-14355
Published
2026-07-03T21:16:55Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-14355 affecting package php for versions less than 8.3.32-1
Details

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

References

Affected packages

Azure Linux:3 / php

Package

Name
php
Purl
pkg:rpm/azure-linux/php

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.3.32-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92001.json"