CVE-2024-11235

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-11235
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11235.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-11235
Aliases
Related
Published
2025-04-04T18:15:48Z
Modified
2025-04-14T12:59:20.158933Z
Downstream
Summary
[none]
Details

In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??=  operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout leading to this, for example by supplying specially crafted inputs to the script, it could lead to remote code execution.

References

Affected packages

Debian:13 / php8.4

Package

Name
php8.4
Purl
pkg:deb/debian/php8.4?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.4.5-1

Affected versions

8.*

8.4.0~alpha1-1
8.4.0~alpha4-1
8.4.0~beta3-1
8.4.0~beta4-1
8.4.0~beta5-1
8.4.0~rc1-1
8.4.0~rc4-1
8.4.1-4
8.4.1-5
8.4.1-6
8.4.2-1
8.4.3-1
8.4.4-1
8.4.4-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/php/php-src

Affected ranges

Type
GIT
Repo
https://github.com/php/php-src
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

NEWS
NEWS-cvs2svn
POST_64BIT_BRANCH_MERGE
POST_AST_MERGE
POST_NATIVE_TLS_MERGE
POST_PHP7_EREG_MYSQL_REMOVALS
POST_PHP7_NSAPI_REMOVAL
POST_PHP7_REMOVALS
POST_PHPNG_MERGE
PRE_64BIT_BRANCH_MERGE
PRE_AST_MERGE
PRE_NATIVE_TLS_MERGE
PRE_PHP7_EREG_MYSQL_REMOVALS
PRE_PHP7_NSAPI_REMOVAL
PRE_PHP7_REMOVALS
PRE_PHPNG_MERGE

php-5.*

php-5.3.23RC1
php-5.3.29
php-5.3.29RC1
php-5.4.30RC1
php-5.4.32RC1
php-5.4.4RC2
php-5.5.24RC1
php-5.6.18RC1
php-5.6.19RC1
php-5.6.22RC1
php-5.6.23RC1
php-5.6.24RC1

php-7.*

php-7.0.11RC1
php-7.0.12RC1
php-7.0.13RC1
php-7.0.3RC1
php-7.0.4RC1
php-7.0.5RC1
php-7.0.7RC1
php-7.0.8RC1
php-7.0.9RC1
php-7.1.0alpha2
php-7.1.31
php-7.1.32
php-7.1.33

php-8.*

php-8.3.18