UBUNTU-CVE-2026-41570

Source
https://ubuntu.com/security/CVE-2026-41570
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-41570
Upstream
  • CVE-2026-41570
Published
2026-05-08T15:16:00Z
Modified
2026-05-20T16:25:41.377471268Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=value command-line arguments without neutralizing INI metacharacters. Because PHP's INI parser interprets " as a string delimiter, ; as the start of a comment, and most importantly a newline as a directive separator, a value containing a newline is parsed by the child process as multiple INI directives. An attacker able to influence a single INI value can therefore inject arbitrary additional directives into the child's configuration, including autoprependfile, extension, disablefunctions, openbasedir, and others. Setting autoprependfile to an attacker-controlled path yields remote code execution in the child process. This issue has been patched in versions 12.5.22 and 13.1.6.

References

Affected packages

Ubuntu:18.04:LTS
phpunit

Package

Name
phpunit
Purl
pkg:deb/ubuntu/phpunit?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.4.6-2
5.4.6-3
6.*
6.5.5-1ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "phpunit",
            "binary_version": "6.5.5-1ubuntu2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"
Ubuntu:20.04:LTS
phpunit

Package

Name
phpunit
Purl
pkg:deb/ubuntu/phpunit?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.5.6-1
8.*
8.5.2-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "phpunit",
            "binary_version": "8.5.2-1ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"
Ubuntu:22.04:LTS
phpunit

Package

Name
phpunit
Purl
pkg:deb/ubuntu/phpunit?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

9.*
9.5.4-1
9.5.10-1ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "phpunit",
            "binary_version": "9.5.10-1ubuntu2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"
Ubuntu:24.04:LTS
phpunit

Package

Name
phpunit
Purl
pkg:deb/ubuntu/phpunit?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

9.*
9.6.10-1
9.6.13-1
9.6.15-1
9.6.16-1
9.6.17-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "phpunit",
            "binary_version": "9.6.17-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"
Ubuntu:25.10
phpunit

Package

Name
phpunit
Purl
pkg:deb/ubuntu/phpunit?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

11.*
11.5.3-1ubuntu4
11.5.19-1build4

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "phpunit",
            "binary_version": "11.5.19-1build4"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"
Ubuntu:26.04:LTS
phpunit

Package

Name
phpunit
Purl
pkg:deb/ubuntu/phpunit?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

11.*
11.5.19-1build4
13.*
13.0.0-2ubuntu6

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "phpunit",
            "binary_version": "13.0.0-2ubuntu6"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"
Ubuntu:Pro:16.04:LTS
phpunit

Package

Name
phpunit
Purl
pkg:deb/ubuntu/phpunit?arch=source&distro=esm-apps%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.7.6-1
4.8.16-1
5.*
5.1.3-1ubuntu1
5.1.3-1+build1
5.1.3-1+ubuntu1
5.1.3-1+ubuntu3
5.1.3-1+ubuntu3+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "phpunit",
            "binary_version": "5.1.3-1+ubuntu3+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"