Wind River Support Network

HomeDefectsLIN1021-14585
Fixed

LIN1021-14585 : Security Advisory - php - CVE-2024-11235

Created: Mar 13, 2025    Updated: May 21, 2025
Resolved Date: May 21, 2025
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??=  operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout leading to this, for example by supplying specially crafted inputs to the script, it could lead to remote code execution.

https://nvd.nist.gov/vuln/detail/CVE-2024-11235

CVEs


Live chat
Online