Reference counting in php_request_shutdown causes Use-After-Free
Vulnerability Description
In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??= operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout leading to this, for example by supplying specially crafted inputs to the script, it could lead to remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-11235
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Junwha Hong
More from PHP Group
View All →Affected Vendor
PHP Group
View all reports →