CVE-2015-9253

Updated: 2025-08-20 00:25:28.321484

Description:

An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell_exec, or system) with a non-blocking STDIN stream, causing this master process to consume 100% of the CPU, and consume disk space with a large volume of error logs, as demonstrated by an attack by a customer of a shared-hosting facility.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 6.8
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Debian 10 php 8.0 6.5 MEDIUM Ignored 2025-05-29 03:53:19
Debian 10 php 5.6 6.5 MEDIUM Already Fixed 2025-05-03 03:54:57
Debian 10 php 7.3 6.5 MEDIUM Ignored 2025-05-29 03:53:19
Debian 10 php 8.2 6.5 MEDIUM Ignored 2025-05-29 03:53:18
Debian 10 php 8.1 6.5 MEDIUM Ignored 2025-05-29 03:53:19
Debian 10 php 7.0 6.5 MEDIUM Ignored 2025-05-29 03:53:19
Debian 10 php 7.1 6.5 MEDIUM Ignored 2025-05-29 03:53:19
Debian 10 php 7.2 6.5 MEDIUM Ignored 2025-05-29 03:53:19
Debian 10 php 7.4 6.5 MEDIUM Ignored 2025-05-29 03:53:19
Debian 11 php 8.1 6.5 MEDIUM Ignored 2025-05-29 03:53:18
Total: 146