CVE-2025-14178

Updated: 2026-01-01 03:12:45.179083

Description:

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Debian 10 php 8.0 6.5 MEDIUM Needs Triage 2025-12-18 23:28:55
Debian 10 php 5.6 6.5 MEDIUM Needs Triage 2025-12-18 23:27:45
Debian 10 php 7.3 6.5 MEDIUM Needs Triage 2025-12-18 23:28:52
Debian 10 php 8.2 6.5 MEDIUM Needs Triage 2025-12-18 23:28:57
Debian 10 php 8.1 6.5 MEDIUM Needs Triage 2025-12-18 23:28:56
Debian 10 php 7.0 6.5 MEDIUM Needs Triage 2025-12-18 23:28:49
Debian 10 php 7.1 6.5 MEDIUM Needs Triage 2025-12-18 23:28:50
Debian 10 php 7.2 6.5 MEDIUM Needs Triage 2025-12-18 23:28:51
Debian 10 php 7.4 6.5 MEDIUM Needs Triage 2025-12-18 23:28:54
Debian 11 php 8.1 6.5 MEDIUM Needs Triage 2025-12-18 23:28:19
Total: 146