Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Ubuntu 22.04 LTS USN-5530-1 Critical: PHP Memory Handling Error

Ubuntu Large Esm H500
PHP could be made to crash or run programs if it processed specially crafted data.
=========================================================================Ubuntu Security Notice USN-5530-1
July 25, 2022

php8.1 vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS

Summary:

PHP could be made to crash or run programs if it processed specially
crafted data.

Software Description:
- php8.1: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP incorrectly handled certain memory operations
when obtaining file information. A remote attacker could use this issue to
cause PHP to crash, resulting in a denial of service, or possibly execute
arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
  libapache2-mod-php8.1           8.1.2-1ubuntu2.2
  php8.1-cgi                      8.1.2-1ubuntu2.2
  php8.1-cli                      8.1.2-1ubuntu2.2
  php8.1-fpm                      8.1.2-1ubuntu2.2
  php8.1-mysql                    8.1.2-1ubuntu2.2
  php8.1-pgsql                    8.1.2-1ubuntu2.2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5530-1
  CVE-2022-31627

Package Information:
  https://launchpad.net/ubuntu/+source/php8.1/8.1.2-1ubuntu2.2

Ubuntu 22.04 LTS USN-5530-1 Critical: PHP Memory Handling Error

ubuntu
Calendar Grey July 25, 2022
Dist Ubuntu Esm H88
A security flaw in PHP for Ubuntu 22.04 LTS could lead to system crashes or potential remote code execution if specific malicious data is processed.
PHP could be made to crash or run programs if it processed specially crafted data.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: libapache2-mod-php8.1 8.1.2-1ubuntu2.2 php8.1-cgi 8.1.2-1ubuntu2.2 php8.1-cli 8.1.2-1ubuntu2.2 php8.1-fpm 8.1.2-1ubuntu2.2 php8.1-mysql 8.1.2-1ubuntu2.2 php8.1-pgsql 8.1.2-1ubuntu2.2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5530-1

CVE-2022-31627

Severity
critical
Lowest
Low
Medium
High
Critical

July 25, 2022

Package Information

https://launchpad.net/ubuntu/+source/php8.1/8.1.2-1ubuntu2.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here