CVE-2026-14355Patch(debian / debian_linux)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch debian debian_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • php

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-06); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
debian_linuxphp

1 version affected across 2 products

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-07-02: 1Mentions · 2026-07-03: 1Mentions · 2026-07-04: 1Mentions · 2026-07-06: 2Mentions · 2026-07-07: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-07-06: 2Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-04: 1Technical Details · 2026-07-06: 2Technical Details · 2026-07-07: 107-0207-0307-0407-0607-07
Signal classification2 categories
Patch
583.3%
Disclosure
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-021
Patch1
2026-07-031
Disclosure1
2026-07-041
Patch1
2026-07-062
Patch2
2026-07-071
Patch1
Full discourse6 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Two PHP flaws are patched. CVE-2026-12184 is a PHP remote DoS that crashes PHP-FPM, and CVE-2026-14355 causes memory corruption. Update PHP now. #PHP #RemoteDoS #DoS #PHPFPM #CyberSecurity #Vulnerability #InfoSec http://securityonline.info/php-remote-dos-cve-2026-12184/

    Post summary

    The post announces that two PHP vulnerabilities (CVE-2026-12184 and CVE-2026-14355) have been patched, urging users to update PHP to mitigate a remote DoS and memory corruption issue.

    02142847
    12.9K followersView on X
  • Sergey Panteleev@s_panteleev
    Patch

    📣 Announcing the immediate availability of #PHP 8.2.32 ‼️ This SECURITY release fix: - Memory corruption in openssl_encrypt with AES-WRAP-PAD (CVE-2026-14355) 🔗 https://php.net/ChangeLog-8#8.2.32

    Post summary

    The post announces PHP 8.2.32 as the fix for CVE‑2026‑14355, a memory‑corruption issue in openssl_encrypt, and links to the change log for the update.

    01030240
    663 followersView on X
  • 大島義裕@yoshihiro_oh
    Patch

    【セキュリティ ニュース】「PHP」にセキュリティ更新 - 複数の脆弱性を修正:Security NEXT https://www.security-next.com/186792 openssl_encryptのメモリ破損(CVE-2026-14355)を修正。 openssl_encrypt()のAES-WRAP-PAD使用時に**クラッシュ(DoS)**が主な影響で、該当関数を使っているサイトは早めの更新推奨

    Post summary

    The article announces a PHP security patch for CVE‑2026‑14355, a memory‑corruption vulnerability in openssl_encrypt that can trigger a DoS crash; users are advised to update promptly.

    00010152
    2.0K followersView on X
  • TECHEPAGES@techepages
    Patch

    PHP patches remote DoS and OpenSSL memory corruption flaws - Fixes are out across supported branches for a high-severity TLS stream bug and a moderate heap corruption issue. 💥 CVE-2026-12184 (High, 8.7): A failed TLS handshake, even just an expired certificate on a remote server crashes the entire PHP-FPM process and all workers; fixed in 8.3.32, 8.4.21, 8.5.6. 🔐 CVE-2026-14355 (Moderate, 4.7): Undersized buffers in openssl_encrypt() with AES-WRAP-PAD corrupt heap metadata, surfacing later as hard-to-diagnose allocator aborts; fixed in 8.2.32, 8.3.32, 8.4.23, 8.5.8.

    Post summary

    The post announces PHP patches for two critical vulnerabilities, providing technical details and specific version fixes.

    0000061
    23 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CVE-2026-14355: Debian 12 PHP 8.2 Buffer Overflow — Detection and Remediation G… "A critical memory corruption vulnerability has been identified in the PHP 8.2 package…" 🔗 https://securityarsenal.com/blog/cve-2026-14355-debian-12-php-82-buffer-overflow-detection-and-remediation-guide #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    Post summary

    The tweet highlights a detection and remediation guide for CVE‑2026‑14355, a buffer‑overflow vulnerability in PHP 8.2 on Debian 12, emphasizing patching and mitigation steps.

    0000055
    18 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension cont… https://www.cve.org/CVERecord?id=CVE-2026-14355

    Post summary

    The text announces CVE‑2026‑14355, detailing affected PHP and OpenSSL versions, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00000711
    57.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux12.0--
Appphpphp---

Explore more