ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class. References: https://bugs.php.net/bug.php?id=77177
Notice: This issue is about serialization, so not considered as a security issue See warning on http://php.net/manual/en/function.unserialize.php COM extension is Windows only
Upstream commit: http://git.php.net/?p=php-src.git;a=commitdiff;h=115ee49b0be12e3df7d2c7027609fbe1a1297e42 As noted in the previous comment, this only affects COM extension that is only available for Windows versions of PHP and hence this does not affect any Red Hat shipped PHP packages.