Bug 2317144 (CVE-2024-9026) - CVE-2024-9026 php: PHP-FPM Log Manipulation Vulnerability
Summary: CVE-2024-9026 php: PHP-FPM Log Manipulation Vulnerability
Keywords:
Status: NEW
Alias: CVE-2024-9026
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-10-08 04:20 UTC by OSIDB Bzimport
Modified: 2025-05-13 10:35 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2024:11026 0 None None None 2024-12-12 22:36:46 UTC
Red Hat Product Errata RHSA-2024:10949 0 None None None 2024-12-11 11:45:08 UTC
Red Hat Product Errata RHSA-2024:10950 0 None None None 2024-12-11 11:44:51 UTC
Red Hat Product Errata RHSA-2024:10951 0 None None None 2024-12-11 11:45:29 UTC
Red Hat Product Errata RHSA-2024:10952 0 None None None 2024-12-11 11:44:27 UTC
Red Hat Product Errata RHSA-2025:7315 0 None None None 2025-05-13 10:35:40 UTC

Description OSIDB Bzimport 2024-10-08 04:20:31 UTC
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.

Comment 1 errata-xmlrpc 2024-12-11 11:44:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:10952 https://access.redhat.com/errata/RHSA-2024:10952

Comment 2 errata-xmlrpc 2024-12-11 11:44:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:10950 https://access.redhat.com/errata/RHSA-2024:10950

Comment 3 errata-xmlrpc 2024-12-11 11:45:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:10949 https://access.redhat.com/errata/RHSA-2024:10949

Comment 4 errata-xmlrpc 2024-12-11 11:45:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:10951 https://access.redhat.com/errata/RHSA-2024:10951

Comment 6 errata-xmlrpc 2025-05-13 10:35:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:7315 https://access.redhat.com/errata/RHSA-2025:7315


Note You need to log in before you can comment on or make changes to this bug.