Bug 2496971 (CVE-2026-14355) - CVE-2026-14355 php: ext/openssl: memory corruption in openssl_encrypt with AES-WRAP-PAD
Summary: CVE-2026-14355 php: ext/openssl: memory corruption in openssl_encrypt with AE...
Keywords:
Status: NEW
Alias: CVE-2026-14355
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-03 22:01 UTC by OSIDB Bzimport
Modified: 2026-08-13 17:17 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:40416 0 None None None 2026-07-15 23:31:26 UTC
Red Hat Product Errata RHSA-2026:47749 0 None None None 2026-07-29 10:44:31 UTC
Red Hat Product Errata RHSA-2026:47750 0 None None None 2026-07-29 10:54:55 UTC
Red Hat Product Errata RHSA-2026:48170 0 None None None 2026-07-29 22:20:15 UTC
Red Hat Product Errata RHSA-2026:48197 0 None None None 2026-07-30 18:19:37 UTC
Red Hat Product Errata RHSA-2026:49914 0 None None None 2026-08-04 07:44:29 UTC

Description OSIDB Bzimport 2026-07-03 22:01:36 UTC
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

Comment 2 errata-xmlrpc 2026-07-15 23:31:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:40416 https://access.redhat.com/errata/RHSA-2026:40416

Comment 3 errata-xmlrpc 2026-07-29 10:44:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:47749 https://access.redhat.com/errata/RHSA-2026:47749

Comment 4 errata-xmlrpc 2026-07-29 10:54:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:47750 https://access.redhat.com/errata/RHSA-2026:47750

Comment 5 errata-xmlrpc 2026-07-29 22:20:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:48170 https://access.redhat.com/errata/RHSA-2026:48170

Comment 6 errata-xmlrpc 2026-07-30 18:19:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:48197 https://access.redhat.com/errata/RHSA-2026:48197

Comment 7 errata-xmlrpc 2026-08-04 07:44:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:49914 https://access.redhat.com/errata/RHSA-2026:49914


Note You need to log in before you can comment on or make changes to this bug.