Fedora Account System
Red Hat Associate
Red Hat Customer
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:40416 https://access.redhat.com/errata/RHSA-2026:40416
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:47749 https://access.redhat.com/errata/RHSA-2026:47749
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:47750 https://access.redhat.com/errata/RHSA-2026:47750
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:48170 https://access.redhat.com/errata/RHSA-2026:48170
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:48197 https://access.redhat.com/errata/RHSA-2026:48197
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:49914 https://access.redhat.com/errata/RHSA-2026:49914