Bug 2541615 (CVE-2026-93682) - CVE-2026-93682 php: php: Out-of-bounds read via empty HTTP redirect Location header
Summary: CVE-2026-93682 php: php: Out-of-bounds read via empty HTTP redirect Location ...
Keywords:
Status: NEW
Alias: CVE-2026-93682
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 20:11 UTC by OSIDB Bzimport
Modified: 2026-09-25 20:16 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 20:11:13 UTC
When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.


Note You need to log in before you can comment on or make changes to this bug.