Out-of-bounds read in PHP - CVE-2026-6104

 

Out-of-bounds read in PHP - CVE-2026-6104

Published: May 10, 2026


Vulnerability identifier: #VU130911
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-6104
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in mbfl_name2encoding_ex() when parsing crafted input. A remote attacker can supply crafted input to cause a denial of service.


Affected software

PHP
Debian Linux
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
Ubuntu
SecurityCenter
php8.1 (Ubuntu package)
php8.4 (Debian package)
php8-fileinfo-debuginfo
php8-ftp-debuginfo
php8-enchant
php8-bz2
php8-curl-debuginfo
php8-cli
php8-ffi
php8-posix
php8-fpm-debugsource
php8-embed
php8-exif
php8-pcntl-debuginfo
php8-gd-debuginfo
php8-sysvshm
php8-pdo
php8-bcmath-debuginfo
php8-xmlreader
php8-calendar-debuginfo
php8-enchant-debuginfo
php8-ldap
php8-curl
php8-fileinfo
php8-openssl-debuginfo
php8-fpm-debuginfo
php8-zip-debuginfo
php8-fastcgi-debugsource
php8-devel
php8-pgsql
php8-mbstring-debuginfo
php8-xmlreader-debuginfo
php8-gd
php8
apache2-mod_php8-debugsource
php8-snmp-debuginfo
php8-exif-debuginfo
php8-tokenizer
php8-cli-debuginfo
php8-tidy
php8-soap
php8-fpm-apache
php8-calendar
php8-debuginfo
php8-posix-debuginfo
php8-opcache
php8-fpm
php8-dom-debuginfo
php8-zlib
apache2-mod_php8-debuginfo
php8-pgsql-debuginfo
php8-sysvsem-debuginfo
php8-ctype
php8-intl-debuginfo
php8-tokenizer-debuginfo
php8-gettext
php8-zip
php8-phar-debuginfo
php8-openssl
php8-sysvmsg
php8-sqlite
php8-embed-debugsource
php8-sodium
php8-embed-debuginfo
apache2-mod_php8
php8-xmlwriter
php8-fastcgi
php8-shmop
php8-pcntl
php8-ldap-debuginfo
php8-bcmath
php8-bz2-debuginfo
php8-xsl-debuginfo
php8-gmp-debuginfo
php8-snmp
php8-tidy-debuginfo
php8-sodium-debuginfo
php8-mysql-debuginfo
php8-readline-debuginfo
php8-soap-debuginfo
php8-sockets-debuginfo
php8-ctype-debuginfo
php8-fastcgi-debuginfo
php8-debugsource
php8-readline
php8-sysvsem
php8-odbc-debuginfo
php8-iconv-debuginfo
php8-ftp
php8-dom
php8-pdo-debuginfo
php8-gmp
php8-sockets
php8-shmop-debuginfo
php8-mysql
php8-xsl
php8-mbstring
php8-ffi-debuginfo
php8-dba-debuginfo
php8-odbc
php8-sysvmsg-debuginfo
php8-sysvshm-debuginfo
php8-sqlite-debuginfo
php8-intl
php8-zlib-debuginfo
php8-phar
php8-opcache-debuginfo
php8-iconv
php8-gettext-debuginfo
php8-dba
php8-xmlwriter-debuginfo

How to mitigate CVE-2026-6104

Install security update from vendor's website.

PHP - addressed in versions 8.4.21, 8.5.6
SecurityCenter - addressed in versions SC202607.1, SC202607.2
php8.1 (Ubuntu package) - addressed in versions 8.1.2-1ubuntu2.24, 8.3.6-0ubuntu0.24.04.9, 8.4.11-1ubuntu1.2, 8.5.4-0ubuntu1.1
php8.4 (Debian package) - update to 8.4.21-1~deb13u1
php8-fileinfo-debuginfo - update to 8.4.21-160000.1.1
php8-ftp-debuginfo - update to 8.4.21-160000.1.1
php8-enchant - update to 8.4.21-160000.1.1
php8-bz2 - update to 8.4.21-160000.1.1
php8-curl-debuginfo - update to 8.4.21-160000.1.1
php8-cli - update to 8.4.21-160000.1.1
php8-ffi - update to 8.4.21-160000.1.1
php8-posix - update to 8.4.21-160000.1.1
php8-fpm-debugsource - update to 8.4.21-160000.1.1
php8-embed - update to 8.4.21-160000.1.1
php8-exif - update to 8.4.21-160000.1.1
php8-pcntl-debuginfo - update to 8.4.21-160000.1.1
php8-gd-debuginfo - update to 8.4.21-160000.1.1
php8-sysvshm - update to 8.4.21-160000.1.1
php8-pdo - update to 8.4.21-160000.1.1
php8-bcmath-debuginfo - update to 8.4.21-160000.1.1
php8-xmlreader - update to 8.4.21-160000.1.1
php8-calendar-debuginfo - update to 8.4.21-160000.1.1
php8-enchant-debuginfo - update to 8.4.21-160000.1.1
php8-ldap - update to 8.4.21-160000.1.1
php8-curl - update to 8.4.21-160000.1.1
php8-fileinfo - update to 8.4.21-160000.1.1
php8-openssl-debuginfo - update to 8.4.21-160000.1.1
php8-fpm-debuginfo - update to 8.4.21-160000.1.1
php8-zip-debuginfo - update to 8.4.21-160000.1.1
php8-fastcgi-debugsource - update to 8.4.21-160000.1.1
php8-devel - update to 8.4.21-160000.1.1
php8-pgsql - update to 8.4.21-160000.1.1
php8-mbstring-debuginfo - update to 8.4.21-160000.1.1
php8-xmlreader-debuginfo - update to 8.4.21-160000.1.1
php8-gd - update to 8.4.21-160000.1.1
php8 - update to 8.4.21-160000.1.1
apache2-mod_php8-debugsource - update to 8.4.21-160000.1.1
php8-snmp-debuginfo - update to 8.4.21-160000.1.1
php8-exif-debuginfo - update to 8.4.21-160000.1.1
php8-tokenizer - update to 8.4.21-160000.1.1
php8-cli-debuginfo - update to 8.4.21-160000.1.1
php8-tidy - update to 8.4.21-160000.1.1
php8-soap - update to 8.4.21-160000.1.1
php8-fpm-apache - update to 8.4.21-160000.1.1
php8-calendar - update to 8.4.21-160000.1.1
php8-debuginfo - update to 8.4.21-160000.1.1
php8-posix-debuginfo - update to 8.4.21-160000.1.1
php8-opcache - update to 8.4.21-160000.1.1
php8-fpm - update to 8.4.21-160000.1.1
php8-dom-debuginfo - update to 8.4.21-160000.1.1
php8-zlib - update to 8.4.21-160000.1.1
apache2-mod_php8-debuginfo - update to 8.4.21-160000.1.1
php8-pgsql-debuginfo - update to 8.4.21-160000.1.1
php8-sysvsem-debuginfo - update to 8.4.21-160000.1.1
php8-ctype - update to 8.4.21-160000.1.1
php8-intl-debuginfo - update to 8.4.21-160000.1.1
php8-tokenizer-debuginfo - update to 8.4.21-160000.1.1
php8-gettext - update to 8.4.21-160000.1.1
php8-zip - update to 8.4.21-160000.1.1
php8-phar-debuginfo - update to 8.4.21-160000.1.1
php8-openssl - update to 8.4.21-160000.1.1
php8-sysvmsg - update to 8.4.21-160000.1.1
php8-sqlite - update to 8.4.21-160000.1.1
php8-embed-debugsource - update to 8.4.21-160000.1.1
php8-sodium - update to 8.4.21-160000.1.1
php8-embed-debuginfo - update to 8.4.21-160000.1.1
apache2-mod_php8 - update to 8.4.21-160000.1.1
php8-xmlwriter - update to 8.4.21-160000.1.1
php8-fastcgi - update to 8.4.21-160000.1.1
php8-shmop - update to 8.4.21-160000.1.1
php8-pcntl - update to 8.4.21-160000.1.1
php8-ldap-debuginfo - update to 8.4.21-160000.1.1
php8-bcmath - update to 8.4.21-160000.1.1
php8-bz2-debuginfo - update to 8.4.21-160000.1.1
php8-xsl-debuginfo - update to 8.4.21-160000.1.1
php8-gmp-debuginfo - update to 8.4.21-160000.1.1
php8-snmp - update to 8.4.21-160000.1.1
php8-tidy-debuginfo - update to 8.4.21-160000.1.1
php8-sodium-debuginfo - update to 8.4.21-160000.1.1
php8-mysql-debuginfo - update to 8.4.21-160000.1.1
php8-readline-debuginfo - update to 8.4.21-160000.1.1
php8-soap-debuginfo - update to 8.4.21-160000.1.1
php8-sockets-debuginfo - update to 8.4.21-160000.1.1
php8-ctype-debuginfo - update to 8.4.21-160000.1.1
php8-fastcgi-debuginfo - update to 8.4.21-160000.1.1
php8-debugsource - update to 8.4.21-160000.1.1
php8-readline - update to 8.4.21-160000.1.1
php8-sysvsem - update to 8.4.21-160000.1.1
php8-odbc-debuginfo - update to 8.4.21-160000.1.1
php8-iconv-debuginfo - update to 8.4.21-160000.1.1
php8-ftp - update to 8.4.21-160000.1.1
php8-dom - update to 8.4.21-160000.1.1
php8-pdo-debuginfo - update to 8.4.21-160000.1.1
php8-gmp - update to 8.4.21-160000.1.1
php8-sockets - update to 8.4.21-160000.1.1
php8-shmop-debuginfo - update to 8.4.21-160000.1.1
php8-mysql - update to 8.4.21-160000.1.1
php8-xsl - update to 8.4.21-160000.1.1
php8-mbstring - update to 8.4.21-160000.1.1
php8-ffi-debuginfo - update to 8.4.21-160000.1.1
php8-dba-debuginfo - update to 8.4.21-160000.1.1
php8-odbc - update to 8.4.21-160000.1.1
php8-sysvmsg-debuginfo - update to 8.4.21-160000.1.1
php8-sysvshm-debuginfo - update to 8.4.21-160000.1.1
php8-sqlite-debuginfo - update to 8.4.21-160000.1.1
php8-intl - update to 8.4.21-160000.1.1
php8-zlib-debuginfo - update to 8.4.21-160000.1.1
php8-phar - update to 8.4.21-160000.1.1
php8-opcache-debuginfo - update to 8.4.21-160000.1.1
php8-iconv - update to 8.4.21-160000.1.1
php8-gettext-debuginfo - update to 8.4.21-160000.1.1
php8-dba - update to 8.4.21-160000.1.1
php8-xmlwriter-debuginfo - update to 8.4.21-160000.1.1

External References

Related Security Bulletins