CVE-2024-11235
Publication date 14 March 2025
Last updated 9 April 2025
Ubuntu priority
In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??= operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout leading to this, for example by supplying specially crafted inputs to the script, it could lead to remote code execution.
Status
Package | Ubuntu Release | Status |
---|---|---|
php5 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
14.04 LTS trusty |
Needs evaluation
|
|
php7.0 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
16.04 LTS xenial |
Needs evaluation
|
|
php7.2 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic |
Needs evaluation
|
|
php7.4 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal |
Fixed 7.4.3-4ubuntu2.29
|
|
php8.1 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy |
Fixed 8.1.2-1ubuntu2.21
|
|
20.04 LTS focal | Not in release | |
php8.3 | 24.10 oracular |
Fixed 8.3.11-0ubuntu0.24.10.5
|
24.04 LTS noble |
Fixed 8.3.6-0ubuntu0.24.04.4
|
|
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
php8.4 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release |
Notes
References
Related Ubuntu Security Notices (USN)
- USN-7400-1
- PHP vulnerabilities
- 31 March 2025