CVE-2026-92842: 
PHP 취약성 분석 및 완화

개요

CVE-2026-92842 is a heap-based out-of-bounds read and information leak vulnerability in PHP's convert.* stream filters (specifically convert.base64-encode, convert.quoted-printable-encode, and convert.quoted-printable-decode). When the line-break-chars option contains embedded NUL bytes, the filter constructors duplicate the value using pestrdup() (which stops at the first NUL) while retaining the original, untruncated length — causing subsequent line-break emission to read past the end of the allocation and copy adjacent heap bytes into the filter output. It affects PHP versions before 8.2.34, 8.3.35, 8.4.26, and 8.5.11, and was published on September 24, 2026. The CVSS v3.1 base score is 5.9 (Moderate) (GitHub Advisory).

기술적 세부 사항

The root cause is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-125 (Out-of-bounds Read). In php_conv_base64_encode_ctor(), php_conv_qprint_encode_ctor(), and php_conv_qprint_decode_ctor() within ext/standard/filters.c, the line-break-chars option is duplicated with pestrdup(), which terminates at the first NUL byte, but the original (full) length is stored separately. When the encoder later inserts a line break, it copies lbchars_len bytes from the truncated allocation — reading one or more bytes past the end of the heap buffer. For example, setting line-break-chars to "\0X" results in a one-byte allocation while lbchars_len is 2, causing a one-byte over-read; extending the value after the NUL increases the leak size. The fix replaces pestrdup() with pestrndup(lbchars, lbchars_len, persistent) in all three constructors. A PoC using ASAN is publicly available in the advisory (GitHub Advisory).

영향

Successful exploitation leaks heap memory adjacent to the line-break-chars allocation into the filter's encoded output, which is then returned to the requester. An attacker can increase the volume of leaked data by lengthening the option value after the embedded NUL byte. While the primary risk is confidentiality — potentially exposing sensitive heap contents such as credentials, keys, or other in-memory data — a crash is also possible on certain allocators and build configurations, though this is less likely in practice (GitHub Advisory).

악용 가능성

Exploitation requires an attacker to control the line-break-chars option passed to one of the affected stream filters, and for that value to contain an embedded NUL byte — a condition described as rare in practice, meaning the majority of applications are not affected. A public PoC using AddressSanitizer is included in the GitHub Security Advisory. The CVE status is listed as "Reserved" with no confirmed in-the-wild exploitation, no CISA KEV listing, and no EPSS score currently published. Nessus detection plugins (IDs 349694, 349787, 349788) have been released to identify vulnerable systems (GitHub Advisory, Feedly).

착취 단계

  1. Identify a vulnerable target: Find a PHP application (versions < 8.2.34, 8.3.35, 8.4.26, or 8.5.11) that accepts user-controlled input and passes it as the line-break-chars option to a convert.base64-encode, convert.quoted-printable-encode, or convert.quoted-printable-decode stream filter.
  2. Craft a malicious payload: Prepare a line-break-chars value containing an embedded NUL byte followed by additional bytes (e.g., "\x00X" or a longer sequence). The longer the suffix after the NUL, the more heap bytes will be read out of bounds.
  3. Deliver the payload: Submit the crafted value via the application's input mechanism — for example, via an HTTP GET/POST parameter that the application decodes and passes directly to the filter options (e.g., base64_decode($_GET['lb64']) used as line-break-chars).
  4. Trigger the filter: Cause the application to invoke the stream filter with the malicious option, such as by appending convert.base64-encode to a stream and reading from it, which triggers line-break emission.
  5. Collect leaked heap data: Capture the encoded output returned by the application. The bytes following the NUL in the line-break position will contain raw heap memory adjacent to the line-break-chars allocation, potentially including sensitive data (GitHub Advisory).

타협의 징후

  • Network: HTTP requests containing base64-encoded or raw values with embedded NUL bytes (%00) in parameters that are passed to stream filter options; unusual encoded output in HTTP responses containing non-printable or unexpected byte sequences.
  • Logs: PHP error logs showing heap-related warnings or crashes (e.g., from ASAN or allocator instrumentation) in contexts involving convert.base64-encode or convert.quoted-printable-* filters; access logs with requests supplying line-break-chars-related parameters with NUL-containing values.
  • Process: PHP processes crashing or producing unexpected output when processing stream filter operations with line-break-chars options containing NUL bytes (GitHub Advisory).

완화 및 해결 방법

PHP has released patched versions 8.2.34, 8.3.35, 8.4.26, and 8.5.11, all published on September 24, 2026. Upgrading to one of these versions is the recommended remediation. As a workaround where upgrading is not immediately possible, applications should validate and sanitize the line-break-chars option to reject any values containing NUL bytes before passing them to stream filters. Restricting user-controlled input from reaching stream filter options entirely is the most effective defense (GitHub Advisory, PHP Changelog).

커뮤니티 반응

The vulnerability was reported by researcher "geeknik" and published by the PHP security team (bukka) via GitHub Security Advisories. Security news outlet SecurityOnline.info covered the broader PHP patch release that included this fix. The Remi repository blog noted the availability of patched PHP packages for RHEL and Fedora. Community reaction has been measured given the moderate severity and the narrow exploitation preconditions required (SecurityOnline, Remi Blog).

추가 자료

리눅스 배포판 수정 현황

주요 리눅스 배포판과 그 릴리스 전반에 걸친 가용성을 수정하세요.

Debian

영향을 받은 사람들

bookworm

php8.2

영향을 받은 사람들

sid

php8.4

영향을 받은 사람들

trixie

php8.4: 8.4.26-1~deb13u1

수정됨

Ubuntu

알 수 없음

bionic (esm-infra)

php7.2

알 수 없음

devel

php8.5

알 수 없음

focal (esm-infra)

php7.4

알 수 없음

jammy

php8.1

알 수 없음

noble

php8.3

알 수 없음

resolute

php8.5

알 수 없음

trusty (esm-infra-legacy)

php5

알 수 없음

xenial (esm-infra-legacy)

php7.0

알 수 없음

RHEL / CentOS

영향을 받은 사람들

RHEL 8

php:7.4/php.src

영향을 받은 사람들

RHEL 9

php.src

영향을 받은 사람들

RHEL 10

php.src

영향을 받은 사람들

Alpine

수정됨

edge

php83: 8.3.35-r0, 8.4.26-r0, 8.5.11-r0

수정됨

근원: 이 보고서는 AI를 사용하여 생성되었습니다.

관련 PHP 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-91768MEDIUM6.5
  • PHP logoPHP
  • php:7.4::php-common
아니요예Sep 25, 2026
CVE-2026-91767MEDIUM6.5
  • PHP logoPHP
  • php-opcache
아니요예Sep 25, 2026
CVE-2026-92842MEDIUM5.9
  • PHP logoPHP
  • php:8.2::php-process
아니요예Sep 25, 2026
CVE-2026-91766MEDIUM5.9
  • PHP logoPHP
  • php8.4-fpm
아니요예Sep 25, 2026
CVE-2026-91769MEDIUM4.3
  • PHP logoPHP
  • php-fpm
아니요예Sep 25, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자