Underflow in PHP-FPM can lead to RCE
Published Oct 28, 2019 ·Due Apr 15, 2022
9.8
CRITICALCVSS 3.1
EPSS 99.78%
Description
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Affected products
-
- Version 7.1.xStatusaffectedConstraints<7.1.33
- Version 7.2.xStatusaffectedConstraints<7.2.24
- Version 7.3.xStatusaffectedConstraints<7.3.11
- Version
Configuration 1
Configuration 2
- 12.04
- 14.04
- 16.04
- 18.04
- 19.04
- 19.10
Configuration 3
- 9.0
- 10.0
Configuration 4
- 29
- 30
- 31
Configuration 5
- < 5.19.0
Configuration 6
- 1.0
- 8.0
- 6.0
- 7.0
- 7.7
- 8.1
- 8.2
- 8.4
- 8.6
- 8.8
- 7.7
- 8.0_aarch64
- 8.1_aarch64
- 8.2_aarch64
- 8.4_aarch64
- 8.6_aarch64
- 8.8_aarch64
- 6.0_s390x
- 7.0_s390x
- 8.0_s390x
- 7.7_s390x
- 8.1_s390x
- 8.2_s390x
- 8.4_s390x
- 8.6_s390x
- 8.8_s390x
- 6.0_ppc64
- 7.0_ppc64
- 7.7_ppc64
- 7.0_ppc64le
- 8.0_ppc64le
- 7.7_ppc64le
- 8.1_ppc64le
- 8.2_ppc64le
- 8.4_ppc64le
- 8.6_ppc64le
- 8.8_ppc64le
- 7.0
- 6.0
- 7.0
- 7.7
- 8.2
- 8.4
- 8.6
- 7.7
- 8.2
- 8.4
- 8.6
- 8.8
- 6.0
- 7.0
No data.
Red Hat Enterprise Linux 6
php-0:5.3.3-50.el6_10
Fixed · RHSA-2019:3287
Red Hat Enterprise Linux 7
php-0:5.4.16-46.1.el7_7
Fixed · RHSA-2019:3286
Red Hat Enterprise Linux 7.6 Extended Update Support
php-0:5.4.16-46.1.el7_6
Fixed · RHSA-2020:2835
Red Hat Enterprise Linux 8
php:7.2-8010020191030112723.dcfb48bd
Fixed · RHSA-2019:3735
Red Hat Enterprise Linux 8
php:7.3-8010020191030161321.dcfb48bd
Fixed · RHSA-2019:3736
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
php:7.2-8000020191113103901.5d58a046
Fixed · RHSA-2020:0322
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-php70-php-0:7.0.27-2.el6
Fixed · RHSA-2019:3724
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php70-php-0:7.0.27-2.el7
Fixed · RHSA-2019:3724
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php71-php-0:7.1.30-2.el7
Fixed · RHSA-2019:3300
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-php70-php-0:7.0.27-2.el7
Fixed · RHSA-2019:3724
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-php71-php-0:7.1.30-2.el7
Fixed · RHSA-2019:3300
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-php70-php-0:7.0.27-2.el7
Fixed · RHSA-2019:3724
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-php71-php-0:7.1.30-2.el7
Fixed · RHSA-2019:3300
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-php70-php-0:7.0.27-2.el7
Fixed · RHSA-2019:3724
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-php71-php-0:7.1.30-2.el7
Fixed · RHSA-2019:3300
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Enterprise Linux 5
php
Not affected
Red Hat Enterprise Linux 5
php53
Not affected
Red Hat Software Collections
rh-php73-php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | php-0:5.3.3-50.el6_10 | Fixed | RHSA-2019:3287 |
| Red Hat Enterprise Linux 7 | php-0:5.4.16-46.1.el7_7 | Fixed | RHSA-2019:3286 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | php-0:5.4.16-46.1.el7_6 | Fixed | RHSA-2020:2835 |
| Red Hat Enterprise Linux 8 | php:7.2-8010020191030112723.dcfb48bd | Fixed | RHSA-2019:3735 |
| Red Hat Enterprise Linux 8 | php:7.3-8010020191030161321.dcfb48bd | Fixed | RHSA-2019:3736 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | php:7.2-8000020191113103901.5d58a046 | Fixed | RHSA-2020:0322 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php70-php-0:7.0.27-2.el6 | Fixed | RHSA-2019:3724 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php70-php-0:7.0.27-2.el7 | Fixed | RHSA-2019:3724 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php71-php-0:7.1.30-2.el7 | Fixed | RHSA-2019:3300 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-php70-php-0:7.0.27-2.el7 | Fixed | RHSA-2019:3724 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-php71-php-0:7.1.30-2.el7 | Fixed | RHSA-2019:3300 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-php70-php-0:7.0.27-2.el7 | Fixed | RHSA-2019:3724 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-php71-php-0:7.1.30-2.el7 | Fixed | RHSA-2019:3300 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-php70-php-0:7.0.27-2.el7 | Fixed | RHSA-2019:3724 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-php71-php-0:7.1.30-2.el7 | Fixed | RHSA-2019:3300 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Enterprise Linux 5 | php | Not affected | n/a |
| Red Hat Enterprise Linux 5 | php53 | Not affected | n/a |
| Red Hat Software Collections | rh-php73-php | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Configuring nginx (or other server that implements the front-end part of the FPM protocol) to check for the existence of the target file before passing it to PHP FPM (e.g. "try_files $uri =404" or "if (-f $uri)" in nginx) for would prevent this vulnerability from happening.
Red Hat statement
This issue only affects instances running php-fpm under nginx server software as environment paths and parameters are handled by different code pieces depending on the server php-fpm is running under. The code where this issue is found is used exclusively when php-fpm detects the request came through an nginx server. Red Hat Product Security team rated this issue as having a Critical security impact as an attacker may take advantage from the existing bug to cause Remote Code Execution on network exposed software.
Red Hat mitigation
1) Check your nginx configuration files, specially the ones related to php-fpm for presence of pattern bellow on fastcgi_split_path_info regex and PATH_INFO parameter: ~~~ fastcgi_split_path_info ^(.+?\.php)(/.*)$; fastcgi_param PATH_INFO $fastcgi_path_info; ~~~ 2) If fastcgi_split_path_info regex matches with the one above, for each fastcgi_param PATH_INFO entry perform the following change: ~~~ fastcgi_param PATH_INFO $fastcgi_path_info if_not_empty; ~~~ This step will allow you to safely continue using PATH_INFO parameter while the patch is not applied. 3) Restart your nginx instance: ~~~ systemctl restart nginx ~~~
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
Date Added
Mar 25, 2022
Patch Due
Apr 15, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 99.78% (0.99780) | 99.95th | v5 (v2026.06.15) |
| Jun 15, 2026 | 99.47% (0.99470) | 99.94th | v5 (v2026.06.15) |
| Mar 17, 2025 | 94.11% (0.94114) | 99.90th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.41% (0.97414) | 99.95th | v3 (v2023.03.01) |
| Jul 17, 2024 | 97.31% (0.97315) | 99.89th | v3 (v2023.03.01) |
| Jun 6, 2024 | 97.47% (0.97472) | 99.97th | v3 (v2023.03.01) |
| May 4, 2024 | 97.45% (0.97447) | 99.95th | v3 (v2023.03.01) |
| Feb 6, 2024 | 97.47% (0.97472) | 99.96th | v3 (v2023.03.01) |
| Jul 8, 2023 | 97.47% (0.97465) | 99.93th | v3 (v2023.03.01) |
| May 8, 2023 | 97.42% (0.97421) | 99.88th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.38% (0.97375) | 99.80th | v3 (v2023.03.01) |
| Mar 6, 2023 | 96.00% (0.96000) | 99.99th | v2 (v2022.01.01) |
| Feb 4, 2022 | 96.00% (0.96000) | 99.99th | v2 (v2022.01.01) |
| Feb 3, 2022 | 81.42% (0.81421) | 99.86th | v1 |
| Sep 1, 2021 | 81.42% (0.81421) | 99.94th | v1 |
| Jul 23, 2021 | 81.42% (0.81421) | 0.00th | v1 |
| Apr 14, 2021 | 80.86% (0.80860) | 0.00th | v1 |
References (34)
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Jan/40 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3286 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3287 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3299 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3300 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3724 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3735 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3736 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0322 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11043 Vendor Advisory
- https://bugs.php.net/bug.php?id=78599 x_refsource_CONFIRMExploitIssue TrackingPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1766378 Issue Tracking
- https://github.com/neex/phuip-fpizdam x_refsource_MISCExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/ vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/ vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/ vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-11043
- https://seclists.org/bugtraq/2020/Jan/44 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20191031-0003/ x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT210919 x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K75408500?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4166-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4166-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11043 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2019-11043
- https://www.debian.org/security/2019/dsa-4552 vendor-advisoryx_refsource_DEBIANMailing ListThird Party Advisory
- https://www.debian.org/security/2019/dsa-4553 vendor-advisoryx_refsource_DEBIANMailing ListThird Party Advisory
- https://www.nginx.com/blog/php-fpm-cve-2019-11043-vulnerability-nginx/
- https://www.synology.com/security/advisory/Synology_SA_19_36 x_refsource_CONFIRMThird Party Advisory
- https://www.tenable.com/security/tns-2021-14 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.