Back

HIGH

Temporary files are not cleaned after OOM when parsing HTTP request data

Published May 20, 2020

Description

In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or field names could lead PHP engine to try to allocate oversized memory storage, hit the memory limit and stop processing the request, without cleaning up temporary files created by upload request. This potentially could lead to accumulation of uncleaned temporary files exhausting the disk space on the target server.

Affected products

Remediation

Vendor solution

Setting post_max_size to value significantly lower than the memory limit prevents this issue from being exploited. Disabling file uploads also prevents this issue from happening.

Red Hat statement

The severity of this issue is considered Moderate because it requires an unlikely large `post_max_size` to be configured.

Red Hat mitigation

Ensure that `post_max_size` is set to a value less than 2GB, or remains default.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner php
Published May 20, 2020
Updated Sep 16, 2024
Reserved Apr 9, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 14, 2020