Out-of-bounds read in urldecode() on NetBSD
Published May 10, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.40%
Description
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.
Affected products
-
- Version 8.2.*StatusaffectedConstraints<8.2.31
- Version 8.3.*StatusaffectedConstraints<8.3.31
- Version 8.4.*StatusaffectedConstraints<8.4.21
- Version 8.5.*StatusaffectedConstraints<8.5.6
- Version
No data.
Red Hat Enterprise Linux 10
php-0:8.3.31-1.el10_2
Fixed · RHSA-2026:23388
Red Hat Enterprise Linux 10
php8.4-0:8.4.21-1.el10_2
Fixed · RHSA-2026:22649
Red Hat Enterprise Linux 8
php:7.4-8100020260604072603.f7998665
Fixed · RHSA-2026:34354
Red Hat Enterprise Linux 8
php:8.2-8100020260521052503.f7998665
Fixed · RHSA-2026:22305
Red Hat Enterprise Linux 9
php-0:8.0.30-6.el9_8
Fixed · RHSA-2026:33449
Red Hat Enterprise Linux 9
php:8.2-9080020260521080715.9
Fixed · RHSA-2026:22143
Red Hat Enterprise Linux 9
php:8.3-9080020260521113736.9
Fixed · RHSA-2026:22142
Red Hat Hardened Images
php-main-8.5.6-1.hum1
Fixed · RHSA-2026:14125
Red Hat Enterprise Linux 6
php
Fix deferred
Red Hat Enterprise Linux 7
php
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/code-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | php-0:8.3.31-1.el10_2 | Fixed | RHSA-2026:23388 |
| Red Hat Enterprise Linux 10 | php8.4-0:8.4.21-1.el10_2 | Fixed | RHSA-2026:22649 |
| Red Hat Enterprise Linux 8 | php:7.4-8100020260604072603.f7998665 | Fixed | RHSA-2026:34354 |
| Red Hat Enterprise Linux 8 | php:8.2-8100020260521052503.f7998665 | Fixed | RHSA-2026:22305 |
| Red Hat Enterprise Linux 9 | php-0:8.0.30-6.el9_8 | Fixed | RHSA-2026:33449 |
| Red Hat Enterprise Linux 9 | php:8.2-9080020260521080715.9 | Fixed | RHSA-2026:22143 |
| Red Hat Enterprise Linux 9 | php:8.3-9080020260521113736.9 | Fixed | RHSA-2026:22142 |
| Red Hat Hardened Images | php-main-8.5.6-1.hum1 | Fixed | RHSA-2026:14125 |
| Red Hat Enterprise Linux 6 | php | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | php | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/code-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-7258 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468561 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28968 Advisory
- https://github.com/php/php-src/security/advisories/GHSA-m8rr-4c36-8gq4 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-7258
- https://www.cve.org/CVERecord?id=CVE-2026-7258
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-7258 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2468561 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28968 | Advisory | |
| https://github.com/php/php-src/security/advisories/GHSA-m8rr-4c36-8gq4 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-7258 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-7258 |
Change history (0)
No recorded changes yet.