In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.
The object deduplication mechanism in the SOAP extension stores pointers to PHP objects in a global map without incrementing the reference counter. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary results map, causing the original PHP object to be freed while its pointer (dangling pointer) remains in the map. A subsequent href reference to the freed node copies this invalid pointer to the result. Since PHP string allocations may reuse the freed memory area, an attacker controlling SOAP request content can trigger arbitrary code execution.
An unauthenticated attacker can achieve remote code execution (RCE) on a server processing malicious SOAP requests, which may lead to complete system compromise and threats to data confidentiality, integrity, and availability.
PHP should be updated as soon as possible to version 8.2.31, 8.3.31, 8.4.21, or 8.5.6 (depending on the branch in use). Until the patch is deployed, consider disabling the SOAP extension (if not required) or restricting access to SOAP endpoints at the firewall level.
PHP versions 8.2.x before 8.2.31, 8.3.x before 8.3.31, 8.4.x before 8.4.21, and 8.5.x before 8.5.6 — affects installations with the SOAP extension enabled.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:RedPHP
APPPhp8.2.0 – 8.2.31 (excl.)8.3.0 – 8.3.31 (excl.)8.4.0 – 8.4.21 (excl.)8.5.0 – 8.5.6 (excl.)
Related vulnerabilities
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit
RCE w PHP-CGI poprzez wstrzyknięcie opcji wiersza poleceń
PHP use-after-free przez __set lub ??= z wyjątkami — RCE
PHP PDO SQLite — błędne cytowanie ciągów prowadzące do SQL injection
PHP: integer overflow w ldap_escape() prowadzący do out-of-bounds write