vulnerability
Alma Linux: CVE-2022-31628: Moderate: php:8.0 security update (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 1 | (AV:L/AC:L/Au:M/C:N/I:N/A:P) | Sep 28, 2022 | Feb 22, 2023 | Apr 20, 2026 |
Severity
1
CVSS
(AV:L/AC:L/Au:M/C:N/I:N/A:P)
Published
Sep 28, 2022
Added
Feb 22, 2023
Modified
Apr 20, 2026
Description
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.
Solutions
alma-upgrade-apcu-panelalma-upgrade-libzipalma-upgrade-libzip-develalma-upgrade-libzip-toolsalma-upgrade-phpalma-upgrade-php-bcmathalma-upgrade-php-clialma-upgrade-php-commonalma-upgrade-php-dbaalma-upgrade-php-dbgalma-upgrade-php-develalma-upgrade-php-embeddedalma-upgrade-php-enchantalma-upgrade-php-ffialma-upgrade-php-fpmalma-upgrade-php-gdalma-upgrade-php-gmpalma-upgrade-php-intlalma-upgrade-php-jsonalma-upgrade-php-ldapalma-upgrade-php-mbstringalma-upgrade-php-mysqlndalma-upgrade-php-odbcalma-upgrade-php-opcachealma-upgrade-php-pdoalma-upgrade-php-pearalma-upgrade-php-pecl-apcualma-upgrade-php-pecl-apcu-develalma-upgrade-php-pecl-rrdalma-upgrade-php-pecl-xdebugalma-upgrade-php-pecl-xdebug3alma-upgrade-php-pecl-zipalma-upgrade-php-pgsqlalma-upgrade-php-processalma-upgrade-php-snmpalma-upgrade-php-soapalma-upgrade-php-xmlalma-upgrade-php-xmlrpc
References
- CVE-2022-31628
- https://attackerkb.com/topics/CVE-2022-31628
- CWE-674
- CWE-835
- EUVD-EUVD-2022-53080
- https://errata.almalinux.org/8/ALSA-2023-0848.html
- https://errata.almalinux.org/8/ALSA-2023-2903.html
- https://errata.almalinux.org/9/ALSA-2023-0965.html
- https://errata.almalinux.org/9/ALSA-2023-2417.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53080
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.