CVE-2014-6228: Facebook Hiphop Virtual Machine

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted arguments to the chunk_split function.

Affected products

  • Facebook Hiphop Virtual Machine: up to and including 3.2.0

Published 2014-12-28. Last modified 2026-06-17.