CVE-2015-4116: Opensuse Leap
Critical severity, CVSS 9.8. EPSS: 5.5% chance of exploitation in the next 30 days.
Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP before 5.5.27 and 5.6.x before 5.6.11 allows remote attackers to execute arbitrary code by triggering a failed SplMinHeap::compare operation.
Affected products
- Opensuse Leap: version 42.1 only
- PHP PHP: up to and including 5.5.26; version 5.6.0 only; version 5.6.1 only; version 5.6.2 only; version 5.6.3 only; version 5.6.4 only; …
Published 2016-05-16. Last modified 2026-06-17.