CVE-2015-6831: Debian Linux

High severity, CVSS 7.3. EPSS: 7.1% chance of exploitation in the next 30 days.

Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • PHP PHP: before 5.4.44 (fixed in 5.4.44); from 5.5.0, before 5.5.28 (fixed in 5.5.28); from 5.6.0, before 5.6.12 (fixed in 5.6.12)

Published 2016-01-19. Last modified 2026-06-17.