CVE-2017-8923: PHP
Critical severity, CVSS 9.8. EPSS: 7.2% chance of exploitation in the next 30 days.
The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.
Affected products
- PHP PHP: before 7.4.24 (fixed in 7.4.24); from 8.0.0, before 8.0.11 (fixed in 8.0.11)
Published 2017-05-12. Last modified 2026-06-17.