CVE-2017-8923: PHP

Critical severity, CVSS 9.8. EPSS: 7.2% chance of exploitation in the next 30 days.

The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.

Affected products

  • PHP PHP: before 7.4.24 (fixed in 7.4.24); from 8.0.0, before 8.0.11 (fixed in 8.0.11)

Published 2017-05-12. Last modified 2026-06-17.