CVE-2019-11043: PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 99.8% chance of exploitation in the next 30 days.

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only; version 31 only
  • PHP PHP: from 7.1.0, before 7.1.33 (fixed in 7.1.33); from 7.2.0, before 7.2.24 (fixed in 7.2.24); from 7.3.0, before 7.3.11 (fixed in 7.3.11)
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.7 only; version 8.1 only; version 8.2 only; version 8.4 only; version 8.6 only; version 8.8 only
  • Red Hat Enterprise Linux Eus Compute Node: version 7.7 only
  • Red Hat Enterprise Linux For Arm 64: version 8.0_aarch64 only
  • Red Hat Enterprise Linux For Arm 64 Eus: version 8.1_aarch64 only; version 8.2_aarch64 only; version 8.4_aarch64 only; version 8.6_aarch64 only; version 8.8_aarch64 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 6.0_s390x only; version 7.0_s390x only; version 8.0_s390x only
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 7.7_s390x only; version 8.1_s390x only; version 8.2_s390x only; version 8.4_s390x only; version 8.6_s390x only; version 8.8_s390x only
  • Red Hat Enterprise Linux For Power Big Endian: version 6.0_ppc64 only; version 7.0_ppc64 only
  • Red Hat Enterprise Linux For Power Big Endian Eus: version 7.7_ppc64 only
  • Red Hat Enterprise Linux For Power Little Endian: version 7.0_ppc64le only; version 8.0_ppc64le only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 7.7_ppc64le only; version 8.1_ppc64le only; version 8.2_ppc64le only; version 8.4_ppc64le only; version 8.6_ppc64le only; version 8.8_ppc64le only
  • Red Hat Enterprise Linux For Scientific Computing: version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.7 only; version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server Tus: version 7.7 only; version 8.2 only; version 8.4 only; version 8.6 only; version 8.8 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Red Hat Software Collections: version 1.0 only
  • Tenable Tenable.sc: before 5.19.0 (fixed in 5.19.0)

Published 2019-10-28. Last modified 2026-06-17.