CVE-2019-9020: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 10.1% chance of exploitation in the next 30 days.

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in ext/xmlrpc/libxmlrpc/xml_element.c.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only
  • Debian Debian Linux: version 9.0 only
  • Netapp Storage Automation Store: affected versions not specified
  • Opensuse Leap: version 42.3 only
  • PHP PHP: before 5.6.40 (fixed in 5.6.40); from 7.0.0, before 7.1.26 (fixed in 7.1.26); from 7.2.0, before 7.2.14 (fixed in 7.2.14); from 7.3.0, before 7.3.1 (fixed in 7.3.1)

Published 2019-02-22. Last modified 2026-06-17.