CVE-2019-9025: Netapp Storage Automation Store

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_mbregex.c can cause PHP to execute memcpy() with a negative argument, which could read and write past buffers allocated for the data.

Affected products

  • Netapp Storage Automation Store: affected versions not specified
  • PHP PHP: from 7.3.0, before 7.3.1 (fixed in 7.3.1)

Published 2019-02-22. Last modified 2026-06-17.