What is CVE-2026-17544?
CVE-2026-17544 is an out-of-bounds write vulnerability in PHP's 'bccomp()' function caused by attacker-provided inputs. This flaw can lead to stack and heap corruption in PHP versions 8.4.* before 8.4.24 and 8.5.* before 8.5.9. Users are strongly advised to update to the latest patched versions immediately.
Azərbaycanca: CVE-2026-17544 PHP-in 'bccomp()' funksiyasında təhqibçi tərəfindən təqdim edilən girişlər nəticəsində yaranan out-of-bounds write zəifliyidir. Bu boşluq 8.4.24-dən əvvəlki 8.4.* və 8.5.9-dan əvvəlki 8.5.* PHP versiyalarında stack və heap korrupsiyasına səbəb ola bilər. İstifadəçilərə dərhal təsirlənmiş versiyalardan ən son yamaqlanmış versiyalara yeniləmə etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
In which PHP function was CVE-2026-17544 discovered?
CVE-2026-17544 was discovered in PHP's 'bccomp()' function.
Which PHP versions are affected by the CVE-2026-17544 vulnerability?
PHP versions 8.4.* prior to 8.4.24 and 8.5.* prior to 8.5.9 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.