CVE-2021-21708 Details
Description
In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugs.php.net/bug.php?id=81708 | CVE | ExploitIssue TrackingPatchVendor Advisory |
| https://security.gentoo.org/glsa/202209-20 | CVE | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20220325-0004/ | CVE | Third Party Advisory |
| https://bugs.php.net/bug.php?id=81708 | [email protected] | ExploitIssue TrackingPatchVendor Advisory |
| https://security.gentoo.org/glsa/202209-20 | [email protected] | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20220325-0004/ | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| php php | >= 7.4.0, < 7.4.28 >= 8.0.0, < 8.0.16 >= 8.1.0, < 8.1.3 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 7, 2022 | Modified Analysis | [email protected] |
| Sep 29, 2022 | CVE Modified | [email protected] |
| Apr 18, 2022 | Modified Analysis | [email protected] |
| Mar 25, 2022 | CVE Modified | [email protected] |
| Mar 7, 2022 | Initial Analysis | [email protected] |
| Feb 27, 2022 | CVE Modified | [email protected] |