yocto ▾
›
master ▾
›
vulnerability
›
CVE-2022-4900
Component Overview
Vulnerability Overview
Name
CVE-2022-4900
Source
NVD (
link
)
Debian (
link
)
Description
A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.
CWEs
CWE-119
CWE-787
Published Date
Nov 2, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://access.redhat.com/security/cve/CVE-2022-4900
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2179880
Issue Tracking
https://security.netapp.com/advisory/ntap-20231130-0008/
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2022-4900
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2179880
Issue Tracking
https://security.netapp.com/advisory/ntap-20231130-0008/
Third Party Advisory
Analysis
#
Affected Component
Analysis
php
False Positive
Vulnerability Ratings
#
6.2
CVSSv31
5.5
CVSSv31
Others affected components
#
Name
Project
Project Version
Version
Status
php
buildroot
2025.02.x
8.3.31
Not Affected
php
buildroot
master
8.5.7
Not Affected
php8
openwrt
master
8.4.16-r4
Not Affected
php8
openwrt
openwrt-25.12
8.4.21-r1
Not Affected
php
yocto
kirkstone
8.1.34
Not Affected
php
yocto
scarthgap
8.2.31
Not Affected