CVE-2022-31627 is a critical heap corruption vulnerability affecting PHP versions 8.1.x below 8.1.8, specifically within fileinfo functions like finfo_buffer. This flaw stems from an incorrect patch to the underlying libmagic library, leading to improper memory deallocation. With a CVSS score of 9.8 (CRITICAL), it can be exploited remotely without user interaction, potentially resulting in complete compromise of confidentiality, integrity, and availability. While no active exploitation, Metasploit modules, or ExploitDB entries are currently reported, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.1.0, < 8.1.8CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.