PT-2021-4560 · Php+10 · Php+10

Published

2021-10-21

·

Updated

2025-08-11

·

CVE-2021-21703

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions 7.3.x through 7.3.31 PHP versions 7.4.x through 7.4.24 PHP versions 8.0.x through 8.0.11
Description The issue is related to the PHP FPM SAPI component, where child worker processes can access and modify memory shared with the main process, potentially causing the root process to conduct invalid memory reads and writes. This can be exploited to escalate privileges from a local unprivileged user to the root user. The vulnerability is associated with errors in access control when running the PHP FPM process.
Recommendations For PHP versions 7.3.x through 7.3.31, update to a version above 7.3.31. For PHP versions 7.4.x through 7.4.24, update to a version above 7.4.24. For PHP versions 8.0.x through 8.0.11, update to a version above 8.0.11. As a temporary workaround, consider restricting access to the PHP FPM SAPI component until a patch is available.

Exploit

Fix

Improper Access Control

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2022:1935
ALT-PU-2021-3131
ALT-PU-2021-3132
ALT-PU-2021-3151
ALT-PU-2021-3178
ALT-PU-2021-3200
ALT-PU-2021-3212
ALT-PU-2021-3645
BDU:2021-05228
BIT-LIBPHP-2021-21703
BIT-PHP-2021-21703
BIT-PHP-MIN-2021-21703
CESA-2022_1935
CVE-2021-21703
DLA-2794-1
DSA-4992-1
DSA-4993-1
MGASA-2021-0501
OESA-2021-1430
OPENSUSE-SU-2021:1570-1
OPENSUSE-SU-2021:3943-1
OPENSUSE-SU-2021_1570-1
OPENSUSE-SU-2021_3943-1
OPENSUSE-SU-2022_0679-1
OPENSUSE-SU-2022_3661-1
OPENSUSE-SU-2022_4067-1
OPENSUSE-SU-2022_4069-1
OPENSUSE-SU-2024:11585-1
OPENSUSE-SU-2024:11594-1
RHSA-2022:1935
RHSA-2022:5491
RHSA-2022_1935
RLSA-2022:1935
SUSE-SU-2021:3726-1
SUSE-SU-2021:3727-1
SUSE-SU-2021:3943-1
SUSE-SU-2021_3726-1
SUSE-SU-2021_3727-1
SUSE-SU-2021_3943-1
SUSE-SU-2022:0679-1
SUSE-SU-2022:3661-1
SUSE-SU-2022:4067-1
SUSE-SU-2022:4068-1
SUSE-SU-2022:4069-1
USN-5125-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Php
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu