Intel

AIKIDO-2025-10257

php-fpm is vulnerable to Use-After-Free

Use-After-Free Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 22, 2025

30

Low Risk

This Affects:

osphp-fpm
5.4.0 - 8.4.5
Fixed in 8.4.6
Are you affected? Scan for Free

TL;DR

Affected versions contain a use-after-free vulnerability caused by improper class destruction during module shutdown. Specifically, child classes reference parent class structures that are freed earlier in the clean_module_classes() function, leading to heap-use-after-free conditions.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

php-fpm is vulnerable to Use-After-Free in versions 5.4.0 - 8.4.5.

How to fix this

Upgrade the php-fpm library to a patch version.