CVE Vulnerabilities

CVE-2016-5768

Double Free

Published: Aug 07, 2016 | Modified: Apr 12, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:N/A:P
RedHat/V3
3.7 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by leveraging a callback exception.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp*5.5.36 (including)
PhpPhp5.6.0-alpha1 (including)5.6.0-alpha1 (including)
PhpPhp5.6.0-alpha2 (including)5.6.0-alpha2 (including)
PhpPhp5.6.0-alpha3 (including)5.6.0-alpha3 (including)
PhpPhp5.6.0-alpha4 (including)5.6.0-alpha4 (including)
PhpPhp5.6.0-alpha5 (including)5.6.0-alpha5 (including)
PhpPhp5.6.0-beta1 (including)5.6.0-beta1 (including)
PhpPhp5.6.0-beta2 (including)5.6.0-beta2 (including)
PhpPhp5.6.0-beta3 (including)5.6.0-beta3 (including)
PhpPhp5.6.0-beta4 (including)5.6.0-beta4 (including)
PhpPhp5.6.1 (including)5.6.1 (including)
PhpPhp5.6.2 (including)5.6.2 (including)
PhpPhp5.6.3 (including)5.6.3 (including)
PhpPhp5.6.4 (including)5.6.4 (including)
PhpPhp5.6.5 (including)5.6.5 (including)
PhpPhp5.6.6 (including)5.6.6 (including)
PhpPhp5.6.7 (including)5.6.7 (including)
PhpPhp5.6.8 (including)5.6.8 (including)
PhpPhp5.6.9 (including)5.6.9 (including)
PhpPhp5.6.10 (including)5.6.10 (including)
PhpPhp5.6.11 (including)5.6.11 (including)
PhpPhp5.6.12 (including)5.6.12 (including)
PhpPhp5.6.13 (including)5.6.13 (including)
PhpPhp5.6.14 (including)5.6.14 (including)
PhpPhp5.6.15 (including)5.6.15 (including)
PhpPhp5.6.16 (including)5.6.16 (including)
PhpPhp5.6.17 (including)5.6.17 (including)
PhpPhp5.6.18 (including)5.6.18 (including)
PhpPhp5.6.19 (including)5.6.19 (including)
PhpPhp5.6.20 (including)5.6.20 (including)
PhpPhp5.6.21 (including)5.6.21 (including)
PhpPhp5.6.22 (including)5.6.22 (including)
PhpPhp7.0.0 (including)7.0.0 (including)
PhpPhp7.0.1 (including)7.0.1 (including)
PhpPhp7.0.2 (including)7.0.2 (including)
PhpPhp7.0.3 (including)7.0.3 (including)
PhpPhp7.0.4 (including)7.0.4 (including)
PhpPhp7.0.5 (including)7.0.5 (including)
PhpPhp7.0.6 (including)7.0.6 (including)
PhpPhp7.0.7 (including)7.0.7 (including)
Red Hat Enterprise Linux 7RedHatphp-0:5.4.16-42.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-php56-0:2.3-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-php56-php-0:5.6.25-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-php56-php-pear-1:1.9.5-4.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-php56-0:2.3-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-php56-php-0:5.6.25-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-php56-php-pear-1:1.9.5-4.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-php56-0:2.3-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-php56-php-0:5.6.25-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-php56-php-pear-1:1.9.5-4.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-php56-0:2.3-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-php56-php-0:5.6.25-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-php56-php-pear-1:1.9.5-4.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSRedHatrh-php56-0:2.3-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSRedHatrh-php56-php-0:5.6.25-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSRedHatrh-php56-php-pear-1:1.9.5-4.el7*
Php5Ubuntuesm-infra-legacy/trusty*
Php5Ubuntutrusty*
Php5Ubuntutrusty/esm*
Php5Ubuntuwily*
Php7.0Ubuntuesm-infra/xenial*
Php7.0Ubuntuupstream*
Php7.0Ubuntuxenial*

Potential Mitigations

References