Heap Buffer Overflow in PHP Affects Multiple Versions
CVE-2025-14178
6.5MEDIUM
What is CVE-2025-14178?
A heap buffer overflow vulnerability has been identified in specific versions of PHP that occurs in the array_merge() function when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE. This issue is triggered by an integer overflow during the precomputation of element counts using zend_hash_num_elements(). The vulnerability poses a risk of memory corruption or server crashes, ultimately affecting the integrity and availability of the targeted server.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PHP 8.1.*
PHP 8.1.* < 8.1.34
PHP 8.2.* < 8.2.30
