Integer Overflow or Wraparound Affecting php-pecl-zip-debuginfo package, versions <0:1.22.3-1.module+el9.7.0+40005+715283ec


Severity

Recommended
0.0
high
0
10

Based on Rocky Linux security rating.

Threat Intelligence

EPSS
0.06% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Integer Overflow or Wraparound vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-ROCKY9-PHPPECLZIPDEBUGINFO-15134016
  • published29 Jan 2026
  • disclosed27 Dec 2025

Introduced: 27 Dec 2025

CVE-2025-14178  (opens in a new tab)
CWE-190  (opens in a new tab)

How to fix?

Upgrade Rocky-Linux:9 php-pecl-zip-debuginfo to version 0:1.22.3-1.module+el9.7.0+40005+715283ec or higher.
This issue was patched in RLSA-2026:1409.

NVD Description

Note: Versions mentioned in the description apply only to the upstream php-pecl-zip-debuginfo package and not the php-pecl-zip-debuginfo package as distributed by Rocky-Linux. See How to fix? for Rocky-Linux:9 relevant fixed versions and status.

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server.

CVSS Base Scores

version 3.1