---
id: CVE-2026-92842
title: >-
  The convert.base64-encode, convert.quoted-printable-encode and
  convert.quoted-printable-decode stream filters accept a line-break-chars
  option whose length is tracked separately from the string itself
summary: >-
  The convert.base64-encode, convert.quoted-printable-encode and
  convert.quoted-printable-decode stream filters accept a line-break-chars
  option whose length is tracked separately from the string itself. The filter
  constructors duplicate t…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-122
  - CWE-125
vendor: PHP Group
product: ext-standard
affected:
  - ext-standard >= 8.2.* < 8.2.34
  - ext-standard >= 8.3.* < 8.3.35
  - ext-standard >= 8.4.* < 8.4.26
  - ext-standard >= 8.5.* < 8.5.11
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T22:18:49.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92842'
references:
  - url: 'https://github.com/php/php-src/security/advisories/GHSA-88hq-2827-7pg6'
    label: security@php.net
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-92842.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-92842'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2541662'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-92842'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92842'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70720'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ingestedAt: '2026-09-25T21:19:40.217Z'
patched:
  - hardened_images
---

## Overview

The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:70720** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70720)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-26 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-92842.json)
