Image reports › php
php — vulnerabilities, FIPS 140-3 and fixes
mirror.gcr.io/library/php · Debian GNU/Linux 13 (trixie)
Latest: php:latest · checked 2026-09-25
Not FIPS-ready
No. php:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: 183 known vulnerabilities
183 known vulnerabilities in 44 packages (12 high); none has a fix available yet.
Critical, high and exploited vulnerabilities in latest
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high | CVE-2019-19449 | linux-libc-dev 6.12.107-1 | no fix yet | In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated). |
| high | CVE-2019-19814 | linux-libc-dev 6.12.107-1 | no fix yet | In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this. |
| high | CVE-2021-3847 | linux-libc-dev 6.12.107-1 | no fix yet | An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system. |
| high | CVE-2024-21803 | linux-libc-dev 6.12.107-1 | no fix yet | Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_bluetooth.C. |
| high | CVE-2024-26461 | libgssapi-krb5-2 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libk5crypto3 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkrb5-3 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkrb5support0 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-25062 | libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3 | no fix yet | An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free. |
| high | CVE-2024-41013 | linux-libc-dev 6.12.107-1 | no fix yet | In the Linux kernel, the following vulnerability has been resolved: |
| high | CVE-2024-41014 | linux-libc-dev 6.12.107-1 | no fix yet | In the Linux kernel, the following vulnerability has been resolved: |
| high | CVE-2021-3864 | linux-libc-dev 6.12.107-1 | no fix yet | A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a resul |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest | Not FIPS-ready | C 183 | 2026-09-25 | Full report |