PHP SplDoublyLinkedList Use-After-Free

A use-after-free vulnerability was discovered in unserialize() with SplDoublyLinkedList object’s deserialization that can be abused for leaking arbitrary memory blocks or execute arbitrary code remotely.

Leave a Reply