Log tampering via incorrect flush-marker offset
Published Oct 8, 2024 · Updated Nov 3, 2025
Log injection in PHP-FPM 8.1.0 through 8.1.29, 8.2.0 through 8.2.23, and 8.3.0 through 8.3.11 allows local users to alter logs. In fpm_stdio_child_said, a split FPM_STDIO_CMD_FLUSH match advances the input start by the partial-match position rather than the marker bytes consumed, inserting marker bytes or deleting up to four message characters. The flaw requires catch_workers_output to be enabled and control of worker stdout or stderr; syslog also truncates content after an injected NUL.
Summary
What happened
Log injection in PHP-FPM 8.1.0 through 8.1.29, 8.2.0 through 8.2.23, and 8.3.0 through 8.3.11 allows local users to alter logs. In fpm_stdio_child_said, a split FPM_STDIO_CMD_FLUSH match advances the input start by the partial-match position rather than the marker bytes consumed, inserting marker bytes or deleting up to four message characters. The flaw requires catch_workers_output to be enabled and control of worker stdout or stderr; syslog also truncates content after an injected NUL.
The record
- CVE
- CVE-2024-9026
- Published
- Oct 8, 2024
- Updated
- Nov 3, 2025
- Vendor
- The PHP Group
- Product
- PHP
- Classifications
- CWE-117, CWE-158, T1070.002
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Oct 8, 2024CVE publishedPublication date reported by the CVE source.
- Nov 3, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=8.1.0 <8.1.30
- Affected versionversion=8.1.* <8.1.30
- Affected versionversion=8.2.0 <8.2.24
- Affected versionversion=8.2.* <8.2.24
- Affected versionversion=8.3.0 <8.3.12
- Affected versionversion=8.3.* <8.3.12
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Upstream PHP-FPM split flush-marker regression testsproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo