CVE-2015-6835 is a use-after-free vulnerability in PHP's session deserialization logic affecting PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13. The flaw is triggered when the session deserializer performs multiple php_var_unserialize calls and mishandles object lifetime, allowing freed memory to be reused while still referenced. In practice, crafted session content can cause PHP to deserialize truncated or malformed serialized data into unintended objects, creating a path to memory corruption. In exploit chains documented at the time, the bug was particularly relevant when session data was stored outside PHP's standard session storage, such as in MySQL-backed session stores, where truncation of serialized session data could transform attacker-controlled input into a dangerous deserialization state. Successful exploitation can lead to arbitrary code execution or application crashes.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A historical PHP unserialize-related use-after-free vulnerability mentioned as part of a broader lineage of similar bugs.
PHPのセッションデコード/デシリアライズ挙動に関する脆弱性で、Joomla!のCVE-2015-8562成立の直接要因として説明されている関連脆弱性。
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.