CVE-2022-31626 is a buffer overflow in PHP's PDO MySQL extension when it uses the mysqlnd driver. PHP versions 7.4.x before 7.4.30, 8.0.x before 8.0.20, and 8.1.x before 8.1.7 are affected. An excessively long password supplied for a connection can overflow a buffer when a third party is permitted to control both the database host and connection password, potentially leading to remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a multi-case PHP exploitation research corpus rather than a single exploit. It contains five exploit environments: RCE-CVE-2022-31626, RCE-CVE-2024-2961, SBE-CVE-2019-6977, RCE-N1CTF-php_master, and RCE-SecurinetsCTF-I_hate_php, plus a large Reproduce/ tree for building vulnerable images, validating mitigations, and benchmarking two defensive patch sets (hashtable and refcount guards). Core exploit capability: each main exploit script achieves memory disclosure followed by corruption of Zend/PHP internal structures to redirect execution to system/popen/destructor gadgets, ultimately executing shell commands and exposing output through a file such as 1.php. The payloads are basic hardcoded shell commands (uname/date), so maturity is OPERATIONAL rather than framework-grade weaponized. Per-case structure: - RCE-CVE-2022-31626: Python exploit against a PHP page that accepts MySQL connection parameters and JSON input. The environment includes a rogue_sql_server.py listener on TCP/3306 to emulate a MySQL server and induce the vulnerable state. The exploit performs two leaks (heap and zend), probes candidate libc offsets, then writes a command string and pivots execution to libc system(). - RCE-CVE-2024-2961: Python exploit against a PHP page calling md5_file() on attacker-controlled php://filter/iconv input. It abuses the glibc ISO-2022-CN-EXT conversion path to obtain heap/zend leaks and then corrupts structures to call system(). - RCE-N1CTF-php_master: Includes a full vulnerable PHP web app (DataForm) with session-backed serialized state and compression/inflate operations. The exploit drives the /dataform endpoint through add/insert/append/delete actions, leaks heap data from error snapshots, constructs fake Zend structures, and brute-probes libc deltas until command execution succeeds. - RCE-SecurinetsCTF-I_hate_php: Includes a custom PHP extension (juice.so) implementing xorBMP(). The exploit sends crafted base64 BMPs and JSON layout data to trigger memory corruption, derives heap and PHP text base addresses from returned BMP data, forges a HashTable/frame, and redirects execution to zif_popen. - SBE-CVE-2019-6977: A PHP-only sandbox-bypass / info-leak / code-exec chain. The target script itself contains the exploitation primitives, exposing ?leak and ?pwn modes. The Python wrapper fetches leaked addresses, computes a gadget address, triggers the overwrite, and polls 1.php for command output. Repository support content: - Dockerfiles for each case build pinned PHP source revisions with custom hardening/experimental patches applied. - Reproduce/Patch-hashtable and Reproduce/Patch-refcnt contain mitigation patches, verification harnesses, and benchmark Dockerfiles. These are not exploits; they are defensive evaluation artifacts showing whether the included exploits still succeed after patching. - Reproduce/run_reliability_100.sh and run_performance_tests.sh automate repeated exploit runs and performance measurements. - Misc/static_analysis.ql and patch files document research into allocator/hashtable/refcount hardening. Overall purpose: to provide reproducible exploit demonstrations for several PHP memory-corruption cases and challenge-derived targets, alongside experimental mitigations and benchmarking infrastructure. The code is clearly exploit-oriented, not merely detection, and the included web endpoints, local FastCGI backends, rogue MySQL service, and output files are all fingerprintable operational artifacts.
This repository contains a proof-of-concept exploit for CVE-2022-31626, a buffer overflow vulnerability in PHP's pdo_mysql extension when used with the mysqlnd driver. The exploit is implemented in Python (exploit.py) and targets PHP versions 7.4.x < 7.4.30, 8.0.x < 8.0.20, and 8.1.x < 8.1.7. The exploit works by sending a specially crafted POST request to a PHP endpoint (e.g., mysql_admin.php) with a very long password and specific key/value pairs, triggering a buffer overflow that can leak heap addresses or achieve remote code execution (RCE), depending on configuration. The README.md provides a brief description of the vulnerability. The exploit requires the attacker to be able to supply the MySQL host and password to the PHP application, and the application must expose a vulnerable endpoint. The main attack vector is network-based, targeting a web-accessible PHP script. The code is a proof-of-concept and may require adaptation for different environments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PHP buffer-overflow vulnerability in which an excessively long password can trigger remote code execution. The notice identifies affected packages on Rocky Linux 8 and directs administrators to apply the CIQ crlsa-2022_5468 advisory updates.
A PHP buffer-overflow vulnerability in which an excessively long password can trigger remote code execution. The notice identifies Rocky Linux 8 hosts with affected PHP packages and directs administrators to apply the CIQ/Rocky Linux security update.
A vulnerability identified as CVE-2022-31626, affecting the Unity Linux/UOS Server package set evaluated by this local security check. The provided CVSS v3 vector indicates a network-reachable flaw requiring low privileges, with high confidentiality, integrity, and availability impact.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.