---
cve: "CVE-2021-21708"
severity: "HIGH"
cvss: 8.2
epss: "3%"
vendor: "PHP Group"
kev: false
exploited: false
published: "2022-02-27 08:00:12"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T17:02:32+02:00"
---

# CVE-2021-21708

> 8.2 HIGH

## Beschreibung

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Gering | warn |

## Patch verfügbar (OSV)

- 33fb9dcbc31840296ac495c74532f71a463380cd (Commit)
- 4f4e4354154778edc85ee882d81b95611b12d04d (Commit)

## Referenzen

- <https://bugs.php.net/bug.php?id=81708>
- <https://security.netapp.com/advisory/ntap-20220325-0004/>
- <https://security.gentoo.org/glsa/202209-20>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2021-21708) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
