---
title: "CVE-2022-31628"
canonical: "https://kb.cynergy.app/space/MD/922845185/CVE-2022-31628"
format: markdown
---
**Description**

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.  


**Published On**

09/28/2022

**Updated On**

10/07/2022

**Trending**

FALSE

**CWE**

<u>[CWE-674](http://cwe.mitre.org/data/definitions/674.html)</u>

 

**Mitigation:**

![image](media://789cd588-c9ee-4bb6-9665-0f6f41e885e6)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

Update to 8.1.11 - [http://www.php.net/releases/8_1_11.php](http://www.php.net/releases/8_1_11.php) 

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-0b77fbd9e7' at the command line. For more information, refer to the dnf documentation available at [http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label](http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label) 

**Reference**

[https://bugs.php.net/bug.php?id=81726](https://bugs.php.net/bug.php?id=81726)  

[https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VI3E6A3ZTH2RP7OMLJHSVFIEQBIFM6RF/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VI3E6A3ZTH2RP7OMLJHSVFIEQBIFM6RF/) 

[https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XNIEABBH5XCXLFWWZYIDE457SPEDZTXV/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XNIEABBH5XCXLFWWZYIDE457SPEDZTXV/)