---
title: "CVE-2021-21708"
canonical: "https://kb.cynergy.app/space/MD/927989761/CVE-2021-21708"
format: markdown
---
**Description**

Specific versions of [Php](https://cve.report/software/php/php) from [Php](https://cve.report/vendor/php) contain the following vulnerability:

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger the use of allocated memory after free, which can result in it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects code that uses FILTER_VALIDATE_FLOAT with min/max limits.

**Published On**

02/27/2022

**Updated On**

10/07/2022

**Trending**

FALSE

**CWE**

<u>[CWE-416](http://cwe.mitre.org/data/definitions/416.html)</u>

**Exploit**

[https://bugs.php.net/bug.php?id=81708](https://bugs.php.net/bug.php?id=81708) 

[https://github.com/MrdUkk/php-sigsegv](https://github.com/MrdUkk/php-sigsegv) 

 

**Mitigation:**

![image](media://5ad10d10-7ce2-4b5c-ab24-017ca01c9848)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- [150525](https://cve.report/qid/150525) PHP Input Validation Vulnerability (CVE-2021-21708)
- [179085](https://cve.report/qid/179085) Debian Security Update for php7.4 (DSA 5082-1)
- [198680](https://cve.report/qid/198680) Ubuntu Security Notification for Hypertext Preprocessor (PHP) Vulnerability (USN-5303-1)
- [282423](https://cve.report/qid/282423) Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2022-1596a2dacb)
- [282424](https://cve.report/qid/282424) Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2022-2e5e723298)
- [38869](https://cve.report/qid/38869) Hypertext Preprocessor (PHP) Use After Free Vulnerability
- [502152](https://cve.report/qid/502152) Alpine Linux Security Update for php7
- [502153](https://cve.report/qid/502153) Alpine Linux Security Update for php8
- [502567](https://cve.report/qid/502567) Alpine Linux Security Update for php7
- [710633](https://cve.report/qid/710633) Gentoo Linux Hypertext Preprocessor (PHP) Multiple Vulnerabilities (GLSA 202209-20)
- [751769](https://cve.report/qid/751769) SUSE Enterprise Linux Security Update for php74 (SUSE-SU-2022:0654-1)
- [751885](https://cve.report/qid/751885) SUSE Enterprise Linux Security Update for php7 (SUSE-SU-2022:0847-1)
- [751890](https://cve.report/qid/751890) OpenSUSE Security Update for php7 (openSUSE-SU-2022:0847-1)
- [901901](https://cve.report/qid/901901) Common Base Linux Mariner (CBL-Mariner) Security Update for Hypertext Preprocessor (PHP) (8846)

**References**

|  |  |  |
| --- | --- | --- |
| PHP: Multiple Vulnerabilities (GLSA 202209-20) — Gentoo security | [http://security.gentoo.org](http://security.gentoo.org)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| CVE-2021-21708 PHP Vulnerability in NetApp Products | NetApp Product Security | [http://security.netapp.com](http://security.netapp.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| PHP :: Sec Bug #81708 :: UAF due to php_filter_float() failing for ints | [http://bugs.php.net](http://bugs.php.net)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |

![image](media://523ed278-1e52-4b1e-82f8-66f13fa9f9d4)