Critical severity9.8NVD Advisory· Published Sep 6, 2019· Updated Jun 17, 2026
CVE-2019-11926
CVE-2019-11926
Description
Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions prior to 3.30.9, all versions between 4.0.0 and 4.8.3, all versions between 4.9.0 and 4.15.2, and versions 4.16.0 to 4.16.3, 4.17.0 to 4.17.2, 4.18.0 to 4.18.1, 4.19.0, 4.20.0 to 4.20.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*range: <=3.30.9
- cpe:2.3:a:facebook:hhvm:4.19.0:*:*:*:*:*:*:*
- (no CPE)range: <3.30.9, 4.0.0-4.8.3, 4.9.0-4.15.2, 4.16.0-4.16.3, 4.17.0-4.17.2, 4.18.0-4.18.1, 4.19.0, 4.20.0-4.20.1
- (no CPE)range: 4.21.0
- Range: <3.30.9, 4.0.0-4.8.3, 4.9.0-4.15.2, 4.16.0-4.16.3, 4.17.0-4.17.2, 4.18.0-4.18.1, 4.19.0, 4.20.0-4.20.1
Patches
Vulnerability mechanics
References
3- github.com/facebook/hhvm/commit/f9680d21beaa9eb39d166e8810e29fbafa51ad15nvdPatchThird Party Advisory
- hhvm.com/blog/2019/09/03/security-update.htmlnvdThird Party Advisory
- www.facebook.com/security/advisories/cve-2019-11926nvdVendor Advisory
News mentions
0No linked articles in our index yet.