Description
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and encounter null pointer dereference, which would likely lead to a crash.
Remediation
References
Related Vulnerabilities
MySQL Insufficiently Protected Credentials Vulnerability (CVE-2012-5627)
WordPress Plugin Akeeba Backup CORE for WordPress Arbitrary File Upload (1.1.3)
Drupal Core 9.4.x Remote Code Execution (9.4.0 - 9.4.2)
WordPress Plugin WP-VR-view-Add Photo Sphere, 360 video to WordPress Cross-Site Scripting (1.6)