Red Hat Product Errata RHSA-2026:22649 - Security Advisory Issued: 2026-06-02 Updated: 2026-06-02 RHSA-2026:22649 - Security Advisory Overview Updated Packages Synopsis Important: php8.4 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for php8.4 is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. Security Fix(es): PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions (CVE-2026-7258) PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation (CVE-2026-6735) php: NULL pointer dereference in SOAP apache:Map decoder with missing <value> (CVE-2026-7262) php: signed integer overflow in metaphone() (CVE-2026-7568) php: denial of service via DOMNode::C14N() (CVE-2026-7263) php: global buffer over-read in mb_convert_encoding() with attacker-supplied encoding (CVE-2026-6104) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2468561 - CVE-2026-7258 PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions BZ - 2468562 - CVE-2026-6735 PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation BZ - 2468565 - CVE-2026-7262 php: NULL pointer dereference in SOAP apache:Map decoder with missing <value> BZ - 2468566 - CVE-2026-7568 php: signed integer overflow in metaphone() BZ - 2468572 - CVE-2026-7263 php: denial of service via DOMNode::C14N() BZ - 2468573 - CVE-2026-6104 php: global buffer over-read in mb_convert_encoding() with attacker-supplied encoding CVEs CVE-2026-6104 CVE-2026-6735 CVE-2026-7258 CVE-2026-7262 CVE-2026-7263 CVE-2026-7568 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM php8.4-8.4.21-1.el10_2.src.rpm SHA-256: d30365621308e36c29a31a1f5a8c3c6bf50dfeeefca7713f28cf1e4867ac61e2 x86_64 php8.4-8.4.21-1.el10_2.x86_64.rpm SHA-256: d55b06da8e602787111cf948b92dd412870714d4c79688e4549c2b59bd4f2993 php8.4-bcmath-8.4.21-1.el10_2.x86_64.rpm SHA-256: 01ebbd92bc33b9f87c4b1b72699a43cddb77c08d4fa3b5a48f6732cf42f9a73b php8.4-bcmath-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: ab7faccfba61151a6f1c19a656c82e1a10a4dc5580937c82f9d0510713b795ad php8.4-cli-8.4.21-1.el10_2.x86_64.rpm SHA-256: 29ab6e427c3d88a8d5a31e0645373a2586868351b23863e42b42f8bb55861cae php8.4-cli-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 41465032b679e2e8da00f0fb685cbc4d309f6faf5ddb722490a718b4eb73862c php8.4-common-8.4.21-1.el10_2.x86_64.rpm SHA-256: f757432f76fdce0d2a44160dc08e6735626b7b243ed0826b67ffbf198eead034 php8.4-common-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: b649a383f01eb4044c394966526b3d2de22746ccc7f6c47436cb5d39eab260dd php8.4-dba-8.4.21-1.el10_2.x86_64.rpm SHA-256: 3031c0619067427d32b456913ae7b17fb91525388793b786d9aecce7829f53a4 php8.4-dba-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 2762be4278a7eb8380934fe71b4a4e89965df39f12d814cb96e25a010af1694f php8.4-dbg-8.4.21-1.el10_2.x86_64.rpm SHA-256: dee3b6819986af6ce1be11b1ce904fb01bf1b918feb67fe3a9b4343627f50091 php8.4-dbg-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 793a2492a8acdc87657e9eea62e1d4ad652535c72f4b27e42f9e326a356f1001 php8.4-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 89a09957bf3085c236ee5fe3553d04e72201bdaeaf82939b10a54a2bee10bfbe php8.4-debugsource-8.4.21-1.el10_2.x86_64.rpm SHA-256: 05951aa28de63282448f432549d0f0b5229b43ae2396e28f7c4587258ea6e160 php8.4-devel-8.4.21-1.el10_2.x86_64.rpm SHA-256: 1df9b5e8609dd218d96bdd2ed06eeb3433bf9c985380df875e3f1e975a36dbee php8.4-embedded-8.4.21-1.el10_2.x86_64.rpm SHA-256: 7baa4ddc245ea0d16f1ad883d4bd1c8001e75f8326c364a695035f6db437f923 php8.4-embedded-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 43709d76d8c7ba17742880db92f3fcff5fb1393a4f0467d2b86dc3c5fa015a40 php8.4-enchant-8.4.21-1.el10_2.x86_64.rpm SHA-256: 11f00127fe225e015665d8bb284f78bef067dd0c455c73bbe044bf6cb2612701 php8.4-enchant-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: aab1a2274a8631cfba6ac356dbf763484f263ce57dc29f31a441abb7968a72c7 php8.4-ffi-8.4.21-1.el10_2.x86_64.rpm SHA-256: b9d3b8b5bb1036cf4c9dc6b1ef459be7f2462b38f7e3c9d19a671a9d9cd8cfb8 php8.4-ffi-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 6d6e4a174ca66155b53274ffb7a7c77464fc7978eb21bb4eac11d5e4265704c2 php8.4-fpm-8.4.21-1.el10_2.x86_64.rpm SHA-256: c65c272478623687e675908d072504038033ac52488a7427e829a0769a4a3735 php8.4-fpm-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 9c5b7926a6565bc5bfaab9f1dfeadf8c3604a879f3bcbf39dccee721c1640665 php8.4-gd-8.4.21-1.el10_2.x86_64.rpm SHA-256: 37f3f31b044263e9a5012b4f2beae110183786e2cb3a890e34634be71ed0bd1f php8.4-gd-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 34b267bfab8255a4338a0d454ab8f9098f6e9e81ee0f610dab3e883422749723 php8.4-gmp-8.4.21-1.el10_2.x86_64.rpm SHA-256: ce3b5d986974d6d8fb54dbd02766ca2140f53b9ae6e99df0819c85d4b706a72d php8.4-gmp-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 7c54ca1e928a2105b15270c03b62e6817e359e24b500193a49a36f14a03d282f php8.4-intl-8.4.21-1.el10_2.x86_64.rpm SHA-256: de38cd9b23a82e1bbd9e41732c61d40b67a554151a68fc8221f442d552fd4a25 php8.4-intl-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: b70f438f8abb7feacf9d57bf931f9d6df139ca2adba9ace04640a96d0ec19448 php8.4-ldap-8.4.21-1.el10_2.x86_64.rpm SHA-256: 03eeefc202af6008889ff3fc75ef16f3cd0950b35a9e2329d874268fa268298b php8.4-ldap-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 93725641b30c063b9883ff9887bfb467865bf6800af4136e8486f1fee1775237 php8.4-mbstring-8.4.21-1.el10_2.x86_64.rpm SHA-256: 90af09588b3722f336e3bf2a417f613895c1f481226b7bb4c130eaca63846e83 php8.4-mbstring-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 1e488da128cfed076f1ec93a064204b6eb83e52de8eb166163f1339f916d03fb php8.4-mysqlnd-8.4.21-1.el10_2.x86_64.rpm SHA-256: bf9253639d07647ded2ebe3de272afe180b718d0507e058ccc15020514207d64 php8.4-mysqlnd-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 0fbf3d576e5f1fb4535087d68f08cf6274d88edfb34339bfca1e44210b4f2c42 php8.4-odbc-8.4.21-1.el10_2.x86_64.rpm SHA-256: c8a0ae648b41d84ca6658b52e303f9be8fd6a49aa6cd6e06d0000558db162e0f php8.4-odbc-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 0b8ec5cbe3889d89e54ac6089d0f6b8b6387391afc85905ade7322e90176c728 php8.4-opcache-8.4.21-1.el10_2.x86_64.rpm SHA-256: 82266a74357418313fc56cf7585b58d61d9b57fcf7916f780e8f3f3b078846f2 php8.4-opcache-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 42216d0623538e2d5cea2dd9633d3ab311eb56790dd787aa3cc6c09a6059b5c9 php8.4-pdo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 95aaa828aeded746508d3b431c7af76b4a27b628ab353980383e6cb3f612651b php8.4-pdo-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 2dac074d48f3d75cece3177116c48ac881b70277630986b77efda73d6a647d51 php8.4-pgsql-8.4.21-1.el10_2.x86_64.rpm SHA-256: 1e9203ebf84d86f343badde82f93af911a1a6182c806b63e264a79fdb955cb07 php8.4-pgsql-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 2fb0367a7b6b0942634205be6d4a5a5d551186aca5083f7598f92fba1a362e62 php8.4-process-8.4.21-1.el10_2.x86_64.rpm SHA-256: 73ab42116ccb8524e6fe528636d89d9d68178268b65a6d3683e01c6a6e8cb0d8 php8.4-process-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: 64f1c4f174dca8ab38d6e300fd9ffa5eaf6db4239005db0e59405b66d18d5105 php8.4-snmp-8.4.21-1.el10_2.x86_64.rpm SHA-256: 6e50f4b438fbf95b84e300c786ab56df97046335d07fbdaee14dd159f9f97d16 php8.4-snmp-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: aa32b11cdb989d1fb2a329f37af223db678c69059bd389130e377107a499c988 php8.4-soap-8.4.21-1.el10_2.x86_64.rpm SHA-256: 7db6610652d263543e425d4b0a140d5532ef82f63fb2301315b188ff873fc200 php8.4-soap-debuginfo-8.4.21-1.el10_2.x86_64.rpm SHA-256: a272a683f9b237b2354d4d68f13a6a1fbaa1f0c090bf9a28d37311f3209a3818 php8.4-xml-8.4.21-1.el10_2.x86_64.rpm SHA-256: 92905b4e4078d17c5c746a3bb4da55df9352c2d473301e748ee99fd9f9870cfb php8.4-xml-debuginfo-8.4.21-1.e
This Red Hat security advisory addresses multiple vulnerabilities in PHP 8.4 for RHEL 10, including a high-severity denial of service via ctype functions (CVE-2026-7258, CVSS 7.5), a cross-site scripting flaw in PHP-FPM (CVE-2026-6735, CVSS 6.1), and a high-severity NULL pointer dereference in the SOAP decoder (CVE-2026-7262, CVSS 7.5). The vulnerabilities affect PHP versions 8.2.0 through 8.2.30, 8.3.0 through 8.3.30, and 8.4.0 through 8.4.20, and are fixed in versions 8.2.31, 8.3.31, and 8.4.21, respectively.