Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:33449: Important: php security update

A critical use-after-free vulnerability (CVE-2026-6722, CVSS 9.8) in the PHP SOAP extension allows for remote code execution. Affected versions are PHP 8.2.0 through 8.2.30, 8.3.0 through 8.3.30, 8.4.0 through 8.4.20, and 8.5.0 through 8.5.5. The fixes are provided in PHP versions 8.2.31, 8.3.31, 8.4.21, and 8.5.6.
Read Full Article →

Red Hat Product Errata RHSA-2026:33449 - Security Advisory Issued: 2026-06-30 Updated: 2026-06-30 RHSA-2026:33449 - Security Advisory Overview Updated Packages Synopsis Important: php security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for php is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): php: php-soap: php-src: PHP SOAP extension: Remote Code Execution via use-after-free vulnerability (CVE-2026-6722) PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions (CVE-2026-7258) PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation (CVE-2026-6735) PHP: PHP SoapServer: Memory corruption and information disclosure via incorrect persistence handling (CVE-2026-7261) php: NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() (CVE-2026-7259) php: NULL pointer dereference in SOAP apache:Map decoder with missing <value> (CVE-2026-7262) php: signed integer overflow in metaphone() (CVE-2026-7568) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2468560 - CVE-2026-6722 php: php-soap: php-src: PHP SOAP extension: Remote Code Execution via use-after-free vulnerability BZ - 2468561 - CVE-2026-7258 PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions BZ - 2468562 - CVE-2026-6735 PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation BZ - 2468563 - CVE-2026-7261 PHP: PHP SoapServer: Memory corruption and information disclosure via incorrect persistence handling BZ - 2468564 - CVE-2026-7259 php: NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() BZ - 2468565 - CVE-2026-7262 php: NULL pointer dereference in SOAP apache:Map decoder with missing <value> BZ - 2468566 - CVE-2026-7568 php: signed integer overflow in metaphone() RHEL-181025 - Backport CVE from PHP 8.2.31 to php 8.0 CVEs CVE-2026-6722 CVE-2026-6735 CVE-2026-7258 CVE-2026-7259 CVE-2026-7261 CVE-2026-7262 CVE-2026-7568 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM php-8.0.30-6.el9_8.src.rpm SHA-256: 89bf2d45ca18911031e23162d3b840ea3bb77957e195788c30e61d4168a92703 x86_64 php-8.0.30-6.el9_8.x86_64.rpm SHA-256: 551437ec0eb481028192ffcb06a33d6f16481cfe58c83975be6a640a123fa0ee php-bcmath-8.0.30-6.el9_8.x86_64.rpm SHA-256: 516e50c8eff6da0e551461688f5d5a3fa05621aa7538f8cf6a09b0f5c4392c82 php-bcmath-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: e73d8919b89aa350c3d3d09d6b3f097937a258eaa0ce700aa1127be4ef598000 php-cli-8.0.30-6.el9_8.x86_64.rpm SHA-256: 5cbcbb1818d1a9970e7638b4614c4e1a8900d10a604cf7263555a87f57ab4c9f php-cli-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: fc4fc6f32b96fa6086d85f764919e8f42a05f8392f6e2e63cc04506a6f3c354f php-common-8.0.30-6.el9_8.x86_64.rpm SHA-256: 851d5af0bef4b69b92956b42969d9ddf5a15cb6aeffb61ad209abbf51f1e931a php-common-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 3b1adc380fe3eb3482faa5cca4b4202b14ea2115eef9dd525f69bf1f07d139f9 php-dba-8.0.30-6.el9_8.x86_64.rpm SHA-256: 8cbbfb16550b1e3ef5d337d8ac08fb1ed57c90d2df708a9934b5ff43222ea616 php-dba-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 96bb853cd52a46ed6b9931f9d9fb34ac69d36618df67752ce1b83a9bd7985c0f php-dbg-8.0.30-6.el9_8.x86_64.rpm SHA-256: e25a1b522cf74a47983a264043e74fb7783b11fd6cfd0a88204ba7abfb6368e6 php-dbg-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: d8292b5c2be6595a2926e6fcc031657df6c14025c182424855c1796d2ad700ab php-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: fca173a6dde589fcad1f6a484657254221530294fb9910267af7eb903237caa6 php-debugsource-8.0.30-6.el9_8.x86_64.rpm SHA-256: 7abd447b2fcc9de79f7940ba4b521218fc65f8013505b6c56e9322f605d6b8d4 php-devel-8.0.30-6.el9_8.x86_64.rpm SHA-256: 3cbaacff510308d4dd91eb8c2d2babc37af61fadc562d8237808482e54e3c1a4 php-embedded-8.0.30-6.el9_8.x86_64.rpm SHA-256: 2b60e85bb2a2969ad42cc4f14f1060d3a9f5fc0de39bf227a0b91cb1268bca4d php-embedded-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 34173dae912e73369bb11bcb52f60bbd4e767cf61acb4fb14c2e23e15a4a3c51 php-enchant-8.0.30-6.el9_8.x86_64.rpm SHA-256: e605f24eae618b34b56e35f899da5803f080f82828b4aa25f4888e7bd13c4180 php-enchant-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 5de509f865208c72707d20d1b2b6e330ba2f8d047a0de1e8e67e8d2d302f57b1 php-ffi-8.0.30-6.el9_8.x86_64.rpm SHA-256: 372c2c6d7a507a807c580dd80f1bfc958336fbc669274a29d68787612517f8f7 php-ffi-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: e39c3b92e51fbe6ec7f7ee6ff6fcb61bf0b51a127bb1c928f94718334ccf8ca9 php-fpm-8.0.30-6.el9_8.x86_64.rpm SHA-256: e8ef082f78dfbb6659608daa59082070b014774ffdedc8e9001073de6fcb14a1 php-fpm-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 08e77d41ee93b8b4a0bfa4c852273b467b715114abba0d941c5bd6ed8ad6185b php-gd-8.0.30-6.el9_8.x86_64.rpm SHA-256: 7868bca086234cdb1b4458194261c9aa275309aa1d7fde16942124bb6c3efd3d php-gd-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 81d9a8e505fd77883b9e90c19bd9cffa6d377676f927b81d44af31330ec09c33 php-gmp-8.0.30-6.el9_8.x86_64.rpm SHA-256: 52a20cb7afafe6fc1dd07d77112e0baea291a22129580a889c1359ac1f521f78 php-gmp-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 153dae715cec437d8490893980819bf7d5a137dbab62a0741fd2fdf46c9552b3 php-intl-8.0.30-6.el9_8.x86_64.rpm SHA-256: bf1397e0486ee0f7829eaf03a4897362f0bc641051d4104bffee215a8e5a1302 php-intl-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 1a47fbf8eca721db268847c81943d39e22b1ec744911ef4e22dba36c54a17f65 php-ldap-8.0.30-6.el9_8.x86_64.rpm SHA-256: 069c258a94e5deeda5cce881470eb8c05154c44222fe4d17e92b6ab8b173f29c php-ldap-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 8adde74729af2a50b20fa15b410b86867a8cd2d8abefb79ced3b602762df2780 php-mbstring-8.0.30-6.el9_8.x86_64.rpm SHA-256: 0a78ffaa56ed1ad9cadfe35e19bd8fd5bbca2fc467fab31f646e9b2408940fc1 php-mbstring-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 57618aa91bb59be098bc26538c9e807061df899df31845aefaad925db280259b php-mysqlnd-8.0.30-6.el9_8.x86_64.rpm SHA-256: 42fe1bc4b03183cbd51ed22e1dbb80236204240965d3775a4a6c59ba1d2f5d52 php-mysqlnd-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 07c1c1bc0ec02bf33757cd61e9e491353d3945af96b1077e4efa198136278cd9 php-odbc-8.0.30-6.el9_8.x86_64.rpm SHA-256: 9c20d5eee980d39c69da87e12ad4a4fc5a1ba346184b845cf54e328422a904ec php-odbc-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 8486f5bf48fa93df3231da66aa1a296be5cf2f24baf645b3894b7ee6490a40fb php-opcache-8.0.30-6.el9_8.x86_64.rpm SHA-256: c68aadbe97063f803e8b77cd73e1ae9683bfd6eb43c2ffae25ab288dbe0689b8 php-opcache-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 7f31e8d8f935b40381dd8c6ae44df31de75d477d75eff92c2eff948f5ffb64e2 php-pdo-8.0.30-6.el9_8.x86_64.rpm SHA-256: d531d5a08ed6864a5a3da6b8c032f4ef89f1e24631a1773ba8c8a41adc76b156 php-pdo-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: d8b444e76f667741335d05923d468d4a82f713af2a76e8542983586ebea70344 php-pgsql-8.0.30-6.el9_8.x86_64.rpm SHA-256: d4d0d9e48696888b1de37af78da9d2a25dbbd01b53a7e628dfce076da8041c53 php-pgsql-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 34b8b33bbf0e61345074de5b224cdac8050414f74c9ef8550fa24e3f9766553d php-process-8.0.30-6.el9_8.x86_64.rpm SHA-256: 3b89ffd56fce213d0100fc7f6466528ba16c763799e8472ec5e60cc19267db60 php-process-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: e6252466e79e19df8710d97a993129fffad854267d2eb5810a3f69e349c694b1 php-snmp-8.0.30-6.el9_8.x86_64.rpm SHA-256: bc7ad2b132b853f3291a7032bfa9d9d3a44b6c3f6f61415ff36add2e80fdad25 php-snmp-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: ac831d6bf3eefa4b5a9a4c004cfde4be71a87f8ad2d2e9c95c39ac7036233aab php-soap-8.0.30-6.el9_8.x86_64.rpm SHA-256: 4745a2ebc4ca6efcad2f50ffd0d8d2ad98b3e57162e06001072068db86d08c46 php-soap-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 75740094a9471ce12208658fc9250f8d9cef7897d2e074f468262c1c1646354a php-xml-8.0.30-6.el9_8.x86_64.rpm SHA-256: f56db179c091507c6a74adc3388bbf17e91c3ffbd074b30ac53e5896c2e6e200 php-xml-debuginfo-8.0.30-6.el9_8.x86_64.rpm SHA-256: 2533cdeba1cb9c46f8d1f6dcb8ec2f1b0df5bf4bbc412df92a24ff9498fc1f

Share this article