Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:34354: Important: php:7.4 security update

This Red Hat Security Advisory addresses multiple vulnerabilities in the PHP 7.4 module for RHEL 8, rated Important, including a critical remote code execution flaw in the SOAP extension (CVE-2026-6722, CVSS 9.8) via a use-after-free vulnerability, a high-severity denial of service in ctype functions (CVE-2026-7258, CVSS 7.5), and several other medium-severity issues. The NVD data indicates these CVEs affect PHP versions 8.2.0 through 8.5.6, with fixes available in versions 8.2.31, 8.3.31, 8.4.21, and 8.5.6. Red Hat has provided updated packages for the php:7.4 module to address these backported vulnerabilities.
Read Full Article →

Red Hat Product Errata RHSA-2026:34354 - Security Advisory Issued: 2026-07-01 Updated: 2026-07-01 RHSA-2026:34354 - Security Advisory Overview Updated Packages Synopsis Important: php:7.4 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the php:7.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): php: php-soap: php-src: PHP SOAP extension: Remote Code Execution via use-after-free vulnerability (CVE-2026-6722) PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions (CVE-2026-7258) PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation (CVE-2026-6735) PHP: PHP SoapServer: Memory corruption and information disclosure via incorrect persistence handling (CVE-2026-7261) php: NULL pointer dereference in SOAP apache:Map decoder with missing <value> (CVE-2026-7262) php: signed integer overflow in metaphone() (CVE-2026-7568) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2468560 - CVE-2026-6722 php: php-soap: php-src: PHP SOAP extension: Remote Code Execution via use-after-free vulnerability BZ - 2468561 - CVE-2026-7258 PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions BZ - 2468562 - CVE-2026-6735 PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation BZ - 2468563 - CVE-2026-7261 PHP: PHP SoapServer: Memory corruption and information disclosure via incorrect persistence handling BZ - 2468565 - CVE-2026-7262 php: NULL pointer dereference in SOAP apache:Map decoder with missing <value> BZ - 2468566 - CVE-2026-7568 php: signed integer overflow in metaphone() RHEL-181020 - Backport CVE from PHP 8.2.31 to php 7.4 CVEs CVE-2026-6722 CVE-2026-6735 CVE-2026-7258 CVE-2026-7261 CVE-2026-7262 CVE-2026-7568 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM libzip-1.6.1-1.module+el8.10.0+22485+a3539972.src.rpm SHA-256: 28877cfe8e1ab5f3762ef0fc6d25eeaeaebd72bdaefdba6de69d00fd19da2f9f php-7.4.33-4.module+el8.10.0+24352+91532d3e.src.rpm SHA-256: 0f0a05614001583bb18d032380809580ca29cc2385db88cbecb5907438d4cfaf php-pear-1.10.13-1.module+el8.10.0+22485+a3539972.src.rpm SHA-256: e69572f73eb3c6e8e3ce1bf61500ba23954cd1aa87e3909063c686aea6c98d66 php-pecl-apcu-5.1.18-1.module+el8.10.0+22485+a3539972.src.rpm SHA-256: fc15f170bd40a9ff09e9ec000f01ed999504e2aac933557f02891c0ebc213094 php-pecl-rrd-2.0.1-1.module+el8.10.0+22485+a3539972.src.rpm SHA-256: b0a56534337edd823cde3c0d3afdc49fc3c12b9d688e4b3fc5309b431b68cbc9 php-pecl-xdebug-2.9.5-1.module+el8.10.0+22485+a3539972.src.rpm SHA-256: f010a8335b2f0dfee9c1adcdc4d8838dc1bb2246ca8833d2a8d97e691c13e696 php-pecl-zip-1.18.2-1.module+el8.10.0+22485+a3539972.src.rpm SHA-256: dfeaf79fe68d48d594efb6b7a172552f8002f98baedbc487c057b9592b42863e x86_64 apcu-panel-5.1.18-1.module+el8.10.0+22485+a3539972.noarch.rpm SHA-256: 67c1e1b3ef6c859695f95365d85c1f202b44e5e1b2538382237e7b4108eedb97 php-pear-1.10.13-1.module+el8.10.0+22485+a3539972.noarch.rpm SHA-256: e6d869410faecf0a1173c1879880847b72629903b94dbd299e5116696a03ce0a apcu-panel-5.1.18-1.module+el8.10.0+22485+a3539972.noarch.rpm SHA-256: 67c1e1b3ef6c859695f95365d85c1f202b44e5e1b2538382237e7b4108eedb97 libzip-1.6.1-1.module+el8.10.0+22485+a3539972.x86_64.rpm SHA-256: 2c06716cd56658862f72fe6b878b6898ae48484bbbc5ac260596281bb71834a2 libzip-debuginfo-1.6.1-1.module+el8.10.0+22485+a3539972.x86_64.rpm SHA-256: 112df53d89fafe0973624aeeb55255964594ad104107fa73c41d6f8be91cf217 libzip-debugsource-1.6.1-1.module+el8.10.0+22485+a3539972.x86_64.rpm SHA-256: 5073931d821f7417d5b10782f1462f1c680927b6ddabed46e807a6e2e4a59b64 libzip-devel-1.6.1-1.module+el8.10.0+22485+a3539972.x86_64.rpm SHA-256: 5ca038f4710cb1b8f55e70ccdd4db7d814cd4d78149df1a574c587ffcac4b632 libzip-tools-1.6.1-1.module+el8.10.0+22485+a3539972.x86_64.rpm SHA-256: 6bb9ea064a2c8a05c5c20dda2c2327f43aad1e8f3d1e57ed58aebf4810341d27 libzip-tools-debuginfo-1.6.1-1.module+el8.10.0+22485+a3539972.x86_64.rpm SHA-256: 3533bc4456fa7af373576d44187ff2d04fa2a12e85528449289b787d01d2f35c php-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 5f2f3873286fbfe9977820cbcfd5d792359503153cb59e49baaa1657aa8cd2f3 php-bcmath-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 560bbfedfaeb3497d8e3e623de3fc1cee359898e5935397daa28905bf4180ce6 php-bcmath-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 1a487243bcbd83c440533077d26117d818e832f2b9864820fc4618f7ca02f58d php-cli-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: d8b24de9b014ed9c73b2d48d146f56c38196c5fc4d4aebbeb8508b425fe066d6 php-cli-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 79eb512a2e16a0dc011694ceb208e9a0cc2c1659bea43f754991bada33cb672b php-common-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 19dc5329fbb9f7ada8c1e0a8d3ee5455d033513692807f2bcc3eb03541a26d6c php-common-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 557e303806f35e2fc342c30c1dd7a8a3108c0dc24bf11a3a26803d3a26dfd373 php-dba-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 287dd53875ae1f877dd13439f67d4772b291cca1cea689e03554e24c3f827e26 php-dba-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: b8c637d3da5f4a5622a8f379e213ff2b0688807990a2a264208a49efada59bce php-dbg-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: d01be33569af5a7dbe7ded8001e55b875857987fd9b2a0be933e1e7b97831774 php-dbg-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: aaff5fbf487eb78d656393fc628980f70192452166a7a5deb8b12b32f6c94f98 php-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 861cfa8ccecf28161502a127a1dcfbd5eea7f6139375b1c49dc4dcbd8ec92478 php-debugsource-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 54643ee7763048a86d3f5303063137d0e312429b5a7be00845a2b8cfca23d2da php-devel-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: d270d95bc87adc7283c359cd8f2fabda762400ba63ff068080ebd604b3c1d1bf php-embedded-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 1f41cff8e614e3fc0f38c7f6ba5510403a95e4bca056613265a2058f61203f47 php-embedded-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: f84927bc55f20aed20e6993f0f09ce0cbc68305c85077a6a9f571ec60c5fd2bc php-enchant-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: ef5d5c823f195849525cda3c341c07203b8c389a74ec55e0210493d883ce0d1d php-enchant-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 1fe14778fa3f6f8b8c0c187640a72d9e215ee1fb88025b55ae196d8cf463035b php-ffi-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 76e7c21ff48945ebc00cde5598d5f53c2acbf6596b2c1668b470162347aeed5e php-ffi-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: bd31c4e447ef2e7effbfc40b2ac3696def217330cad5d6487dc2a0409529002f php-fpm-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 408cd04b0a265b1a33226b44fcaf0a2918e307580625ea0e98c1cef115805690 php-fpm-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: ee56320e90e13c2c1716cb8548bc3c9c7a95be4b59820b8d02a1b990b36f773f php-gd-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: b8b632ab88d51598414b904ba99754a8290ca1fd433627585a9e8a3b618e4b50 php-gd-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: c3ea18313d4e6f3631ba6616a27b899caa009acbf3e32a86069aaddfbd7fff89 php-gmp-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 78fbfc88cc719d1f7952e21d7d58fefa71cf8a97eb4b62f9fe87444ef9db1bc6 php-gmp-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: ea38cd82fdc69fb8214e011c57c4a2fa198d38772815d6e7c38914d95b5f6a9a php-intl-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 0e3a4b9534772dc7f7cf5f036c69f231ca20b4c00aca289be344e5adfedfee40 php-intl-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 90046ef5c4ea7d6bd2bbaa95363a1c07e9ffabdf0f9e4fd288f642fb3b649f78 php-json-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: ad2a921c0e780f792adf4fc6d362c7f170a5471bd5929f0965e3fa4a145b652d php-json-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 9dda7a77380e6c57e2802ed30a72b27e0af1bf61c7540b7c494e528436588dea php-ldap-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: 0ce1055828693bd9b70847e5d146dee8c06a96b9c087375cde6364c5a4d74cd2 php-ldap-debuginfo-7.4.33-4.module+el8.10.0+24352+91532d3e.x86_64.rpm SHA-256: bc4e28a7161aaba711f08631fb1c546fb995d66f26d37ab2293a1af3311b9e89 php-mbstring-7.4.33-4.module+el8.10.0+

Share this article