- What: Security update for PHP in Red Hat Enterprise Linux 9
- Impact: Addresses memory corruption and SQL injection vulnerabilities
Red Hat Product Errata RHSA-2026:61259 - Security Advisory Issued: 2026-08-31 Updated: 2026-08-31 RHSA-2026:61259 - Security Advisory Overview Updated Packages Synopsis Low: php security, bug fix, and enhancement update Type/Severity Security Advisory: Low Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for php is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): php: ext/openssl: memory corruption in openssl_encrypt with AES-WRAP-PAD (CVE-2026-14355) php: ext-pgsql: PHP: SQL injection via improper backslash escaping (CVE-2026-17543) php: PHP: Denial of Service via circular symbolic links in phar archives (CVE-2026-7260) Bug Fix(es) and Enhancement(s): Backport fix for CVE-2026-14355 to PHP 8.0 in 9.8.z (JIRA:RHEL-192624) Backport fix for CVE-2026-17543 and CVE-2026-7260 to PHP 8.0 in 9.8.z (JIRA:RHEL-223940) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2496971 - CVE-2026-14355 php: ext/openssl: memory corruption in openssl_encrypt with AES-WRAP-PAD BZ - 2509254 - CVE-2026-17543 php: ext-pgsql: PHP: SQL injection via improper backslash escaping RHEL-192624 - Backport fix for CVE-2026-14355 to PHP 8.0 in 9.8.z RHEL-223940 - Backport fix for CVE-2026-17543 and CVE-2026-7260 to PHP 8.0 in 9.8.z CVEs CVE-2026-7260 CVE-2026-14355 CVE-2026-17543 References https://access.redhat.com/security/updates/classification/#low Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM php-8.0.30-8.el9_8.src.rpm SHA-256: ab81bc8436d1904407107a55d758303ff4a5298f6a26903560898cd97d743399 x86_64 php-8.0.30-8.el9_8.x86_64.rpm SHA-256: 6d938481d0c061ef79d9c65143239ddb2a67a001c3f9a57fba1f238372b1f729 php-bcmath-8.0.30-8.el9_8.x86_64.rpm SHA-256: 5bfb7f56a38533e0b6a3b2e193a447bfdb330b652e3fd298ef083cafa58f1434 php-bcmath-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: 717e7dd6229dc9d90f1fa5aeb3975c627562628f4ebafa2bf774f366eab2e181 php-cli-8.0.30-8.el9_8.x86_64.rpm SHA-256: 1f3ec1a0ff482cd0d2aa75de2892674e609a5069b92b1fb9d0891e69a9c9ad0f php-cli-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: ad638b962f5a5e69720bde407f9466a63759d4ab01df4ce9cfbb879c6c5574b9 php-common-8.0.30-8.el9_8.x86_64.rpm SHA-256: 8f25e6374cc9894323df611fbd72233e73786332f077614f53776bc8e66f6bc2 php-common-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: 6c02af24e907cb93485d700038d8271aab912627471d325797144affbc8f627e php-dba-8.0.30-8.el9_8.x86_64.rpm SHA-256: 310cc4a9a6a37ac4ab6d774566cfe2079ae07f7d58c6e327c4f58910712b9875 php-dba-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: f40ff4440fa0981471855291cac8640f11622d0baeabe93a6ed51dd6ee4e33ad php-dbg-8.0.30-8.el9_8.x86_64.rpm SHA-256: 312e10ea6c458bb2c6dd0b5fead0c563c6c681473d256831a3574b1690e28e84 php-dbg-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: e8311d7fbc42c509131aa9bc93905aada4371bba58f29785fcf3b447f4d65f3a php-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: 16170f62dd122b0af78cb9a5a9eae15292b363ee8866715c72327d791ee5687f php-debugsource-8.0.30-8.el9_8.x86_64.rpm SHA-256: a8c655f35e3b7c77c4b570030a67725dde35e285b619cd7abee7f1264a1b58b1 php-devel-8.0.30-8.el9_8.x86_64.rpm SHA-256: 272e94ae4517252381ec89ea28eb02e4ffb48c8f99c0529d8e2a9ca4bf6a83f5 php-embedded-8.0.30-8.el9_8.x86_64.rpm SHA-256: 41372b95737cd42c144b92453ba79acd466a9269ee91e9f9bea130251c380d0d php-embedded-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: abae10018ed46f0bfd5b260dcb29d7245e4f17611b3ce96be22e3060feb2a709 php-enchant-8.0.30-8.el9_8.x86_64.rpm SHA-256: b6c3aa0116320655987dbe39f333603f0810329df318cd22eace0e3a2aff70d6 php-enchant-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: 323368622c99989a0596ccf2fd9b7b7e02ad3f5e787585ef2a70cf63b8e447ea php-ffi-8.0.30-8.el9_8.x86_64.rpm SHA-256: 4972dc26fc69c5a3cf45231a9b195d465e21c069020b429554c0e7e82e72efb7 php-ffi-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: 193ceb83f33f6d7ca6220af9dce93f22d7acf54624ac814a50b7ebcf33472994 php-fpm-8.0.30-8.el9_8.x86_64.rpm SHA-256: e846abfae94c41c09d24668793b010519673f71d2f2eb6b68619bd3fc357da8f php-fpm-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: d03a7452d2250429c06505f7f90df896625557f079f661fe86123449d3b20cfe php-gd-8.0.30-8.el9_8.x86_64.rpm SHA-256: 42e18e1288e044403de2361dfc2ddc288896ca146f1d8f0ecb7445f8508939c6 php-gd-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: f25b6ae084dbb2539080d2591ec4fdf23f1ae96c693a7675daef09cd7a9f619e php-gmp-8.0.30-8.el9_8.x86_64.rpm SHA-256: 33b1c0db3a76f3ffcb6ddfbab25c89ec7172fde3c5c4b5f4b9f08b99a7af0a55 php-gmp-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: 1f5bab336e0bde23a557590ca228397f3284ac9eb5b4bd4561900e8d3baa592f php-intl-8.0.30-8.el9_8.x86_64.rpm SHA-256: efc760844a7cdb56d4f255c9f6c91faef6f0bdce77984c2f01f43ef68dafef07 php-intl-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: e86f08c380867f35c97fc42f0743ced9ab2beb3cb9006c69987e8a7943764681 php-ldap-8.0.30-8.el9_8.x86_64.rpm SHA-256: 7f479d413e049bf705193b76f2e3a6c007038fa30842169a798dfc0dc19d6ba0 php-ldap-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: 6c1c1aa5caf17426e6f25b70b6893f5b0b70333414ff497134bbe815be3edcf5 php-mbstring-8.0.30-8.el9_8.x86_64.rpm SHA-256: b9eaab3cd4f4f73a9fbe4913c689de6fed4e7e603f5903749155fabda662e86f php-mbstring-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: 817bc24455a2b2a98170b4e0a24c8d7d81a5c80dddfaf2f1e6b682bf4767e8e1 php-mysqlnd-8.0.30-8.el9_8.x86_64.rpm SHA-256: 83d45e55a72e5a2a81bcd0a32eca741602605e788abd201731ce287755cb47cd php-mysqlnd-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: aa0a8222fcaa59dde3b5b91fc63928be3c4793fa8108042332da6ffcaf0b95d6 php-odbc-8.0.30-8.el9_8.x86_64.rpm SHA-256: 26b44dd304ecbd5a6c6d8ce3a09fff49eb2ae7fd2d3d7e66a791de2c232a23ac php-odbc-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: c2c8e673c9b1ba925c9d2a83a424da378264ac187432c6ed4268c0de8157a088 php-opcache-8.0.30-8.el9_8.x86_64.rpm SHA-256: d8730b46e1cfcd5b067708c9d35dd6a22f93d2590c9bcb202db26d6ca45e4b34 php-opcache-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: 6e26d9b80d45c95bc478c1176e417fbd1735cd4309625f95f2a7cb82db81695d php-pdo-8.0.30-8.el9_8.x86_64.rpm SHA-256: b0a97a19e8458b0cc8ffa2d1723bd8551aa66dc43f3efb6329c76d3ab723f7ff php-pdo-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: e1f2dcd6dc14e6dc5bf995557cf69f4d5bb566029b4f66cf327e50cc814d7b5c php-pgsql-8.0.30-8.el9_8.x86_64.rpm SHA-256: 293cfca0638271dbbbfa0329c5144dc634af8478f944585d946b3a0c42b3cbc1 php-pgsql-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: f1f115d7c525ee8711bc74e9e535af017d71ce36baa79a26f6cb5a4770ae0d92 php-process-8.0.30-8.el9_8.x86_64.rpm SHA-256: 47ae32b90611301b9b96ec594ef5f56c98ee02319ea4e259b6c8f751730d678e php-process-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: f2d554f86fab65deec2ba9eadc76d14c111298e53b969cec2dc15c82567b7d96 php-snmp-8.0.30-8.el9_8.x86_64.rpm SHA-256: f849a36c63adfc4364bc9115e81061b0ad97125185f0b1fc5a905dbcf3e91d5e php-snmp-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: c0e535bb423b4707ad91ac7bcc01355b642e3c697ed61506604acb8ab77adb71 php-soap-8.0.30-8.el9_8.x86_64.rpm SHA-256: 73b0e0652e811c6ddb7910d9f1c5d17c69e0d41f6a8998fcf2bbb010b2c04bfe php-soap-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: c559877f20af36db0af8360cfd4870e5f3e6d7120ae6d6dfb9068d5873a935e6 php-xml-8.0.30-8.el9_8.x86_64.rpm SHA-256: 11319304e402f8a97032615a6933b107d9da1c0210a1adb5ea31cf332686d17d php-xml-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: e15b0fa8d2c738f6d6948c7364bc1a9153b4bb6a1c6aaa1da8caf748d85859b1 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM php-8.0.30-8.el9_8.src.rpm SHA-256: ab81bc8436d1904407107a55d758303ff4a5298f6a26903560898cd97d743399 x86_64 php-8.0.30-8.el9_8.x86_64.rpm SHA-256: 6d938481d0c061ef79d9c65143239ddb2a67a001c3f9a57fba1f238372b1f729 php-bcmath-8.0.30-8.el9_8.x86_64.rpm SHA-256: 5bfb7f56a38533e0b6a3b2e193a447bfdb330b652e3fd298ef083cafa58f1434 php-bcmath-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: 717e7dd6229dc9d90f1fa5aeb3975c627562628f4ebafa2bf774f366eab2e181 php-cli-8.0.30-8.el9_8.x86_64.rpm SHA-256: 1f3ec1a0ff482cd0d2aa75de2892674e609a5069b92b1fb9d0891e69a9c9ad0f php-cli-debuginfo-8.0.30-8.el9_8.x86_64.rpm SHA-256: ad638b962f5a5e69720bde407f9466a63759d4ab01df4ce9cfbb879c6c5574b9 php-common-8.0.30-8.el9_8.x86_64.r