Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:56969

Опубликовано: 20 авг. 2026
Источник: rocky
Оценка: Important

Описание

Important: php8.4 security, bug fix, and enhancement update

PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts.

Security Fix(es):

  • php: ext-pgsql: PHP: SQL injection via improper backslash escaping (CVE-2026-17543)

  • php: PHP: Arbitrary code execution via out-of-bounds write in bccomp() (CVE-2026-17544)

Bug Fix(es) and Enhancement(s):

  • Rebase PHP to 8.4.24 for CVE-2026-17543 and CVE-2026-7260 and CVE-2026-17544 in 10.2.z (JIRA:Rocky Linux-223949)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
php8.4-pgsqlaarch641.el10_2php8.4-pgsql-8.4.24-1.el10_2.aarch64.rpm
php8.4-mbstringaarch641.el10_2php8.4-mbstring-8.4.24-1.el10_2.aarch64.rpm
php8.4-bcmathaarch641.el10_2php8.4-bcmath-8.4.24-1.el10_2.aarch64.rpm
php8.4-gdaarch641.el10_2php8.4-gd-8.4.24-1.el10_2.aarch64.rpm
php8.4-processaarch641.el10_2php8.4-process-8.4.24-1.el10_2.aarch64.rpm
php8.4-soapaarch641.el10_2php8.4-soap-8.4.24-1.el10_2.aarch64.rpm
php8.4-ffiaarch641.el10_2php8.4-ffi-8.4.24-1.el10_2.aarch64.rpm
php8.4-dbaaarch641.el10_2php8.4-dba-8.4.24-1.el10_2.aarch64.rpm
php8.4-dbgaarch641.el10_2php8.4-dbg-8.4.24-1.el10_2.aarch64.rpm
php8.4-xmlaarch641.el10_2php8.4-xml-8.4.24-1.el10_2.aarch64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
27 дней назад

ELSA-2026-56969: php8.4 security, bug fix, and enhancement update (IMPORTANT)

suse-cvrf
около 1 месяца назад

Security update for php8

CVSS3: 9.8
ubuntu
около 2 месяцев назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 8.1
redhat
около 2 месяцев назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 9.8
nvd
около 2 месяцев назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.