Описание
Low: php security, bug fix, and enhancement update
PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.
Security Fix(es):
-
php: ext/openssl: memory corruption in openssl_encrypt with AES-WRAP-PAD (CVE-2026-14355)
-
php: ext-pgsql: PHP: SQL injection via improper backslash escaping (CVE-2026-17543)
-
php: PHP: Denial of Service via circular symbolic links in phar archives (CVE-2026-7260)
Bug Fix(es) and Enhancement(s):
-
Backport fix for CVE-2026-14355 to PHP 8.0 in 9.8.z (JIRA:Rocky Linux-192624)
-
Backport fix for CVE-2026-17543 and CVE-2026-7260 to PHP 8.0 in 9.8.z (JIRA:Rocky Linux-223940)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Затронутые продукты
Rocky Linux 9
Связанные CVE
Ссылки на источники
Исправления
- Red Hat - 2496971
- Red Hat - 2509254
- Red Hat - 2509255