RHSA-2026:49914: Low: php8.4 security, bug fix, and enhancement update
Low: php8.4 security, bug fix, and enhancement update
Other sources
PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts.Security Fix(es): php: PHP OpenSSL extension: Denial of Service due to buffer allocation flaw in AES-WRAP-PAD (CVE-2026-14355) Bug Fix(es) and Enhancement(s): Rebase PHP to 8.4.23 for CVE-2026-14355 in 10.2.z (JIRA:RHEL-192616) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/php8.4to a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-bcmathto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-clito a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-cli-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-commonto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-common-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-dbato a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-dba-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-dbgto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-debugsourceto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-develto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-embeddedto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-enchantto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-ffito a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-ffi-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-fpmto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-gdto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-gd-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-gmpto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-intlto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-intl-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-ldapto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-mbstringto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-mysqlndto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-odbcto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-opcacheto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-pdoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-pgsqlto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-processto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-process-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-snmpto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-soapto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-soap-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-xmlto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-xml-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2 - Upgrade
Upgrade
redhat/php8.4to a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-bcmathto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-clito a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-cli-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-commonto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-common-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-dbato a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-dba-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-dbgto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-debugsourceto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-develto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-embeddedto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-enchantto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-ffito a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-ffi-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-fpmto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-gdto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-gd-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-gmpto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-intlto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-intl-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-ldapto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-mbstringto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-mysqlndto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-odbcto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-opcacheto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-pdoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-pgsqlto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-processto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-process-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-snmpto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-soapto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-soap-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-xmlto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-xml-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.23-1.el10_2.aa - Upgrade
Upgrade
php8.4to a version that resolves this vulnerability.Fixed in 8.4.23Patch CVE-2026-14355 - Compensating control
Rebase PHP to include the fix for the PHP OpenSSL extension denial of service issue caused by the AES-WRAP-PAD buffer allocation flaw (CVE-2026-14355).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49914?
The severity of RHSA-2026:49914 is classified as low.
How do I fix RHSA-2026:49914?
To fix RHSA-2026:49914, you need to apply the latest security, bug fix, and enhancement updates for PHP 8.4.
What is the nature of the update in RHSA-2026:49914?
RHSA-2026:49914 includes security fixes, bug fixes, and enhancements specifically for PHP 8.4.
Which software is affected by RHSA-2026:49914?
RHSA-2026:49914 affects Red Hat Enterprise Linux across various architectures including ARM 64, Power, and x86_64.
Is RHSA-2026:49914 part of Extended Update Support?
Yes, RHSA-2026:49914 is relevant for systems under Extended Update Support for Red Hat Enterprise Linux.