RHSA-2026:56969: Important: php8.4 security, bug fix, and enhancement update
PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts.Security Fix(es): php: ext-pgsql: PHP: SQL injection via improper backslash escaping (CVE-2026-17543) php: PHP: Arbitrary code execution via out-of-bounds write in bccomp() (CVE-2026-17544) Bug Fix(es) and Enhancement(s): Rebase PHP to 8.4.24 for CVE-2026-17543 and CVE-2026-7260 and CVE-2026-17544 in 10.2.z (JIRA:RHEL-223949) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/php8.4to a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-bcmathto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-clito a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-cli-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-commonto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-common-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-dbato a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-dba-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-dbgto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-debugsourceto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-develto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-embeddedto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-enchantto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-ffito a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-ffi-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-fpmto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-gdto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-gd-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-gmpto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-intlto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-intl-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-ldapto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-mbstringto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-mysqlndto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-odbcto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-opcacheto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-pdoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-pgsqlto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-processto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-process-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-snmpto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-soapto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-soap-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-xmlto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4-xml-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2 - Upgrade
Upgrade
redhat/php8.4to a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-bcmathto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-clito a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-cli-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-commonto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-common-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-dbato a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-dba-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-dbgto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-debugsourceto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-develto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-embeddedto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-enchantto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-ffito a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-ffi-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-fpmto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-gdto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-gd-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-gmpto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-intlto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-intl-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-ldapto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-mbstringto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-mysqlndto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-odbcto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-opcacheto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-pdoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-pgsqlto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-processto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-process-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-snmpto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-soapto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-soap-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-xmlto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
redhat/php8.4-xml-debuginfoto a version that resolves this vulnerability.Fixed in 8.4.24-1.el10_2.aa - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 8.4.24Patch JIRA:RHEL-223949
Event History
Frequently Asked Questions
Which installed components should be included in an exposure inventory?
Inventory deployments of redhat/php8.4 and the listed related packages: bcmath, cli, common, and dba, including their debuginfo variants where present. The advisory identifies these packages as affected software.
What PHP rebase does this update provide, and which issues does it address?
The update rebases PHP to 8.4.24 in 10.2.z. It addresses CVE-2026-17543, CVE-2026-7260, and CVE-2026-17544.