RHSA-2026:61259: Low: php security, bug fix, and enhancement update
PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.Security Fix(es): php: ext/openssl: memory corruption in opensslencrypt with AES-WRAP-PAD (CVE-2026-14355) php: ext-pgsql: PHP: SQL injection via improper backslash escaping (CVE-2026-17543) php: PHP: Denial of Service via circular symbolic links in phar archives (CVE-2026-7260) Bug Fix(es) and Enhancement(s): Backport fix for CVE-2026-14355 to PHP 8.0 in 9.8.z (JIRA:RHEL-192624) Backport fix for CVE-2026-17543 and CVE-2026-7260 to PHP 8.0 in 9.8.z (JIRA:RHEL-223940) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-bcmathto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-clito a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-cli-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-commonto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-common-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-dbato a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-dba-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-dbgto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-debugsourceto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-develto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-embeddedto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-enchantto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-ffito a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-ffi-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-fpmto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-gdto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-gd-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-gmpto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-intlto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-intl-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-ldapto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-mbstringto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-mysqlndto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-odbcto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-opcacheto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-pdoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-pgsqlto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-processto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-process-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-snmpto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-soapto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-soap-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-xmlto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/php-xml-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-bcmathto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-clito a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-cli-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-commonto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-common-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-dbato a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-dba-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-dbgto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-debugsourceto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-develto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-embeddedto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-enchantto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-ffito a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-ffi-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-fpmto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-gdto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-gd-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-gmpto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-intlto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-intl-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-ldapto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-mbstringto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-mysqlndto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-odbcto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-opcacheto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-pdoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-pgsqlto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-processto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-process-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-snmpto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-soapto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-soap-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-xmlto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
redhat/php-xml-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-8.el9_8.aa - Upgrade
Upgrade
PHP 8.0to a version that resolves this vulnerability.Fixed in 9.8.zPatch JIRA:RHEL-223940 - Upgrade
Upgrade
PHP 8.0to a version that resolves this vulnerability.Fixed in 9.8.zPatch JIRA:RHEL-192624
Event History
Frequently Asked Questions
Which package names should be included in an inventory search for this update?
The listed packages are redhat/php, redhat/php-bcmath, redhat/php-bcmath-debuginfo, redhat/php-cli, redhat/php-cli-debuginfo, redhat/php-common, redhat/php-common-debuginfo, and redhat/php-dba.
Which security fixes were backported to PHP 8.0 in 9.8.z?
The update backports fixes for CVE-2026-14355 in ext/openssl, CVE-2026-17543 in ext-pgsql, and CVE-2026-7260 involving circular symbolic links in phar archives.