RHSA-2026:62334: Important: php:7.4 security, bug fix, and enhancement update
Important: php:7.4 security, bug fix, and enhancement update
Other sources
PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.Security Fix(es): php: ext-pgsql: PHP: SQL injection via improper backslash escaping (CVE-2026-17543) php: PHP: Denial of Service via circular symbolic links in phar archives (CVE-2026-7260) Bug Fix(es) and Enhancement(s): Backport fix for CVE-2026-17543 and CVE-2026-7260 to PHP 7.4 in 8.10.z (JIRA:RHEL-223936) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libzipto a version that resolves this vulnerability.Fixed in 1.6.1-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-pearto a version that resolves this vulnerability.Fixed in 1.10.13-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pecl-apcuto a version that resolves this vulnerability.Fixed in 5.1.18-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pecl-rrdto a version that resolves this vulnerability.Fixed in 2.0.1-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pecl-xdebugto a version that resolves this vulnerability.Fixed in 2.9.5-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pecl-zipto a version that resolves this vulnerability.Fixed in 1.18.2-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/apcu-panelto a version that resolves this vulnerability.Fixed in 5.1.18-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/libzip-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/libzip-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.1-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/libzip-develto a version that resolves this vulnerability.Fixed in 1.6.1-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/libzip-toolsto a version that resolves this vulnerability.Fixed in 1.6.1-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/libzip-tools-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-bcmathto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-clito a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-cli-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-commonto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-common-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-dbato a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-dba-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-dbgto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-debugsourceto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-develto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-embeddedto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-enchantto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-ffito a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-ffi-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-fpmto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-gdto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-gd-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-gmpto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-intlto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-intl-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-jsonto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-json-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-ldapto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-mbstringto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-mysqlndto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-odbcto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-opcacheto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-pdoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-pecl-apcu-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.18-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pecl-apcu-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.18-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pecl-apcu-develto a version that resolves this vulnerability.Fixed in 5.1.18-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pecl-rrd-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.1-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pecl-rrd-debugsourceto a version that resolves this vulnerability.Fixed in 2.0.1-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pecl-xdebug-debuginfoto a version that resolves this vulnerability.Fixed in 2.9.5-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pecl-xdebug-debugsourceto a version that resolves this vulnerability.Fixed in 2.9.5-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pecl-zip-debuginfoto a version that resolves this vulnerability.Fixed in 1.18.2-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pecl-zip-debugsourceto a version that resolves this vulnerability.Fixed in 1.18.2-1.module+el8.10.0+22485+a3539972 - Upgrade
Upgrade
redhat/php-pgsqlto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-processto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-process-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-snmpto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-soapto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-soap-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-xmlto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-xml-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-xmlrpcto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/php-xmlrpc-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec - Upgrade
Upgrade
redhat/libzipto a version that resolves this vulnerability.Fixed in 1.6.1-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/libzip-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/libzip-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.1-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/libzip-develto a version that resolves this vulnerability.Fixed in 1.6.1-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/libzip-toolsto a version that resolves this vulnerability.Fixed in 1.6.1-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/libzip-tools-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-bcmathto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-clito a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-cli-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-commonto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-common-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-dbato a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-dba-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-dbgto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-debugsourceto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-develto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-embeddedto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-enchantto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-ffito a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-ffi-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-fpmto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-gdto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-gd-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-gmpto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-intlto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-intl-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-jsonto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-json-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-ldapto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-mbstringto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-mysqlndto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-odbcto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-opcacheto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-pdoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-pecl-apcuto a version that resolves this vulnerability.Fixed in 5.1.18-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pecl-apcu-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.18-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pecl-apcu-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.18-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pecl-apcu-develto a version that resolves this vulnerability.Fixed in 5.1.18-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pecl-rrdto a version that resolves this vulnerability.Fixed in 2.0.1-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pecl-rrd-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.1-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pecl-rrd-debugsourceto a version that resolves this vulnerability.Fixed in 2.0.1-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pecl-xdebugto a version that resolves this vulnerability.Fixed in 2.9.5-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pecl-xdebug-debuginfoto a version that resolves this vulnerability.Fixed in 2.9.5-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pecl-xdebug-debugsourceto a version that resolves this vulnerability.Fixed in 2.9.5-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pecl-zipto a version that resolves this vulnerability.Fixed in 1.18.2-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pecl-zip-debuginfoto a version that resolves this vulnerability.Fixed in 1.18.2-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pecl-zip-debugsourceto a version that resolves this vulnerability.Fixed in 1.18.2-1.module+el8.10.0+22485+a3539972.aa - Upgrade
Upgrade
redhat/php-pgsqlto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-processto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-process-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-snmpto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-soapto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-soap-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-xmlto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-xml-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-xmlrpcto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
redhat/php-xmlrpc-debuginfoto a version that resolves this vulnerability.Fixed in 7.4.33-6.module+el8.10.0+24605+5caacdec.aa - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 8.10.zPatch JIRA:RHEL-223936
Event History
Frequently Asked Questions
Which components are affected by this update?
The advisory covers Red Hat PHP 7.4 packages and lists related libzip and PHP extension packages, including APCu, RRD, Xdebug, and ZIP packages.
What conditions are relevant to exploitation of the SQL injection issue?
The SQL injection issue is in PHP's ext-pgsql component and involves improper backslash escaping. Systems using PHP PostgreSQL functionality are the relevant exposure area identified by the advisory.
What conditions are relevant to the denial-of-service issue?
The denial-of-service issue involves circular symbolic links in PHAR archives. Exposure is relevant where PHP processes PHAR archives that could contain circular symbolic links.
What remediation does the advisory provide?
The update backports fixes for CVE-2026-17543 and CVE-2026-7260 to PHP 7.4 in 8.10.z.