Issued at: 2026-08-31
Updated at: 2026-09-01
Advisory content derived from Red Hat RHSA-2026:61259, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Low: php security, bug fix, and enhancement update
Description
PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.
Security Fix(es):
* php: ext/openssl: memory corruption in openssl_encrypt with AES-WRAP-PAD (CVE-2026-14355)
* php: ext-pgsql: PHP: SQL injection via improper backslash escaping (CVE-2026-17543)
* php: PHP: Denial of Service via circular symbolic links in phar archives (CVE-2026-7260)
Bug Fix(es) and Enhancement(s):
* Backport fix for CVE-2026-14355 to PHP 8.0 in 9.8.z (JIRA:Rocky Linux-192624)
* Backport fix for CVE-2026-17543 and CVE-2026-7260 to PHP 8.0 in 9.8.z (JIRA:Rocky Linux-223940)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.