- What: Security update for php:8.2 module
- Impact: Systems using Red Hat Enterprise Linux 9 affected
Red Hat Product Errata RHSA-2026:22143 - Security Advisory Issued: 2026-06-01 Updated: 2026-06-01 RHSA-2026:22143 - Security Advisory Overview Updated Packages Synopsis Important: php:8.2 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the php:8.2 module is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions (CVE-2026-7258) PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation (CVE-2026-6735) php: NULL pointer dereference in SOAP apache:Map decoder with missing <value> (CVE-2026-7262) php: signed integer overflow in metaphone() (CVE-2026-7568) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2468561 - CVE-2026-7258 PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions BZ - 2468562 - CVE-2026-6735 PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation BZ - 2468565 - CVE-2026-7262 php: NULL pointer dereference in SOAP apache:Map decoder with missing <value> BZ - 2468566 - CVE-2026-7568 php: signed integer overflow in metaphone() CVEs CVE-2026-6735 CVE-2026-7258 CVE-2026-7262 CVE-2026-7568 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM php-8.2.31-1.module+el9.8.0+24325+74f58d38.src.rpm SHA-256: c06954ffe3d5843b1465bc0079a69b7c07bc49c7d198de1600c1c0512e2959ba php-pecl-apcu-5.1.23-1.module+el9.7.0+24111+199d2cc4.src.rpm SHA-256: 6ae1bc6fa55dda36e0a4e034311842294e9af19a0942c386ecf4424c635fda1d php-pecl-rrd-2.0.3-4.module+el9.7.0+24111+199d2cc4.src.rpm SHA-256: 4b5e3816d4b3aa52e8f95bba2a01312b892c7acbddc450684115fd1188b8c629 php-pecl-xdebug3-3.2.2-2.module+el9.7.0+24111+199d2cc4.src.rpm SHA-256: 665ac571e6cbb0de68c7eab4884f8e4d89ee01a28145cf8752ede68b1e5d9648 php-pecl-zip-1.22.3-1.module+el9.7.0+24111+199d2cc4.src.rpm SHA-256: 36735364e2db51abbb6f7684958b5a4c3c4ecdb49395b38a076f71bf1f31ae9e x86_64 apcu-panel-5.1.23-1.module+el9.7.0+24111+199d2cc4.noarch.rpm SHA-256: 87bf89be70641c339ac2634f39ccf002c68f58b9a89a6ab83be64103403518c7 apcu-panel-5.1.23-1.module+el9.7.0+24111+199d2cc4.noarch.rpm SHA-256: 87bf89be70641c339ac2634f39ccf002c68f58b9a89a6ab83be64103403518c7 apcu-panel-5.1.23-1.module+el9.7.0+24111+199d2cc4.noarch.rpm SHA-256: 87bf89be70641c339ac2634f39ccf002c68f58b9a89a6ab83be64103403518c7 php-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 6be2da6ef4b17a38314cb29e5d428595d44986ecccde2eeac66f6dcd880cd807 php-bcmath-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 974dd1fda94c00e60adc9ed3610b49ba88e0418b614a419777357239bd74fdc7 php-bcmath-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 2e0a99305da9404149aec47b51ecae428869cab84a68928af75edc091779433b php-cli-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: c0ef2ddc82d1d7f45d2442789beb2eca72f9080d8e006e24b1f3477711192357 php-cli-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: eb97cbff4cff33f755743a5ad55addbbf612b1f80c75b11308b2b4eb64209aaa php-common-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: bc59b0bb3fb52f797008779ea600c83b6e0266510aed078944b40a32783f5a83 php-common-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: e1c9acfd85d661a83b65fb9481557022c02e3bae3fb546197de83bc732d778b1 php-dba-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 38ca52689a0265b544925f6670eba73cdfc2cebbd047b92eda51c8d396f1d7ef php-dba-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: a80bd46fd3e6122bbda69ada3d867e6d5487a644c0a0b778b34712fd75a4a6cd php-dbg-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 63b941e82e7e259c880b1ba6427e95c780915787a79a4b99119b50a5ec6a5c48 php-dbg-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 8457f827ba4c6bd7dc4d5a703cd67af53896345a26c46fec8a678a9820855b1e php-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: d903c94c435c25ef10749fecf73a435dfc3ca57e98a18c386a2b69beccc221e5 php-debugsource-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: ed7fcc3cc1078a5b69ba5b766465782b735cb0b6ecdbd31d83c61149e56428c8 php-devel-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 9c9adef7d080e959267f9883dff0d1fb96169180990489bbd89602b1f14ffb6a php-embedded-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: f715a54fbb560b4096e3e83aead6274a6fa4d28b648e076a06e2acdf61230c5b php-embedded-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: abb216ff194aa4bf8b04059e67de5ab86adccf541bcb89d50f608e3f368f31cf php-enchant-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 1bfcd11689340705cfe320e282867ab2924a0c4a07b7a11447640cc287003c5b php-enchant-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 00d784c629c9e4450b9215f4fb2143e5cf7dc3d6d6bfa74b36d2c1846d035956 php-ffi-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 40c1da022a52f0fcb0eaaeccdc233fb47667ed4f3cb4f4f7b23de9ae92252257 php-ffi-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: f0a2fac99575c8effb96a483f0110ccac0063ac8187f12c41bbb3cc598c1eccb php-fpm-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: c44d0a98ff31c1cf809aad02cb7588ac8e5005bddb7436e9d99530b6f716abbe php-fpm-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: f82de808e63257113b9f3cc876fad87d29df5500c56f335b4bbd90042fa09cd7 php-gd-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 601e16a33f65342ffee7c976fbe85667470a11fa4905dfaddfb6e800a9937f4d php-gd-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 2aa3ce2f615e1c72d2b3daab5f5afeb50a45cffab3baffaa2ec14d1eda4b64ab php-gmp-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 66c0b881d9ea043f55cde6908f1f9016f58e48e0dfb05828f06590e1a1b76a6b php-gmp-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 5a1c5ea4b7a885fe02c97c036d39ae3eda8d85de604cb030510d7867cc04122a php-intl-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 06191371756f0ea5d56ed79e4a6b55a41fed542be2740d5f33b69268ff2daff3 php-intl-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 95fe98d096911c71618fd2f602db955d76ca2aa94ce64a86553c594e082cb7e2 php-ldap-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 063d4bcc1cfd9b363a781058c6c388532e56250cba6a8338d06eee5c40982b90 php-ldap-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 181870dbdb78fa7df426266f670bd117163fe0ffd1165830e2d86ad8b99d6aa8 php-mbstring-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 7bec82d61d5fa87253920f17e118cdc1fe2b18a286b500ceae8d83c251f4fef5 php-mbstring-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 6672c5313bcd8ff02a82ce980b60a8f0c13d1ccbd5986e56891ffaa54f1e8c79 php-mysqlnd-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 2c400c1e9ffc632c2856d59bdc1beead2483cf69429b5911e01516197bad556d php-mysqlnd-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 3bacbff1ac4550c648e8c001d571846d3e1f465309d8e86465bd66d30f4942f7 php-odbc-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 77171bb8c6bc605dcce580de334c2d83a1e603abaf3a1e609b4f78d17d17d16c php-odbc-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: d80060d63c35754742d0377cf575399cb57499db57f3b76e312710037e740f64 php-opcache-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 17436752c8b9e3951506670c03bf7d934d7c21d8a960267b28517738682f9b12 php-opcache-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 53b12d18cebf4d3e5f5f8dc1dca56a7cc262ecf85e612d28e471ebac25d9def6 php-pdo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 6ee3caaa8b8154b312821ee33981d5880d438ae0f292703a8fa5b184d70123b4 php-pdo-debuginfo-8.2.31-1.module+el9.8.0+24325+74f58d38.x86_64.rpm SHA-256: 8f9c329916564086fbdc883ec3beb0d5c04cbd8c06622034f2d68bd2dc