Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-6735 — PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation CVE-2026-7258 — PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions
🎯 Affected products4
- Red Hat Hardened Images
- php-main@aarch64 as a component of Red Hat Hardened Images
- php-main@src as a component of Red Hat Hardened Images
- php-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Restrict network access to the PHP-FPM status page to trusted internal networks or localhost. This can be achieved by configuring web server access controls (e.g., Apache httpd or Nginx) to deny external access to the status page URL. If the PHP-FPM status page functionality is not required, it should be disabled in the PHP-FPM configuration. Any changes to web server or PHP-FPM configuration may require a service reload or restart to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:14125
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-7258
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-6735
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_14125.json