Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (11)
📋 Description
CVE-2025-1218 — php: php: Denial of Service via out-of-bounds read in mysqlnd wire protocol parser CVE-2025-14181 — php: PHP: Denial of Service via heap buffer overflow in SOAP client CVE-2026-6103 — php: PHP: Archive entry injection via integer overflow in TAR parser CVE-2026-17545 — php: PHP: Denial of Service via reserved device names on Windows CVE-2026-91765 — php: php: Denial of Service via unbounded recursion in SOAP parser CVE-2026-91766 — php: php: Credential disclosure via cross-origin HTTP redirects CVE-2026-91767 — php: php: Information disclosure via crafted TLS server certificate CVE-2026-91768 — php: php: Access control bypass via partial IPv6 address comparison CVE-2026-91769 — php: php: Server impersonation via Common Name fallback in TLS verification CVE-2026-92842 — php: php: Information disclosure via out-of-bounds read in stream filters CVE-2026-93682 — php: php: Out-of-bounds read via empty HTTP redirect Location header
🎯 Affected products58
- Red Hat Hardened Images
- php-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-0:8.5.11-2.hum1@src as a component of Red Hat Hardened Images
- php-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-bcmath-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-bcmath-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-cli-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-cli-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-common-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-common-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-dba-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-dba-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-dbg-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-dbg-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-devel-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-devel-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-embedded-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-embedded-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-enchant-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-enchant-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-ffi-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-ffi-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-fpm-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-fpm-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-gd-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-gd-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-gmp-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-gmp-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- php-intl-0:8.5.11-2.hum1@aarch64 as a component of Red Hat Hardened Images
- php-intl-0:8.5.11-2.hum1@x86_64 as a component of Red Hat Hardened Images
- +28 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: If SoapServer is unused, disable or remove the SOAP extension (php-soap / extension=soap) so the vulnerable parser is not loaded. Restrict any exposed SoapServer endpoints to trusted clients using a host firewall or network segmentation. Process and cgroup resource limits may contain host impact but do not prevent PHP-FPM worker crashes or pool exhaustion from crafted nested SOAP requests. Workaround: Configure PHP-FPM to communicate over a local UNIX domain socket or enforce IPv6 access controls using host-based firewall rules. 1. Local UNIX domain socket configuration (for deployments where the web server and PHP-FPM reside on the same host): Edit `/etc/php-fpm.d/www.conf` to set: listen = /run/php-fpm/www.sock Configure the upstream web server (such as Apache HTTP Server or NGINX) to route FastCGI requests via the UNIX socket path instead of TCP. Apply the configuration by restarting the service: systemctl restart php-fpm 2. Firewall filtering (if PHP-FPM must listen over a TCP network port): Restrict access to the FastCGI port using firewalld to ensure exact 128-bit IPv6 address matching: firewall-cmd --permanent --add-rich-rule='rule family="ipv6" source address="<ALLOWED_IPV6_HOST>/128" port port="9000" protocol="tcp" accept' firewall-cmd --reload Caveats: Switching to a UNIX domain socket requires aligning FastCGI proxy parameters in the upstream web server. Applying firewall rules may block legitimate traffic if authorized client IPv6 addresses change dynamically. Warning: Restarting php-fpm will terminate active FastCGI connections and temporarily disrupt processing of PHP requests. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:70720
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-93682
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-6103
- externalhttps://access.redhat.com/security/cve/CVE-2026-91765
- externalhttps://access.redhat.com/security/cve/CVE-2026-17545
- externalhttps://access.redhat.com/security/cve/CVE-2026-91768
- externalhttps://access.redhat.com/security/cve/CVE-2026-92842
- externalhttps://access.redhat.com/security/cve/CVE-2026-91766
- externalhttps://access.redhat.com/security/cve/CVE-2025-1218
- externalhttps://access.redhat.com/security/cve/CVE-2026-91767
- externalhttps://access.redhat.com/security/cve/CVE-2025-14181
- externalhttps://access.redhat.com/security/cve/CVE-2026-91769
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_70720.json