Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
A critical security flaw exists in PHP's bccomp() function used in Red Hat Hardened Images, leading to an out-of-bounds write that can cause stack and heap corruption. This memory corruption may enable arbitrary code execution by a remote attacker. The vulnerability affects PHP 8.4 and 8.5 streams in Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS 2.0.z. Exploitation requires high attack complexity but no privileges or user interaction. Red Hat has released updated PHP RPM packages to address this issue. No mitigations meeting Red Hat's criteria are currently available aside from applying the update.
AI Analysis
Technical Summary
CVE-2026-17544 is a critical vulnerability in PHP's bccomp() function that allows a remote attacker to cause an out-of-bounds write, resulting in stack and heap corruption. This memory corruption can lead to arbitrary code execution, compromising the affected system. The flaw affects PHP versions 8.4 and 8.5 streams as shipped in Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS 2.0.z. Red Hat has issued updated PHP RPM packages (version 8.5.9-1.hum1) for multiple PHP components to fix this issue. The vulnerability is classified under CWE-787 (Out-of-bounds Write) and CWE-89 (SQL Injection is listed but not detailed in the advisory). Exploitation requires high attack complexity but no privileges or user interaction. Red Hat's advisory states no effective mitigations exist other than applying the update. The vendor advisory is the authoritative source for patch status and impact.
Potential Impact
Successful exploitation of this vulnerability can lead to arbitrary code execution on affected systems, allowing an attacker to take full control. The flaw causes memory corruption (stack and heap), which can also result in denial of service through crashes. The attack vector is network-based with no privileges or user interaction required, but the attack complexity is high. This makes the vulnerability critical in severity.
Mitigation Recommendations
Red Hat has released updated PHP RPM packages (version 8.5.9-1.hum1) that fix this vulnerability. Applying these updates to the affected PHP packages in Red Hat Hardened Images is the recommended remediation. No other mitigations meeting Red Hat's criteria for ease of use, applicability, and stability are currently available. Users should follow Red Hat's official update instructions at https://images.redhat.com/ to apply the fix.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
A critical security flaw exists in PHP's bccomp() function used in Red Hat Hardened Images, leading to an out-of-bounds write that can cause stack and heap corruption. This memory corruption may enable arbitrary code execution by a remote attacker. The vulnerability affects PHP 8.4 and 8.5 streams in Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS 2.0.z. Exploitation requires high attack complexity but no privileges or user interaction. Red Hat has released updated PHP RPM packages to address this issue. No mitigations meeting Red Hat's criteria are currently available aside from applying the update.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-17544 is a critical vulnerability in PHP's bccomp() function that allows a remote attacker to cause an out-of-bounds write, resulting in stack and heap corruption. This memory corruption can lead to arbitrary code execution, compromising the affected system. The flaw affects PHP versions 8.4 and 8.5 streams as shipped in Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS 2.0.z. Red Hat has issued updated PHP RPM packages (version 8.5.9-1.hum1) for multiple PHP components to fix this issue. The vulnerability is classified under CWE-787 (Out-of-bounds Write) and CWE-89 (SQL Injection is listed but not detailed in the advisory). Exploitation requires high attack complexity but no privileges or user interaction. Red Hat's advisory states no effective mitigations exist other than applying the update. The vendor advisory is the authoritative source for patch status and impact.
Potential Impact
Successful exploitation of this vulnerability can lead to arbitrary code execution on affected systems, allowing an attacker to take full control. The flaw causes memory corruption (stack and heap), which can also result in denial of service through crashes. The attack vector is network-based with no privileges or user interaction required, but the attack complexity is high. This makes the vulnerability critical in severity.
Mitigation Recommendations
Red Hat has released updated PHP RPM packages (version 8.5.9-1.hum1) that fix this vulnerability. Applying these updates to the affected PHP packages in Red Hat Hardened Images is the recommended remediation. No other mitigations meeting Red Hat's criteria for ease of use, applicability, and stability are currently available. Users should follow Red Hat's official update instructions at https://images.redhat.com/ to apply the fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:47200
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-17544"]
- Cvss Version
- null
Threat ID: 6a74cfabbf8831d5391b1a7a
Added to database: 08/06/2026, 18:17:15 UTC
Last enriched: 08/06/2026, 19:18:11 UTC
Last updated: 08/07/2026, 00:41:12 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.