Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.5%top 62%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
Critical
Published: 07/28/2026 (07/28/2026, 18:29:08 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A critical security flaw exists in PHP's bccomp() function used in Red Hat Hardened Images, leading to an out-of-bounds write that can cause stack and heap corruption. This memory corruption may enable arbitrary code execution by a remote attacker. The vulnerability affects PHP 8.4 and 8.5 streams in Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS 2.0.z. Exploitation requires high attack complexity but no privileges or user interaction. Red Hat has released updated PHP RPM packages to address this issue. No mitigations meeting Red Hat's criteria are currently available aside from applying the update.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 19:18:11 UTC

Technical Analysis

CVE-2026-17544 is a critical vulnerability in PHP's bccomp() function that allows a remote attacker to cause an out-of-bounds write, resulting in stack and heap corruption. This memory corruption can lead to arbitrary code execution, compromising the affected system. The flaw affects PHP versions 8.4 and 8.5 streams as shipped in Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS 2.0.z. Red Hat has issued updated PHP RPM packages (version 8.5.9-1.hum1) for multiple PHP components to fix this issue. The vulnerability is classified under CWE-787 (Out-of-bounds Write) and CWE-89 (SQL Injection is listed but not detailed in the advisory). Exploitation requires high attack complexity but no privileges or user interaction. Red Hat's advisory states no effective mitigations exist other than applying the update. The vendor advisory is the authoritative source for patch status and impact.

Potential Impact

Successful exploitation of this vulnerability can lead to arbitrary code execution on affected systems, allowing an attacker to take full control. The flaw causes memory corruption (stack and heap), which can also result in denial of service through crashes. The attack vector is network-based with no privileges or user interaction required, but the attack complexity is high. This makes the vulnerability critical in severity.

Mitigation Recommendations

Red Hat has released updated PHP RPM packages (version 8.5.9-1.hum1) that fix this vulnerability. Applying these updates to the affected PHP packages in Red Hat Hardened Images is the recommended remediation. No other mitigations meeting Red Hat's criteria for ease of use, applicability, and stability are currently available. Users should follow Red Hat's official update instructions at https://images.redhat.com/ to apply the fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:47200
Cve Count
2
Additional Cves
["CVE-2026-17544"]
Cvss Version
null

Threat ID: 6a74cfabbf8831d5391b1a7a

Added to database: 08/06/2026, 18:17:15 UTC

Last enriched: 08/06/2026, 19:18:11 UTC

Last updated: 08/07/2026, 00:41:12 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses