Security update for php8
Multiple critical vulnerabilities affecting PHP 8 have been addressed in updates up to version 8.5.9. These include a stack overflow in phar with circular symlinks, an SQL injection vulnerability in ext-pgsql, an out-of-bounds write in bccomp(), and an upgrade to libgd to fix related issues. The vulnerabilities impact various PHP 8 branches prior to their respective fixed versions. A security update is available and should be applied to mitigate these risks.
AI Analysis
Technical Summary
This security update for PHP 8 addresses several critical vulnerabilities: CVE-2026-7260 is a stack overflow in phar when processing circular symlinks; CVE-2026-17543 is an SQL injection vulnerability in the ext-pgsql extension via E'...' backslash breakout; CVE-2026-17544 is an out-of-bounds write in the bccomp() function triggered by crafted operands and scale; and CVE-2026-9672 involves an upgrade to libgd to fix unspecified issues. The update brings PHP to version 8.5.9, which includes fixes for these vulnerabilities. The affected versions span multiple PHP 8 branches, including >=8.2.0 <8.2.33, >=8.3.0 <8.3.33, >=8.4.0 <8.4.24, and >=8.5.0 <8.5.9. The vendor advisory from Red Hat confirms the availability of patches and recommends updating to version 8.5.9.
Potential Impact
Exploitation of these vulnerabilities could lead to serious security consequences including arbitrary code execution (stack overflow), unauthorized database access or manipulation (SQL injection), and memory corruption (out-of-bounds write). These issues pose a critical risk to systems running affected PHP versions, potentially allowing attackers to compromise application integrity and confidentiality.
Mitigation Recommendations
A security update is available that addresses these vulnerabilities. Users should upgrade PHP to version 8.5.9 or later as provided by their vendor packages. The vendor advisory from Red Hat confirms the availability of this official fix. Applying the update will mitigate the risks associated with these vulnerabilities.
Security update for php8
Description
Multiple critical vulnerabilities affecting PHP 8 have been addressed in updates up to version 8.5.9. These include a stack overflow in phar with circular symlinks, an SQL injection vulnerability in ext-pgsql, an out-of-bounds write in bccomp(), and an upgrade to libgd to fix related issues. The vulnerabilities impact various PHP 8 branches prior to their respective fixed versions. A security update is available and should be applied to mitigate these risks.
Affected software
pkg:bitnami/phpRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This security update for PHP 8 addresses several critical vulnerabilities: CVE-2026-7260 is a stack overflow in phar when processing circular symlinks; CVE-2026-17543 is an SQL injection vulnerability in the ext-pgsql extension via E'...' backslash breakout; CVE-2026-17544 is an out-of-bounds write in the bccomp() function triggered by crafted operands and scale; and CVE-2026-9672 involves an upgrade to libgd to fix unspecified issues. The update brings PHP to version 8.5.9, which includes fixes for these vulnerabilities. The affected versions span multiple PHP 8 branches, including >=8.2.0 <8.2.33, >=8.3.0 <8.3.33, >=8.4.0 <8.4.24, and >=8.5.0 <8.5.9. The vendor advisory from Red Hat confirms the availability of patches and recommends updating to version 8.5.9.
Potential Impact
Exploitation of these vulnerabilities could lead to serious security consequences including arbitrary code execution (stack overflow), unauthorized database access or manipulation (SQL injection), and memory corruption (out-of-bounds write). These issues pose a critical risk to systems running affected PHP versions, potentially allowing attackers to compromise application integrity and confidentiality.
Mitigation Recommendations
A security update is available that addresses these vulnerabilities. Users should upgrade PHP to version 8.5.9 or later as provided by their vendor packages. The vendor advisory from Red Hat confirms the availability of this official fix. Applying the update will mitigate the risks associated with these vulnerabilities.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:47200
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-17544"]
- State
- PUBLISHED
Threat ID: 6a74cfabbf8831d5391b1a7a
Added to database: 08/06/2026, 18:17:15 UTC
Last enriched: 09/17/2026, 03:18:55 UTC
Last updated: 09/21/2026, 22:01:32 UTC
Views: 93
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.