AlmaLinux 2572 Published by

AlmaLinux has issued an important security update for PHP versions 8.2 and 8.3 across both AlmaLinux 8 and 9 environments. This release patches four distinct vulnerabilities that could allow attackers to crash services through ctype functions or exploit improper URL handling in PHP-FPM. A NULL pointer crash during SOAP decoding and an integer overflow inside the metaphone routine round out the list of critical flaws requiring immediate attention. Administrators should apply these fixes right away because unpatched servers remain highly exposed to denial of service attacks and XSS exploits.

ALSA-2026:22305: php:8.2 security update (Important)
ALSA-2026:22142: php:8.3 security update (Important)
ALSA-2026:22143: php:8.2 security update (Important)




ALSA-2026:22305: php:8.2 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-06-01

Summary:

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.

Security Fix(es):

* PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions (CVE-2026-7258)
* PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation (CVE-2026-6735)
* php: NULL pointer dereference in SOAP apache:Map decoder with missing (CVE-2026-7262)
* php: signed integer overflow in metaphone() (CVE-2026-7568)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-22305.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:22142: php:8.3 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-06-01

Summary:

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.

Security Fix(es):

* PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions (CVE-2026-7258)
* PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation (CVE-2026-6735)
* php: NULL pointer dereference in SOAP apache:Map decoder with missing (CVE-2026-7262)
* php: signed integer overflow in metaphone() (CVE-2026-7568)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-22142.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:22143: php:8.2 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-06-01

Summary:

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.

Security Fix(es):

* PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions (CVE-2026-7258)
* PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation (CVE-2026-6735)
* php: NULL pointer dereference in SOAP apache:Map decoder with missing (CVE-2026-7262)
* php: signed integer overflow in metaphone() (CVE-2026-7568)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-22143.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team