php-8.0.30-6.el9_8

エラータID: AXSA:2026-1445:02

リリース日: 
2026/08/04 Tuesday - 17:15
題名: 
php-8.0.30-6.el9_8
影響のあるチャネル: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.

Security Fix(es):

* php: php-soap: php-src: PHP SOAP extension: Remote Code Execution via use-after-free vulnerability (CVE-2026-6722)
* PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions (CVE-2026-7258)
* PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation (CVE-2026-6735)
* PHP: PHP SoapServer: Memory corruption and information disclosure via incorrect persistence handling (CVE-2026-7261)
* php: NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() (CVE-2026-7259)
* php: NULL pointer dereference in SOAP apache:Map decoder with missing (CVE-2026-7262)
* php: signed integer overflow in metaphone() (CVE-2026-7568)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-6722
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.
CVE-2026-6735
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
CVE-2026-7258
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.
CVE-2026-7259
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding().
CVE-2026-7261
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.
CVE-2026-7262
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.
CVE-2026-7568
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. php-8.0.30-6.el9_8.src.rpm
    MD5: 7b8e2c977284ab4f92ae8311255e6dbf
    SHA-256: ad5d8aad7c1894a981edb25dbf5e6de2069e8d2e293455ccca35f95f61bb49de
    Size: 10.60 MB

Asianux Server 9 for x86_64
  1. php-8.0.30-6.el9_8.x86_64.rpm
    MD5: 4098d791f297f252c0697e209d323daf
    SHA-256: cb6d854d8a89b9a29c50c33b92d4a23d05831d7d611a7d7f23cc0f535770b078
    Size: 9.26 kB
  2. php-bcmath-8.0.30-6.el9_8.x86_64.rpm
    MD5: 8755cc617daa08ccc4a3a86d404daa2b
    SHA-256: c1a6c61fc7b65db565e65a472b5dfaf3638e31cd576d8afdbc973ec883d5a7b2
    Size: 34.37 kB
  3. php-cli-8.0.30-6.el9_8.x86_64.rpm
    MD5: 5df4b282540f844fa6e111f27ae7bbd9
    SHA-256: cd8bc26b439e07e1b5817e91bd09c896009e328cafa9b03e78648f3228c1c4e6
    Size: 3.09 MB
  4. php-common-8.0.30-6.el9_8.x86_64.rpm
    MD5: 33aa7b486809db1ababdaa1f5464907a
    SHA-256: c64591d8c642074fdc838fa9353a50144e20fe2a94d86defbabbcdc6791963b2
    Size: 679.40 kB
  5. php-dba-8.0.30-6.el9_8.x86_64.rpm
    MD5: 902bd4aedf215f66f85ae0002b74471f
    SHA-256: d9900298c6b733717282aa9b1fb2a172968088b2a5c86ea77042b80fa3a0340d
    Size: 33.33 kB
  6. php-dbg-8.0.30-6.el9_8.x86_64.rpm
    MD5: f4184a6f00b0e3899fe37830eb1dd0aa
    SHA-256: 3bbcd25f55421c40d4562d15e1d2ffd5e25229ff6df0c2bd849211b5482bc7f9
    Size: 1.63 MB
  7. php-devel-8.0.30-6.el9_8.x86_64.rpm
    MD5: f658df5ebe63874f90e072b6b23c8e20
    SHA-256: a66ce7b531cb350d1d30015e817a524c1404424037d605465a26c8217aece571
    Size: 726.14 kB
  8. php-embedded-8.0.30-6.el9_8.x86_64.rpm
    MD5: 322dbbbdc42f18726931a655c371afa4
    SHA-256: a76e743d3845fd13680a757b272a3a387e60d5f3eb88d9d29b5fbbd27c7089b6
    Size: 1.52 MB
  9. php-enchant-8.0.30-6.el9_8.x86_64.rpm
    MD5: 9178d6c3e6763a90d886ccbbe1908224
    SHA-256: 72fdb684f74dd9537b8823373373a0dc352be936e607ee74c1ace2f131651c14
    Size: 18.92 kB
  10. php-ffi-8.0.30-6.el9_8.x86_64.rpm
    MD5: 8a7c467884cb688f8827afeedcca7723
    SHA-256: 733524e13684104e56c5ddb3b6fa1855b402a2dbae0a33a4c579a48e923ff60c
    Size: 73.85 kB
  11. php-fpm-8.0.30-6.el9_8.x86_64.rpm
    MD5: b6dee5a7bbe477f8f620a3445e9c4a1e
    SHA-256: f8b7879c5311a53a557aa8c314b26ed56865a6cd9253b02c92b5e2b56a79f73b
    Size: 1.60 MB
  12. php-gd-8.0.30-6.el9_8.x86_64.rpm
    MD5: 832b2dd14e666dc8d4ce47f5a450e0a9
    SHA-256: 7641826f20f44f4fd1d28772ed472e644123812c2383265c27a488251036270c
    Size: 40.42 kB
  13. php-gmp-8.0.30-6.el9_8.x86_64.rpm
    MD5: 21269db6dcd8af920a4a293e875b2606
    SHA-256: ab65a6f5d772fffb1173bc969043c8a051c65164598995314657a4abdbd43aee
    Size: 30.85 kB
  14. php-intl-8.0.30-6.el9_8.x86_64.rpm
    MD5: c0f0b84b584b4b351d629af16b472ce1
    SHA-256: f17a754b117eb59878a51f75d8b5065fd2f87fd4727b2dc7f3659ecd5b924932
    Size: 149.50 kB
  15. php-ldap-8.0.30-6.el9_8.x86_64.rpm
    MD5: 3ee51f035375250d061c1b2523d19498
    SHA-256: 6304f9ae8e804a60030cb005a0beb143be3f35bf6de2feea6857a6ff8079de88
    Size: 40.62 kB
  16. php-mbstring-8.0.30-6.el9_8.x86_64.rpm
    MD5: 9304100c848c73f9b1aabb2a649bfae2
    SHA-256: 254f04bc9a4ec91f5201170a4253abae1bbdbba363fc5a9fa8a6f0cc8e84de54
    Size: 466.88 kB
  17. php-mysqlnd-8.0.30-6.el9_8.x86_64.rpm
    MD5: 25fc37128c941270825c6fd8cce2e9dc
    SHA-256: 8e12d2053981ac65f80a04ef43f944dcff567dd8243718a324edde1fbbee6492
    Size: 150.95 kB
  18. php-odbc-8.0.30-6.el9_8.x86_64.rpm
    MD5: 455f3c60538071859ff524533a8c9028
    SHA-256: 5932d36e5069bfd33e089cbfb6a01d3c8c195d2ba1ebb4b46d56da01c6e97652
    Size: 44.24 kB
  19. php-opcache-8.0.30-6.el9_8.x86_64.rpm
    MD5: d42307459605c3b138cf05bb1e412f67
    SHA-256: 310573f67f1af38e5ae4f895ecab7c07dfa9e31513245330760f4543d0cb02f0
    Size: 510.60 kB
  20. php-pdo-8.0.30-6.el9_8.x86_64.rpm
    MD5: d7c5779e2a35b49ff8b39e66e73fdb94
    SHA-256: 48d9e89dfd48c509004b8bcb78003ab63925a593d0e156c722311f0974f648d8
    Size: 82.09 kB
  21. php-pgsql-8.0.30-6.el9_8.x86_64.rpm
    MD5: 91a8e7d0234cd14369d84c3ea8dc4ab1
    SHA-256: 8cd040910058b0f1995e9b0c9368578c40608da14200cc80c9f78686cf595af4
    Size: 72.55 kB
  22. php-process-8.0.30-6.el9_8.x86_64.rpm
    MD5: 8ce3d361e4cd928c4b3bfd4e8074f99f
    SHA-256: 728da0cd70f7bb13298c26e6578752f7f32d112abe0704a24eb74f4e582f52c1
    Size: 41.17 kB
  23. php-snmp-8.0.30-6.el9_8.x86_64.rpm
    MD5: fb07e4e0c9bd38c82cd5711b5d319bfb
    SHA-256: 65f4ad039415669928bf72e516d30105e63249737d1adba26304ce8f1f9e2680
    Size: 30.35 kB
  24. php-soap-8.0.30-6.el9_8.x86_64.rpm
    MD5: bc6fadd0e696e4ac882dae229d2a13d1
    SHA-256: 7c4dfe1d71a7b4af5c32d48f5a57c29df78af8987c616c899b16f04f0d322eac
    Size: 133.94 kB
  25. php-xml-8.0.30-6.el9_8.x86_64.rpm
    MD5: 1be115501631180752c7c8e90c13e9a7
    SHA-256: 30d185764bb69c4f5811e6b1fe62d3102e38c068096895f42c586f92e11346c6
    Size: 133.06 kB