Fedora 42 : php (2025-ce8a4096e7)

high Nessus Plugin ID 279350

Language:

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 42 host has a package installed that is affected by multiple vulnerabilities as referenced in the FEDORA-2025-ce8a4096e7 advisory.

**PHP version 8.4.16** (18 Dec 2025)

**Core:**

* Sync all boost.context files with release 1.86.0. (mvorisek)
* Fixed bug [GH-20435](https://github.com/php/php-src/issues/20435) (SensitiveParameter doesn't work for named argument passing to variadic parameter). (ndossche)
* Fixed bug [GH-20286](https://github.com/php/php-src/issues/20286) (use-after-destroy during userland stream_close()). (ndossche, David Carlier)

**Bz2:**

* Fix assertion failures resulting in crashes with stream filter object parameters. (ndossche)

**Date:**

* Fix crashes when trying to instantiate uninstantiable classes via date static constructors. (ndossche)

**DOM:**

* Fix memory leak when edge case is hit when registering xpath callback. (ndossche)
* Fixed bug [GH-20395](https://github.com/php/php-src/issues/20395) (querySelector and querySelectorAll requires elements in $selectors to be lowercase). (ndossche)
* Fix missing NUL byte check on C14NFile(). (ndossche)

**Fibers:**

* Fixed bug [GH-20483](https://github.com/php/php-src/issues/20483) (ASAN stack overflow with fiber.stack_size INI small value). (David Carlier)

**FTP:**

* Fixed bug [GH-20601](https://github.com/php/php-src/issues/20601) (ftp_connect overflow on timeout).
(David Carlier)

**GD:**

* Fixed bug [GH-20511](https://github.com/php/php-src/issues/20511) (imagegammacorrect out of range input/output values). (David Carlier)
* Fixed bug [GH-20602](https://github.com/php/php-src/issues/20602) (imagescale overflow with large height values). (David Carlier)

**Intl:**

* Fixed bug [GH-20426](https://github.com/php/php-src/issues/20426) (Spoofchecker::setRestrictionLevel() error message suggests missing constants). (DanielEScherzer)

**LibXML:**

* Fix some deprecations on newer libxml versions regarding input buffer/parser handling. (ndossche)

**MbString:**

* Fixed bug [GH-20491](https://github.com/php/php-src/issues/20491) (SLES15 compile error with mbstring oniguruma). (ndossche)
* Fixed bug [GH-20492](https://github.com/php/php-src/issues/20492) (mbstring compile warning due to non- strings). (ndossche)

**MySQLnd:**

* Fixed bug [GH-20528](https://github.com/php/php-src/issues/20528) (Regression breaks mysql connexion using an IPv6 address enclosed in square brackets). (Remi)

**Opcache:**

* Fixed bug [GH-20329](https://github.com/php/php-src/issues/20329) (opcache.file_cache broken with full interned string buffer). (Arnaud)

**PDO:**

* Fixed [GHSA-8xr5-qppj-gvwj](https://github.com/php/php-src/security/advisories/GHSA-8xr5-qppj-gvwj) (PDO quoting result null deref). (**CVE-2025-14180**) (Jakub Zelenka)

**Phar:**

* Fixed bug [GH-20442](https://github.com/php/php-src/issues/20442) (Phar does not respect case- insensitiveness of __halt_compiler() when reading stub). (ndossche, TimWolla)
* Fix broken return value of fflush() for phar file entries. (ndossche)
* Fix assertion failure when fseeking a phar file out of bounds. (ndossche)

**PHPDBG:**

* Fixed ZPP type violation in phpdbg_get_executable() and phpdbg_end_oplog(). (Girgias)

**SPL:**

* Fixed bug [GH-20614](https://github.com/php/php-src/issues/20614) (SplFixedArray incorrectly handles references in deserialization). (ndossche)

**Standard:**

* Fix memory leak in array_diff() with custom type checks. (ndossche)
* Fixed bug [GH-20583](https://github.com/php/php-src/issues/20583) (Stack overflow in http_build_query via deep structures). (ndossche)
* Fixed [GHSA-www2-q4fc-65wf](https://github.com/php/php-src/security/advisories/GHSA-www2-q4fc-65wf) (Null byte termination in dns_get_record()). (ndossche)
* Fixed [GHSA-h96m-rvf9-jgm2](https://github.com/php/php-src/security/advisories/GHSA-h96m-rvf9-jgm2) (Heap buffer overflow in array_merge()). (**CVE-2025-14178**) (ndossche)
* Fixed [GHSA-3237-qqm7-mfv7](https://github.com/php/php-src/security/advisories/GHSA-3237-qqm7-mfv7) (Information Leak of Memory in getimagesize). (**CVE-2025-14177**) (ndossche)

**Tidy:**

* Fixed bug [GH-20374](https://github.com/php/php-src/issues/20374) (PHP with tidy and custom-tags).
(ndossche)

**XML:**

* Fixed bug [GH-20439](https://github.com/php/php-src/issues/20439) (xml_set_default_handler() does not properly handle special characters in attributes when passing data to callback). (ndossche)

**Zlib:**

* Fix assertion failures resulting in crashes with stream filter object parameters. (ndossche)


Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected php package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2025-ce8a4096e7

Plugin Details

Severity: High

ID: 279350

File Name: fedora_2025-ce8a4096e7.nasl

Version: 1.2

Type: local

Agent: unix

Published: 12/19/2025

Updated: 1/9/2026

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.0

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2025-14180

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:php, cpe:/o:fedoraproject:fedora:42

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 12/17/2025

Vulnerability Publication Date: 12/17/2025

Reference Information

CVE: CVE-2025-14177, CVE-2025-14178, CVE-2025-14180

FEDORA: 2025-ce8a4096e7

IAVA: 2026-A-0020