Fedora 44 : php (2026-5f0023de35)

medium Nessus Plugin ID 358428

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 44 host has a package installed that is affected by multiple vulnerabilities as referenced in the FEDORA-2026-5f0023de35 advisory.

**PHP version 8.5.11** (24 Sep 2026)

**BCMath:**

* Fixed out-of-bounds read in bc_is_zero_for_scale() when scale exceeds n_scale. (Ilia Alshanetsky)

**Core:**

* Fixed out-of-bounds reads during automatic UTF-16/32 encoding detection. (Yudai Takada)
* Fixed bug [GH-15375](https://github.com/php/php-src/issues/15375) (Nested yield from skips items after a valid() or next() call on the inner generator). (iliaal)
* Fixed bug [GH-23232](https://github.com/php/php-src/issues/23232) (lone namespace separator asks the autoloader for an empty class name). (spawnia)
* Fixed bug [GH-23301](https://github.com/php/php-src/issues/23301) (Nested yield from yields a value twice when the middle generator delegates again). (Lazizbek Ergashev)

**DOM:**

* Fixed NamedNodeMap::getNamedItemNS() with an empty URI not matching the null namespace in spec-following mode. (Ilia Alshanetsky)
* Fixed stale getElementsByClassName() and other node list caches after className/classList writes and attribute removals. (Ilia Alshanetsky)
* Fixed a use-after-free when cloning a DOMNameSpaceNode after DOMDocument::xinclude(). (iliaal)
* Fixed a crash in DOMXPath when a php:function callback receives a nodeset and a later callback returns a node from another document. (iliaal)
* Fixed bug [GH-23331](https://github.com/php/php-src/issues/23331) (UAF when node_list_unlink() skips attribute children that still have a live wrapper). (iliaal)
* Fixed a use-after-free when Dom\Element::setAttributeNS() replaces the value of an attribute whose child still has a live wrapper. (iliaal)

**GD:**

* Fixed imageaffinematrixget() and imageaffinematrixconcat() reporting the wrong argument in error messages. (Weilin Du)

**FPM:**

* Fixed bug [GH-19320](https://github.com/php/php-src/issues/19320) (FPM UID and GID overflow). (Pratik Bhujel)
* Fixed [GHSA-62xp-839h-2637](https://github.com/php/php-src/security/advisories/GHSA-62xp-839h-2637) (IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison).
(**CVE-2026-91768**) (Alexandre Daubois)

**Intl:**

* Fixed grapheme_strpos() and grapheme_strrpos() with an empty needle returning UTF-16 offsets instead of grapheme offsets. (Ilia Alshanetsky)
* Fixed a memory leak when dumping IntlCalendar instances. (Ilia Alshanetsky)
* Fixed a memory leak when iterating IntlBreakIterator::getPartsIterator() results. (iliaal)
* Fixed a double-free when IntlGregorianCalendar construction fails after the ICU constructor adopts the TimeZone. (iliaal)
* Fixed bug [GH-23094](https://github.com/php/php-src/issues/23094) (NumberFormatter parsing offsets use UTF-16 positions for UTF-8 strings). (ColumbusLabs)
* Fixed Locale::parseLocale() reading past a trailing '-' or '_'. (iliaal, Xuyang Zhang)
* Fixed grapheme_str_split() treating UBRK_DONE as a byte index. (iliaal)
* Fixed a leak in Locale::getKeywords() when a keyword value cannot be read. (iliaal)
* Fixed a use-after-free when IntlRuleBasedBreakIterator is constructed from compiled rules. (iliaal)

**MBString:**

* Fixed mb_ereg_replace() emitting a NUL or out-of-bounds bytes in the replacement when a \k<name> backref has no closing delimiter. (Ilia Alshanetsky)

**MySQLnd:**

* Fixed [GHSA-r6x9-5r99-36j7](https://github.com/php/php-src/security/advisories/GHSA-r6x9-5r99-36j7) (Various packet overreads in mysqlnd wire protocol). (**CVE-2025-1218**) (Jakub Zelenka, Nora Dossche)

**ODBC:**

* Fixed odbc_field_len(), odbc_field_scale() and odbc_field_type() returning uninitialized memory when SQLColAttribute fails. (Ilia Alshanetsky)

**Opcache:**

* Fixed opcache.protect_memory race under ZTS. (realFlowControl)
* Fixed a tracing JIT crash when compiling a side trace for a method of a class that could not be stored in the inheritance cache. ([GH-21710](https://github.com/php/php-src/issues/21710)) (Arnaud, iliaal)
* Fixed a crash when the huge page SHM remap discarded mappings outside the reserved address range. (Piotr Haas)

**OpenSSL:**

* Fixed [GHSA-vvx9-73fr-5jjx](https://github.com/php/php-src/security/advisories/GHSA-vvx9-73fr-5jjx) (TLS hostname verification falls back to CN after SAN mismatch). (**CVE-2026-91769**) (Jakub Zelenka)
* Fixed [GHSA-xr7j-rvgx-xq5p](https://github.com/php/php-src/security/advisories/GHSA-xr7j-rvgx-xq5p) (Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN).
(**CVE-2026-91767**) (Jakub Zelenka)

**PDO:**

* Fixed a leak when a persistent connection failed a liveness check with no other live PDO handle.
(iliaal)

**PDO_PGSQL:**

* Fixed PDO::CURSOR_SCROLL statements failing under lazy fetching (PDO::ATTR_PREFETCH => 0).
(KentarouTakeda)

**PDO Sqlite:**

* Fixed bug [GH-20214](https://github.com/php/php-src/issues/20214) (PDO::FETCH_DEFAULT unexpected behavior with PDOStatement::setFetchMode). (SakiTakamachi)

**Phar:**

* Fixed bug [GH-23418](https://github.com/php/php-src/issues/23418) (Use-after-free when looking up mounted directories). (Weilin Du)
* Fixed bug [GH-23477](https://github.com/php/php-src/issues/23477) (Memory leak on duplicate native Phar manifest entries). (Weilin Du)
* Fixed [GHSA-j3wh-g957-2m85](https://github.com/php/php-src/security/advisories/GHSA-j3wh-g957-2m85) (Integer overflow in phar_tar_number() allowing TAR archive entry injection). (**CVE-2026-6103**) (Jakub Zelenka)

**Readline:**

* Fixed the interactive shell not waiting for the pager process to exit. (Weilin Du)

**SOAP:**

* Fixed WSDL cache corruption when a soap:header defines headerfaults. (Ilia Alshanetsky)
* Fixed stack overflow when parsing a WSDL with self-referential schema groups or attributeGroups. (Ilia Alshanetsky)
* Fixed [GHSA-rgrp-mwpx-f6rm](https://github.com/php/php-src/security/advisories/GHSA-rgrp-mwpx-f6rm) (Unbounded recursion in server-side cleanup_xml_node()). (**CVE-2026-91765**) (Alexandre Daubois)
* Fixed [GHSA-cj93-vc83-wgqv](https://github.com/php/php-src/security/advisories/GHSA-cj93-vc83-wgqv) (Integer overflow to buffer overflow in SOAP HTTP parsing). (**CVE-2025-14181**) (Nora Dossche, Jakub Zelenka)

**Standard:**

* Fixed a segfault when a stream filter callback unsets StreamBucket::$data before re-attaching the bucket. (iliaal)
* Fixed [GHSA-7875-c8px-7q5f](https://github.com/php/php-src/security/advisories/GHSA-7875-c8px-7q5f) (Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header).
(**CVE-2026-93682**) (Ilia Alshanetsky, Jordi Kroon)
* Fixed read buffer compaction in php_stream_filter_flush(). (crystarm)
* Fixed bug [GH-22410](https://github.com/php/php-src/issues/22410) (Incorrect float behavior with large numbers). (arshidkv12)
* Fixed [GH-23338](https://github.com/php/php-src/issues/23338) (fsockopen()/pfsockopen() ValueError reported wrong argument number for $timeout). (lacatoire)
* Fixed bug [GH-23576](https://github.com/php/php-src/issues/23576) (Next index for array returned from array_keys() is wrong). (Lazizbek Ergashev)
* Fixed [GHSA-88hq-2827-7pg6](https://github.com/php/php-src/security/advisories/GHSA-88hq-2827-7pg6) (Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL). (**CVE-2026-92842**) (geeknik)
* Fixed [GHSA-fpwc-w8rq-cr92](https://github.com/php/php-src/security/advisories/GHSA-fpwc-w8rq-cr92) (Cross-origin credential leak in HTTP stream wrapper redirects). (**CVE-2026-91766**) (Alexandre Daubois)

**SimpleXML:**

* Fixed writing to a dimension of the object returned by attributes() not creating the attribute. (Ilia Alshanetsky)
* Fixed child elements of the element returned by SimpleXMLElement::addChild() not being accessible by property name when namespaces are involved. (Ilia Alshanetsky)

**SAPI:**

* Fixed fuzzer targets failing to build in isolation. (Mrmaxmeier)
* Fixed returns uninitialized value on LiteSpeed lsapi SAPI (Go Kudo)

Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected php package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2026-5f0023de35

Plugin Details

Severity: Medium

ID: 358428

File Name: fedora_2026-5f0023de35.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 51.46

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 4.5

Vector: CVSS2#AV:A/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-91768

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:44, p-cpe:/a:fedoraproject:fedora:php

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/22/2026

Vulnerability Publication Date: 9/22/2026

Reference Information

CVE: CVE-2025-1218, CVE-2025-14181, CVE-2026-6103, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842, CVE-2026-93682