VDB
ALSA-2025%3A23309
ALSA-2025%3A23309
PUBLISHED
PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): * php: pgsql extension does not check for errors during escaping (CVE-2025-1735) * php: NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix (CVE-2025-6491) * php: PHP Hostname Null Character Vulnerability (CVE-2025-1220) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| AlmaLinux:9 | php-common | 0, 0 |
| AlmaLinux:9 | php-pecl-apcu | 0, 0 |
| AlmaLinux:9 | php-soap | 0, 0 |
| AlmaLinux:9 | php-embedded | 0, 0 |
| AlmaLinux:9 | php-pdo | 0, 0 |
| AlmaLinux:9 | php-opcache | 0, 0 |
| AlmaLinux:9 | php-cli | 0, 0 |
| AlmaLinux:9 | php-dba | 0, 0 |
| AlmaLinux:9 | php-pgsql | 0, 0 |
| AlmaLinux:9 | php-process | 0, 0 |
| AlmaLinux:9 | php-pecl-xdebug3 | 0, 0 |
| AlmaLinux:9 | php-dbg | 0, 0 |
| AlmaLinux:9 | php-pecl-rrd | 0, 0 |
| AlmaLinux:9 | php-gd | 0, 0 |
| AlmaLinux:9 | php-pecl-zip | 0, 0 |
| AlmaLinux:9 | php-mysqlnd | 0, 0 |
| AlmaLinux:9 | php-pecl-apcu-devel | 0, 0 |
| AlmaLinux:9 | php-ffi | 0, 0 |
| AlmaLinux:9 | php-pecl-redis6 | 0, 0 |
| AlmaLinux:9 | php-gmp | 0, 0 |
…and 12 more
Timeline
- Dec 16, 2025 CVE Published
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Security Advisory
- Mar 12, 2026 Distribution Patch
References
- https://access.redhat.com/errata/RHSA-2025:23309 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-1220 third-party-advisory
- https://bugzilla.redhat.com/2378689 third-party-advisory
- https://bugzilla.redhat.com/2378690 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2025-1735 report
- https://access.redhat.com/security/cve/CVE-2025-6491 report
- https://bugzilla.redhat.com/2379792 report
- https://errata.almalinux.org/9/ALSA-2025-23309.html advisory