VDB

ALSA-2025%3A23309

ALSA-2025%3A23309 PUBLISHED

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): * php: pgsql extension does not check for errors during escaping (CVE-2025-1735) * php: NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix (CVE-2025-6491) * php: PHP Hostname Null Character Vulnerability (CVE-2025-1220) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected Products

VendorProductVersions
AlmaLinux:9php-common0, 0
AlmaLinux:9php-pecl-apcu0, 0
AlmaLinux:9php-soap0, 0
AlmaLinux:9php-embedded0, 0
AlmaLinux:9php-pdo0, 0
AlmaLinux:9php-opcache0, 0
AlmaLinux:9php-cli0, 0
AlmaLinux:9php-dba0, 0
AlmaLinux:9php-pgsql0, 0
AlmaLinux:9php-process0, 0
AlmaLinux:9php-pecl-xdebug30, 0
AlmaLinux:9php-dbg0, 0
AlmaLinux:9php-pecl-rrd0, 0
AlmaLinux:9php-gd0, 0
AlmaLinux:9php-pecl-zip0, 0
AlmaLinux:9php-mysqlnd0, 0
AlmaLinux:9php-pecl-apcu-devel0, 0
AlmaLinux:9php-ffi0, 0
AlmaLinux:9php-pecl-redis60, 0
AlmaLinux:9php-gmp0, 0

…and 12 more

Timeline

  • Dec 16, 2025 CVE Published
  • Mar 6, 2026 Distribution Patch
  • Mar 6, 2026 Security Advisory
  • Mar 12, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›