In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.
CVE state is currently "Fix Deferred". Is there a plan to fix this for Red Hat 8.10 for DNF Module php:8.2?
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:23309 https://access.redhat.com/errata/RHSA-2025:23309
Will a fix be issued to Red Hat Enterprise Linux 8?
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1412 https://access.redhat.com/errata/RHSA-2026:1412
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1409 https://access.redhat.com/errata/RHSA-2026:1409