In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:1169 https://access.redhat.com/errata/RHSA-2026:1169
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:1185 https://access.redhat.com/errata/RHSA-2026:1185
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:1187 https://access.redhat.com/errata/RHSA-2026:1187
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:1190 https://access.redhat.com/errata/RHSA-2026:1190
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1412 https://access.redhat.com/errata/RHSA-2026:1412
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1409 https://access.redhat.com/errata/RHSA-2026:1409
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1429 https://access.redhat.com/errata/RHSA-2026:1429
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:1628 https://access.redhat.com/errata/RHSA-2026:1628
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:2470 https://access.redhat.com/errata/RHSA-2026:2470
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:2799 https://access.redhat.com/errata/RHSA-2026:2799
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:4077 https://access.redhat.com/errata/RHSA-2026:4077
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:4086 https://access.redhat.com/errata/RHSA-2026:4086
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:4212 https://access.redhat.com/errata/RHSA-2026:4212
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:4266 https://access.redhat.com/errata/RHSA-2026:4266
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:4507 https://access.redhat.com/errata/RHSA-2026:4507
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:4514 https://access.redhat.com/errata/RHSA-2026:4514
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:4517 https://access.redhat.com/errata/RHSA-2026:4517