Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
PHP 8.5.9 already in F44 stable
FEDORA-2026-d755ca77c4 (php-8.4.24-1.fc43) has been submitted as an update to Fedora 43. https://bodhi.fedoraproject.org/updates/FEDORA-2026-d755ca77c4
FEDORA-2026-d755ca77c4 (php-8.4.24-1.fc43) has been pushed to the Fedora 43 stable repository. If problem still persists, please make note of it in this bug report.