In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??= operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout leading to this, for example by supplying specially crafted inputs to the script, it could lead to remote code execution.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7418 https://access.redhat.com/errata/RHSA-2025:7418
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7489 https://access.redhat.com/errata/RHSA-2025:7489