Fedora Account System
Red Hat Associate
Red Hat Customer
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
Notice: Versions < 8.4 are not affected
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:56969 https://access.redhat.com/errata/RHSA-2026:56969