{"id":"RHSA-2026:70720","summary":"Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update","modified":"2026-09-26T10:27:37.883275123Z","published":"2026-09-26T10:12:16Z","upstream":["CVE-2025-1218","CVE-2026-17545","CVE-2026-6103","CVE-2026-91765","CVE-2026-91766","CVE-2026-91767","CVE-2026-91768","CVE-2026-92842","CVE-2026-93682"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:70720"},{"type":"ARTICLE","url":"https://images.redhat.com/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-93682"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-6103"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-91765"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-17545"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-91768"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-92842"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-91766"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-1218"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-91767"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_70720.json"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2541655"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2025-1218"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1218"},{"type":"ARTICLE","url":"https://github.com/php/php-src/security/advisories/GHSA-r6x9-5r99-36j7"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2541638"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-6103"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6103"},{"type":"ARTICLE","url":"https://github.com/php/php-src/security/advisories/GHSA-j3wh-g957-2m85"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2541645"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-17545"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17545"},{"type":"ARTICLE","url":"https://github.com/php/php-src/security/advisories/GHSA-9f67-6fw4-hpfp"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2541646"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-91765"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91765"},{"type":"ARTICLE","url":"https://github.com/php/php-src/security/advisories/GHSA-rgrp-mwpx-f6rm"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2541649"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-91766"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91766"},{"type":"ARTICLE","url":"https://github.com/php/php-src/security/advisories/GHSA-fpwc-w8rq-cr92"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2541652"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-91767"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91767"},{"type":"ARTICLE","url":"https://github.com/php/php-src/security/advisories/GHSA-xr7j-rvgx-xq5p"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2541660"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-91768"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91768"},{"type":"ARTICLE","url":"https://github.com/php/php-src/security/advisories/GHSA-62xp-839h-2637"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2541662"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-92842"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92842"},{"type":"ARTICLE","url":"https://github.com/php/php-src/security/advisories/GHSA-88hq-2827-7pg6"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2541615"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-93682"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93682"},{"type":"ARTICLE","url":"https://github.com/php/php-src/security/advisories/GHSA-7875-c8px-7q5f"}],"affected":[{"package":{"name":"php","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-bcmath","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-bcmath"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-cli","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-cli"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-common","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-dba","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-dba"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-dbg","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-dbg"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-devel","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-embedded","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-embedded"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-enchant","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-enchant"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-ffi","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-ffi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-fpm","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-fpm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-gd","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-gd"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-gmp","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-gmp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-intl","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-intl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-ldap","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-ldap"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-mbstring","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-mbstring"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-mysqlnd","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-mysqlnd"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-odbc","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-odbc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-pdo","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-pdo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-pdo-dblib","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-pdo-dblib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-pdo-firebird","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-pdo-firebird"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-pgsql","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-pgsql"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-process","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-process"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-snmp","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-snmp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-soap","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-soap"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-sodium","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-sodium"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-tidy","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-tidy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}},{"package":{"name":"php-xml","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/php-xml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.5.11-2.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:70720.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}