elsa-2026-33449
oracle_linux
Description
[8.0.30-6] - Fix XSS within status endpoint CVE-2026-6735 - Fix Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() CVE-2026-7259 - Fix Stale SOAP_GLOBAL(ref_map) pointer with Apache Map CVE-2026-6722 - Fix Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION CVE-2026-7261 - Fix Broken Apache map value NULL check CVE-2026-7262 - Fix Signed integer overflow of char array offset CVE-2026-7568 - Fix Consistently pass unsigned char to ctype.h functions CVE-2026-7258
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cves": [
"CVE-2026-6722",
"CVE-2026-6735",
"CVE-2026-7258",
"CVE-2026-7259",
"CVE-2026-7261",
"CVE-2026-7262",
"CVE-2026-7568"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[8.0.30-6]\n- Fix XSS within status endpoint\n CVE-2026-6735\n- Fix Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()\n CVE-2026-7259\n- Fix Stale SOAP_GLOBAL(ref_map) pointer with Apache Map\n CVE-2026-6722\n- Fix Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION\n CVE-2026-7261\n- Fix Broken Apache map value NULL check\n CVE-2026-7262\n- Fix Signed integer overflow of char array offset\n CVE-2026-7568\n- Fix Consistently pass unsigned char to ctype.h functions\n CVE-2026-7258",
"id": "ELSA-2026-33449",
"ovalId": "oval:com.oracle.elsa:def:202633449",
"source": "oracle_linux",
"title": "ELSA-2026-33449: php security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-33449.html"
}