Critical SQL Injection Vulnerabilities in Rocky Linux PHP Modules

Critical SQL Injection Vulnerabilities in Rocky Linux PHP Modules

First seen 2 Sep 2026, 13:13 UTC Linuxsecurity 66.0

Article Content

Browse articles
ThreatCluster

Rocky Linux has released advisories for critical SQL injection vulnerabilities affecting PHP modules in both Rocky Linux 8 and 9. The vulnerabilities allow for Denial of Service (DoS) attacks through SQL injection methods. The affected components include php, module.php-pecl-rrd, module.php-pecl-apcu, and others. The updates are crucial for maintaining system security and mitigating potential exploits. The Common Vulnerability Scoring System (CVSS) scores for these vulnerabilities indicate a high severity level, emphasizing the urgency of applying the patches. Users of Rocky Linux 8 and 9 are advised to update their systems immediately. Specific RPM packages affected include various versions of php and libzip. The advisories are available for review on Linuxsecurity.com.

Key Points: • Critical SQL injection vulnerabilities found in Rocky Linux PHP modules. • Affected systems include Rocky Linux 8 and 9 with specific RPM packages. • Immediate patching is recommended to prevent potential DoS attacks.

Timeline

2026-09-02
Advisory released for Rocky Linux 9
Rocky Linux issued an advisory for critical SQL injection vulnerabilities affecting PHP modules in version 9.
Linuxsecurity
2026-09-02
Advisory released for Rocky Linux 8
An advisory was also issued for Rocky Linux 8, detailing similar vulnerabilities in PHP modules.
Linuxsecurity