CODERED VTA

SUSE Ships PHP8 Update Fixing Ten Flaws Across Enterprise Linux and SAP Servers

High
Computer motherboard close-up
Photo by George Prentzas on Unsplash

SUSE has published security advisory SUSE-SU-2026:4603-1, rated important and released on 9 October 2026, which resolves ten separate vulnerabilities in the php8 package. The update moves the affected platforms to php8 version 8.2.34, with the binary packages carrying the build string 8.2.34-150600.3.36.1. Affected products are openSUSE Leap 15.6, SUSE Linux Enterprise Server 15 SP6, SUSE Linux Enterprise Server 15 SP6 LTSS, and SUSE Linux Enterprise Server for SAP Applications 15 SP6. The ten issues are tracked as CVE-2025-1218, CVE-2025-14181, CVE-2026-6103, CVE-2026-91765 through CVE-2026-91769, CVE-2026-92842 and CVE-2026-93682. The highest SUSE-assigned score in the set is 8.7 under CVSS v4.0 for CVE-2026-91765, an availability-only denial of service, followed by 8.3 for CVE-2025-14181 and 8.2 for CVE-2026-91766.

The advisory describes each flaw by component rather than publishing exploitation details or proof-of-concept code. Three of the issues are memory-safety problems reachable through parsing untrusted input: CVE-2025-1218 is an out-of-bounds read in the mysqlnd wire protocol parser that can crash the interpreter, CVE-2026-92842 is an out-of-bounds read in stream filters leading to information disclosure, and CVE-2026-93682 is an out-of-bounds read triggered by an empty HTTP redirect Location header. The SOAP extension carries two defects, an integer overflow that becomes a buffer overflow during SOAP HTTP parsing in CVE-2025-14181, and unbounded recursion in the SOAP parser that exhausts resources in CVE-2026-91765. CVE-2026-6103 is an archive entry injection caused by an integer overflow in the TAR parser. The remaining four are transport and trust failures: credentials leaking across cross-origin HTTP redirects in CVE-2026-91766, information disclosure through a crafted TLS server certificate in CVE-2026-91767, an access control bypass caused by comparing only part of an IPv6 address in CVE-2026-91768, and OpenSSL stream peer verification falling back to the certificate Common Name whenever no subjectAltName matches in CVE-2026-91769, which permits a trusted certificate to be impersonated. Several of the CVSS vectors are adjacent-network rather than fully remote, including CVE-2025-1218, CVE-2026-91767 and CVE-2026-91768, which narrows the position an attacker needs to hold.

PHP sits directly in the request path on most of the web estate these platforms serve, and on SUSE Linux Enterprise Server for SAP Applications the same interpreter runs alongside business-critical workloads where an interpreter crash has operational weight well beyond a single page error. The trust-boundary failures are the more consequential half of this set, because the OpenSSL Common Name fallback and the partial IPv6 address comparison both weaken checks that application code assumes are already correct, meaning a developer following documented practice would still be exposed. Credential disclosure across cross-origin redirects is similarly silent, since the application sees a successful HTTP transaction while the authorisation header travels to a host that was never intended to receive it. On current evidence, exploitation is not being observed. None of the ten CVEs appear in the CISA Known Exploited Vulnerabilities catalog, and FIRST EPSS places all of them under one percent probability of exploitation in the next thirty days, with CVE-2026-91768 highest at 0.6 percent, CVE-2026-91765 at 0.5 percent, CVE-2026-92842 and CVE-2026-93682 at 0.4 percent, CVE-2025-14181 and CVE-2026-91766 at 0.3 percent, CVE-2025-1218, CVE-2026-6103 and CVE-2026-91767 at 0.2 percent, and CVE-2026-91769 lowest at 0.1 percent. The practical exposure is therefore a window of unpatched interpreters on internet-facing hosts rather than an incident in progress, and the risk concentrates on systems where the soap, mysql, openssl, phar and curl extensions are installed and processing data from outside the trust boundary.

Attack Surface

Web Application, Server OS, Infrastructure

Tactics

Initial Access, Credential Access, Defense Evasion, Impact

Techniques

  • T1190 – Exploit Public-Facing Application
  • T1557 – Adversary-in-the-Middle
  • T1499 – Endpoint Denial of Service
  • T1499.004 – Application or System Exploitation
  • T1552 – Unsecured Credentials

SuperPRO's Threat Countermeasures Procedures

  1. Install the php8 update that brings all packages to version 8.2.34-150600.3.36.1 on openSUSE Leap 15.6, SUSE Linux Enterprise Server 15 SP6, SLES 15 SP6 LTSS and SLES for SAP Applications 15 SP6, using 'zypper patch' or YaST online_update.
  2. Apply the product-specific patch command from advisory SUSE-SU-2026:4603-1: 'zypper in -t patch SUSE-2026-4603' on openSUSE Leap 15.6, 'zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4603' on SLES 15 SP6 LTSS, and 'zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4603' on SLES for SAP Applications 15 SP6.
  3. Inventory hosts with 'rpm -qa | grep php8' and prioritise any system where php8-soap is present, since CVE-2025-14181 (integer overflow to buffer overflow in SOAP HTTP parsing) and CVE-2026-91765 (unbounded recursion in the SOAP parser, SUSE CVSS 8.7) both require that extension; restart apache2-mod_php8 and php8-fpm after the update so the new code is loaded.
  4. Audit PHP code that opens TLS streams through php8-openssl and confirm stream context options verify_peer and verify_peer_name are set to true with an explicit peer_name, because CVE-2026-91769 allows peer verification to fall back to the certificate Common Name when no subjectAltName matches, and CVE-2026-91767 permits information disclosure through a crafted server certificate.
  5. Review application code that follows HTTP redirects — file_get_contents and fopen with the http wrapper, and curl handles with CURLOPT_FOLLOWLOCATION enabled — and disable automatic redirect following where it is not required, as CVE-2026-91766 leaks credentials across cross-origin redirects and CVE-2026-93682 causes an out-of-bounds read on an empty Location header.
  6. Restrict php8-mysql and mysqlnd connections to known database hosts using firewall rules on TCP/3306, since CVE-2025-1218 is an out-of-bounds read in the mysqlnd wire protocol parser exploitable from an adjacent-network position by a malicious or hijacked MySQL endpoint.
  7. Stop processing untrusted TAR archives through php8-phar and PharData until the updated packages are deployed, and review any IP allow-list logic that compares IPv6 addresses in PHP, because CVE-2026-6103 permits archive entry injection via a TAR parser integer overflow and CVE-2026-91768 allows access control bypass through partial IPv6 address comparison.

Source

Code Red Cyber / VTA – coderedcyber.ai