vulnerability
Rocky Linux: CVE-2025-1220: php-7.4 (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:M/Au:N/C:P/I:N/A:N) | Jan 28, 2026 | Jan 29, 2026 | Feb 13, 2026 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
Jan 28, 2026
Added
Jan 29, 2026
Modified
Feb 13, 2026
Description
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.
Solutions
rocky-upgrade-libziprocky-upgrade-libzip-debuginforocky-upgrade-libzip-debugsourcerocky-upgrade-libzip-develrocky-upgrade-libzip-toolsrocky-upgrade-libzip-tools-debuginforocky-upgrade-phprocky-upgrade-php-bcmathrocky-upgrade-php-bcmath-debuginforocky-upgrade-php-clirocky-upgrade-php-cli-debuginforocky-upgrade-php-commonrocky-upgrade-php-common-debuginforocky-upgrade-php-dbarocky-upgrade-php-dba-debuginforocky-upgrade-php-dbgrocky-upgrade-php-dbg-debuginforocky-upgrade-php-debuginforocky-upgrade-php-debugsourcerocky-upgrade-php-develrocky-upgrade-php-embeddedrocky-upgrade-php-embedded-debuginforocky-upgrade-php-enchantrocky-upgrade-php-enchant-debuginforocky-upgrade-php-ffirocky-upgrade-php-ffi-debuginforocky-upgrade-php-fpmrocky-upgrade-php-fpm-debuginforocky-upgrade-php-gdrocky-upgrade-php-gd-debuginforocky-upgrade-php-gmprocky-upgrade-php-gmp-debuginforocky-upgrade-php-intlrocky-upgrade-php-intl-debuginforocky-upgrade-php-jsonrocky-upgrade-php-json-debuginforocky-upgrade-php-ldaprocky-upgrade-php-ldap-debuginforocky-upgrade-php-mbstringrocky-upgrade-php-mbstring-debuginforocky-upgrade-php-mysqlndrocky-upgrade-php-mysqlnd-debuginforocky-upgrade-php-odbcrocky-upgrade-php-odbc-debuginforocky-upgrade-php-opcacherocky-upgrade-php-opcache-debuginforocky-upgrade-php-pdorocky-upgrade-php-pdo-debuginforocky-upgrade-php-pecl-apcurocky-upgrade-php-pecl-apcu-debuginforocky-upgrade-php-pecl-apcu-debugsourcerocky-upgrade-php-pecl-apcu-develrocky-upgrade-php-pecl-redis6rocky-upgrade-php-pecl-redis6-debuginforocky-upgrade-php-pecl-redis6-debugsourcerocky-upgrade-php-pecl-rrdrocky-upgrade-php-pecl-rrd-debuginforocky-upgrade-php-pecl-rrd-debugsourcerocky-upgrade-php-pecl-xdebugrocky-upgrade-php-pecl-xdebug-debuginforocky-upgrade-php-pecl-xdebug-debugsourcerocky-upgrade-php-pecl-xdebug3rocky-upgrade-php-pecl-xdebug3-debuginforocky-upgrade-php-pecl-xdebug3-debugsourcerocky-upgrade-php-pecl-ziprocky-upgrade-php-pecl-zip-debuginforocky-upgrade-php-pecl-zip-debugsourcerocky-upgrade-php-pgsqlrocky-upgrade-php-pgsql-debuginforocky-upgrade-php-processrocky-upgrade-php-process-debuginforocky-upgrade-php-snmprocky-upgrade-php-snmp-debuginforocky-upgrade-php-soaprocky-upgrade-php-soap-debuginforocky-upgrade-php-xmlrocky-upgrade-php-xml-debuginforocky-upgrade-php-xmlrpcrocky-upgrade-php-xmlrpc-debuginfo
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.