Source: php8.4 Version: 8.4.23-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>, [email protected]
Hi Ondrej, The following vulnerabilities were published for php8.4. I guess they are important enough to make as well a DSA. There is as a well a libgd2 update, but I have made a aseparate bug about it. CVE-2026-7260[0]: | Circular symbolic links in phar archives could lead to unbounded | recursion, exhausting the C stack and crashing the PHP process, in | PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, | from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9. CVE-2026-17543[1]: | Improper escaping of backslashes in attacker-provided parameters | would allow for trivial SQL injection in PHP versions from 8.2.* | before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, | and from 8.5.* before 8.5.9. CVE-2026-17544[2]: | Attacker-provided inputs to bccomp() could lead to an out-of-bounds | write with stack and heap corruption in PHP versions from 8.4.* | before 8.4.24 and from 8.5.* before 8.5.9. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-7260 https://www.cve.org/CVERecord?id=CVE-2026-7260 [1] https://security-tracker.debian.org/tracker/CVE-2026-17543 https://www.cve.org/CVERecord?id=CVE-2026-17543 [2] https://security-tracker.debian.org/tracker/CVE-2026-17544 https://www.cve.org/CVERecord?id=CVE-2026-17544 Regards, Salvatore

