Source: php8.4
Version: 8.4.23-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team 
<[email protected]>, [email protected]

Hi Ondrej,

The following vulnerabilities were published for php8.4.

I guess they are important enough to make as well a DSA. There is as a
well a libgd2 update, but I have made a aseparate bug about it.

CVE-2026-7260[0]:
| Circular symbolic links in phar archives could lead to unbounded
| recursion, exhausting the C stack and crashing the PHP process, in
| PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33,
| from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.


CVE-2026-17543[1]:
| Improper escaping of backslashes in attacker-provided parameters
| would allow for trivial SQL injection in PHP versions from 8.2.*
| before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24,
| and from 8.5.* before 8.5.9.


CVE-2026-17544[2]:
| Attacker-provided inputs to bccomp() could lead to an out-of-bounds
| write with stack and heap corruption in PHP versions from 8.4.*
| before 8.4.24 and from 8.5.* before 8.5.9.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-7260
    https://www.cve.org/CVERecord?id=CVE-2026-7260
[1] https://security-tracker.debian.org/tracker/CVE-2026-17543
    https://www.cve.org/CVERecord?id=CVE-2026-17543
[2] https://security-tracker.debian.org/tracker/CVE-2026-17544
    https://www.cve.org/CVERecord?id=CVE-2026-17544

Regards,
Salvatore

Reply via email to