Your message dated Mon, 03 Aug 2026 15:51:21 +0000
with message-id <[email protected]>
and subject line Bug#1143153: fixed in php8.4 8.4.24-1~deb13u1
has caused the Debian Bug report #1143153,
regarding php8.4: CVE-2026-7260 CVE-2026-17543 CVE-2026-17544
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143153: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143153
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: php8.4
Version: 8.4.23-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team
<[email protected]>, [email protected]
Hi Ondrej,
The following vulnerabilities were published for php8.4.
I guess they are important enough to make as well a DSA. There is as a
well a libgd2 update, but I have made a aseparate bug about it.
CVE-2026-7260[0]:
| Circular symbolic links in phar archives could lead to unbounded
| recursion, exhausting the C stack and crashing the PHP process, in
| PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33,
| from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
CVE-2026-17543[1]:
| Improper escaping of backslashes in attacker-provided parameters
| would allow for trivial SQL injection in PHP versions from 8.2.*
| before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24,
| and from 8.5.* before 8.5.9.
CVE-2026-17544[2]:
| Attacker-provided inputs to bccomp() could lead to an out-of-bounds
| write with stack and heap corruption in PHP versions from 8.4.*
| before 8.4.24 and from 8.5.* before 8.5.9.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-7260
https://www.cve.org/CVERecord?id=CVE-2026-7260
[1] https://security-tracker.debian.org/tracker/CVE-2026-17543
https://www.cve.org/CVERecord?id=CVE-2026-17543
[2] https://security-tracker.debian.org/tracker/CVE-2026-17544
https://www.cve.org/CVERecord?id=CVE-2026-17544
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: php8.4
Source-Version: 8.4.24-1~deb13u1
Done: Ondřej Surý <[email protected]>
We believe that the bug you reported is fixed in the latest version of
php8.4, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Ondřej Surý <[email protected]> (supplier of updated php8.4 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 31 Jul 2026 07:11:11 +0200
Source: php8.4
Architecture: source
Version: 8.4.24-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian PHP Maintainers <[email protected]>
Changed-By: Ondřej Surý <[email protected]>
Closes: 1143153
Changes:
php8.4 (8.4.24-1~deb13u1) trixie-security; urgency=high
.
* New upstream version 8.4.24 (Closes: #1143153)
+ [CVE-2026-17544]: Out-of-bounds write in bccomp()
+ [CVE-2026-17543]: SQL injection via E'...' backslash breakout
+ [CVE-2026-7260]: Crash via recursive symlinks
Checksums-Sha1:
41308a37c77ab36f46e38631dcd2f4260b14c3a2 5619 php8.4_8.4.24-1~deb13u1.dsc
487710711182ab94c04c15c8254efe2cc02f77e4 13752320 php8.4_8.4.24.orig.tar.xz
a6c16c9b3425efe80574cc0040b64f387bd9a1a9 265 php8.4_8.4.24.orig.tar.xz.asc
d37394a090133737f2218695fa9df97656fb2956 74756
php8.4_8.4.24-1~deb13u1.debian.tar.xz
b69b349d864f041a14fe4bf763fbe45b1e3ddcac 34422
php8.4_8.4.24-1~deb13u1_amd64.buildinfo
Checksums-Sha256:
fd84ce153abc1af23514100a25d04acd3c728f5c4b5c30c3e1a0788ef9c780eb 5619
php8.4_8.4.24-1~deb13u1.dsc
e127be09a8506f4327c5cfa78a614b00d210714484ec215ce0011b4a03c00731 13752320
php8.4_8.4.24.orig.tar.xz
16643bb748cb7e38f8496989cff457bc01bdd26806aa152b4da6d69fae31068f 265
php8.4_8.4.24.orig.tar.xz.asc
d638895a968c753cb01c28e45b1f21f03ef909f656870a1e52ff0a356d3239cb 74756
php8.4_8.4.24-1~deb13u1.debian.tar.xz
3334a40f265f77e1ef7d7b29de32118ea7e46b3813642e3c00f8917a0b8c6b1f 34422
php8.4_8.4.24-1~deb13u1_amd64.buildinfo
Files:
a12dbeeef697d8054cf2fcb4b51c8724 5619 php optional php8.4_8.4.24-1~deb13u1.dsc
13cb7ced4e0b2ecee75a4a99b262680f 13752320 php optional
php8.4_8.4.24.orig.tar.xz
b52cfc5578c949da87ff0d67e4c6e31a 265 php optional php8.4_8.4.24.orig.tar.xz.asc
5d5897023d1a5f36a87a7337bd8f76d5 74756 php optional
php8.4_8.4.24-1~deb13u1.debian.tar.xz
31a3bc96e4c4bc5963700443fa623cb5 34422 php optional
php8.4_8.4.24-1~deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEEw2Gx4wKVQ+vGJel9g3Kkd++uWcIFAmpsP/NfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEMz
NjFCMUUzMDI5NTQzRUJDNjI1RTk3RDgzNzJBNDc3RUZBRTU5QzIACgkQg3Kkd++u
WcJ7Qg//fsBRjf1jqHFvfc5SIpW0TW09vMl88vDIDA8swOMhjtal+5UQ3fqhzoGp
/j6/ULfP68fibvByA0x1e2XtGPboey0CYkZZWuS28lFp0wcWy3Fkd+wJNEakpD4a
4C1quyN+PKLq5E4n+IFZC/fzCg0VPfeoTFjCDFuDMReor+ui0FK2NyA28rk2XC9F
O4Hj83imj/ebfn+qdtzKirnlzb3UCHKR+ajyA8brHwbiKjeTi8IxSttAyE8NIMel
5RoU+7Xdj/acS/zN1ExaKoYckzqLNXp1UB5ZT1844tXoVbJqFem1HknnS4q+KJlH
mJZFZ0hPUxuGXEYu+3uBrJIpwSSkah/eFxtlOq2RqE8DiQKjTjdJJZhmGaubHeyb
IFpoZ7a2Hu2Vli6/6pTcksOoJRoa5H2ANxUc+t2l9wdlO3A1xUK7BoXUVowC3c8W
1r+U4TlXKvyhq3rpuSRX7aSPpSWQdmrDhTAgKo2JXUCw9w96r5Wz6HrbqZLhqIa4
nZ0ifBhGlUGoLmAZP82Ee7wdARf87vJP4+OGcbaTA1Rme1IZotzHTmJdrJrmiqJA
VmdHR6VCOpYIgV3QVlcevfxIWaYjSwkLR/2Zu2gnmunChzxXk1vYyh1iUA39nsxr
zrH7Dy1Q2+hsukjpp/jnq9u2Nnt7r+c0j33Tu1mBfh8KeqN/nME=
=2zOd
-----END PGP SIGNATURE-----
pgpkdCZLaUXDv.pgp
Description: PGP signature
--- End Message ---