[CLSA-2026:1786519532] Fix CVE(s): CVE-2026-17543, CVE-2026-7260, CVE-2026-9672
Type:
security
Severity:
Critical
Release date:
2026-08-12 07:25:45 UTC
Description:
* CVE-2026-9672: three defects in the GIF LZW decoder of the bundled libgd - the code-table reset loop wrote sd->table[1][0] instead of sd->table[1][i] so most of table[1] kept stale data, LWZReadByte_() kept decoding past the end-of-information code when the trailing data blocks drained cleanly, and ReadImage() left its LZW_STATIC_DATA uninitialised on the stack * CVE-2026-17543: SQL injection in ext/pgsql - php_pgsql_add_quotes() wrapped values in an E'...' literal, in which the backslash left unescaped by PQescapeStringConn() (the default standard_conforming_strings=on doubles only the quote) escapes the following quote and lets a payload break out; pg_convert(), pg_insert(), pg_update(), pg_delete() and pg_select() are affected. Now quoted with a plain '...' literal * CVE-2026-7260: unbounded recursion in phar_get_link_source() when a tar-based phar archive contains a circular symlink chain; resolution is now an iterative walk with Floyd cycle detection, returning NULL on a cycle
Updated packages:
  • alt-php70_7.0.33-140_amd64.deb
    sha:29c5f8491766e17abc909353797eaeda23e34f1d
  • alt-php70-bcmath_7.0.33-140_amd64.deb
    sha:cc869c64bf0534cb6d5c664e98f18002eedc39a9
  • alt-php70-cli_7.0.33-140_amd64.deb
    sha:5baaac20bfaa0f24d25cb2aba077258c9c9768ad
  • alt-php70-common_7.0.33-140_amd64.deb
    sha:5bbf6115b45113407f64c24a785ae0eb3a8c0751
  • alt-php70-dba_7.0.33-140_amd64.deb
    sha:018d03d9832c19eea18b51f4676f6be0aa655219
  • alt-php70-dev_7.0.33-140_amd64.deb
    sha:8f5abbc6a5ae363111c01a080173aeb91f197447
  • alt-php70-enchant_7.0.33-140_amd64.deb
    sha:8135190c395c673db5dba76b23b4f12a7f59d433
  • alt-php70-firebird_7.0.33-140_amd64.deb
    sha:64f29f69f1502c2eccf174b7d1d385a2532d0eeb
  • alt-php70-gd_7.0.33-140_amd64.deb
    sha:7393c3fd4c3c4eb85f1220c51af45e463aaef617
  • alt-php70-imap_7.0.33-140_amd64.deb
    sha:b07dc1338ae38e4a250bce145e113a05d6466699
  • alt-php70-intl_7.0.33-140_amd64.deb
    sha:e0004700feb4d749b46cfee8cce547d1e691612e
  • alt-php70-ldap_7.0.33-140_amd64.deb
    sha:2a9892700439c23124952e5a2ce4ef757a88dde1
  • alt-php70-mbstring_7.0.33-140_amd64.deb
    sha:97e5b0b091348c88fe445645531cf66ed2aeeaa9
  • alt-php70-mcrypt_7.0.33-140_amd64.deb
    sha:dbf6ce6e331974950aee8b30c683fba07d67824d
  • alt-php70-mysqlnd_7.0.33-140_amd64.deb
    sha:a850c1688cf972f0e6044d3a51dc1864c9f9058b
  • alt-php70-odbc_7.0.33-140_amd64.deb
    sha:2a31b0fe8e23c1fc92de222d0bd041ed8c1b37c2
  • alt-php70-opcache_7.0.33-140_amd64.deb
    sha:9da142e8a1e19e5e48f8c17c4e2648a1ca38d763
  • alt-php70-pdo_7.0.33-140_amd64.deb
    sha:7d90fa76844fee365fba13fe1686fca3b3af956f
  • alt-php70-pgsql_7.0.33-140_amd64.deb
    sha:21e58bf6a4ada4b58f79f4c22282e09bbcff3c4a
  • alt-php70-php-fpm_7.0.33-140_amd64.deb
    sha:0488d873426772b6c1ce36063a6c4a29a544943f
  • alt-php70-process_7.0.33-140_amd64.deb
    sha:e64ce86ccbc9cd6446ef18bbf692e28631167ae3
  • alt-php70-pspell_7.0.33-140_amd64.deb
    sha:1c474692884d0957f92a15a3ee0f4271fdcd60b4
  • alt-php70-recode_7.0.33-140_amd64.deb
    sha:43bb1e5c4ea4cceb45f491b937dc21154fc7f17f
  • alt-php70-snmp_7.0.33-140_amd64.deb
    sha:8957247aa5efb48f959576a0dec3d7f9a6af28d8
  • alt-php70-soap_7.0.33-140_amd64.deb
    sha:72b9f29d3a61c398a5ac262fc4198eb29408fdd2
  • alt-php70-tidy_7.0.33-140_amd64.deb
    sha:bf5a37d18ea11f3edec9d0219450a0ed331742ed
  • alt-php70-xml_7.0.33-140_amd64.deb
    sha:011a7067a2176d7c0977bec3f8bc2406af1e69dc
  • alt-php70-xmlrpc_7.0.33-140_amd64.deb
    sha:852b2334ea4a9480de63348429f60836eb5b5fdd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.