[CLSA-2026:1786360554] Fix CVE(s): CVE-2026-17543, CVE-2026-7260, CVE-2026-9672
Type:
security
Severity:
Critical
Release date:
2026-08-10 11:16:06 UTC
Description:
* SECURITY UPDATE: three defects in the bundled libgd GIF LZW decoder - debian/patches/php-7.1-CVE-2026-9672.patch: backport upstream commit fcd691b377 in ext/gd/libgd/gd_gif_in.c - reset sd->table[1][i] instead of sd->table[1][0] so the suffix table is fully cleared between images, stop decoding once the LZW end code is seen instead of falling through with a stale code, and zero-initialise LZW_STATIC_DATA in ReadImage(). - CVE-2026-9672 * SECURITY UPDATE: SQL injection in ext/pgsql via an E'...' backslash breakout - debian/patches/php-7.1-CVE-2026-17543.patch: backport upstream commit ab048bd83b in ext/pgsql/pgsql.c - php_pgsql_add_quotes() no longer emits the E prefix, since PQescapeStringConn() only doubles the single quote and a trailing backslash could therefore escape the closing quote of an E'...' literal. Test expectations updated accordingly and a regression test added. - CVE-2026-17543 * SECURITY UPDATE: phar crash on circular symlinks - debian/patches/php-7.1-CVE-2026-7260.patch: backport upstream commit 2e0fa0a444 in ext/phar/util.c - phar_get_link_source() follows the link chain with Floyd cycle detection via a new phar_follow_one_link() helper instead of recursing into itself until the C stack is exhausted, and phar_get_link_location() restores the path separator it temporarily overwrites in entry->filename. - CVE-2026-7260
Updated packages:
  • alt-php71_7.1.33-105_amd64.deb
    sha:68f5f3f809aa29e99d4086918b236722798744ce
  • alt-php71-bcmath_7.1.33-105_amd64.deb
    sha:28dc4469a3c9a0afb5d2931d5407e50ad212915e
  • alt-php71-cli_7.1.33-105_amd64.deb
    sha:41265e2ff335a1d0cfcf254036396b8c4fae8273
  • alt-php71-common_7.1.33-105_amd64.deb
    sha:bf80ca90adbb1d7bae8fc9a2066bba96d08bac99
  • alt-php71-dba_7.1.33-105_amd64.deb
    sha:6c55b5974eb5f7fa931757b523d6c907b3a6728f
  • alt-php71-dev_7.1.33-105_amd64.deb
    sha:0d47b166167b8a729db6ab43613e5a27932dc02a
  • alt-php71-enchant_7.1.33-105_amd64.deb
    sha:7784eff3c779c2be02dcafb5b9a0fd0972595ab0
  • alt-php71-firebird_7.1.33-105_amd64.deb
    sha:ea13aaf178d15640a8786e2804c49efde7cb2b4d
  • alt-php71-gd_7.1.33-105_amd64.deb
    sha:2ccc2976ae75f295a7d93c281e9bcf42f97da11f
  • alt-php71-imap_7.1.33-105_amd64.deb
    sha:6113a4974ae0e2ece51d16562af84975d260f016
  • alt-php71-intl_7.1.33-105_amd64.deb
    sha:538c0d701c183a28dd97f9535531de2c94319b4a
  • alt-php71-ldap_7.1.33-105_amd64.deb
    sha:886054296639a16855188b22c15c3df4eb8bf760
  • alt-php71-mbstring_7.1.33-105_amd64.deb
    sha:d3d9997b9cb2fe4a4cd445b027ead000e32dc058
  • alt-php71-mcrypt_7.1.33-105_amd64.deb
    sha:9e8bb2fdbcec369eb5134418c7ecc97d495789d4
  • alt-php71-mysqlnd_7.1.33-105_amd64.deb
    sha:5b421c23bdd0313be7103ac55806f876541022f4
  • alt-php71-odbc_7.1.33-105_amd64.deb
    sha:658b0d3a44f190f7620b603d4aa6b8eaf9199331
  • alt-php71-opcache_7.1.33-105_amd64.deb
    sha:1ad61e87d75fa8881378b2669920835e9a1ea26d
  • alt-php71-pdo_7.1.33-105_amd64.deb
    sha:5a8172bcf75f26d2e260ef98c5567a0e5dcc89e8
  • alt-php71-pgsql_7.1.33-105_amd64.deb
    sha:fd35fdf4c5cec9def975754a1e3775e1e1a3fd4d
  • alt-php71-php-fpm_7.1.33-105_amd64.deb
    sha:61af7b4f2b0de2db9dcb80714a377ba60d618b5c
  • alt-php71-process_7.1.33-105_amd64.deb
    sha:3ad7d60e84de2916d1261ed96a38c726b236bfd3
  • alt-php71-pspell_7.1.33-105_amd64.deb
    sha:28b5e832ed7713216a4d351c63e71ca60dbd93a3
  • alt-php71-recode_7.1.33-105_amd64.deb
    sha:3ed6deacd195cbbc2e2d7db5ff5a14dc0ba3aee0
  • alt-php71-snmp_7.1.33-105_amd64.deb
    sha:4fe2238079eaf60910321749113435d1da2610c8
  • alt-php71-soap_7.1.33-105_amd64.deb
    sha:f1b1f2ed4e9f739b68b48dc2ce862d8c430880e6
  • alt-php71-tidy_7.1.33-105_amd64.deb
    sha:80a962dd5ac16e1a8377bc22468e63ce9086f763
  • alt-php71-xml_7.1.33-105_amd64.deb
    sha:b46a4199243b9eb4e5a00df92fc966dba11ba3de
  • alt-php71-xmlrpc_7.1.33-105_amd64.deb
    sha:5860c5e368e00e9f506da16ad48124e72f2d90ba
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.