[CLSA-2026:1786372275] Fix CVE(s): CVE-2026-17543, CVE-2026-7260, CVE-2026-9672
Type:
security
Severity:
Critical
Release date:
2026-08-10 14:31:29 UTC
Description:
* CVE-2026-9672: fix three defects in the bundled libgd GIF LZW decoder reachable from attacker-controlled GIF data via imagecreatefromgif(). The table reset cleared sd->table[1][0] instead of sd->table[1][i], so stale suffixes leaked between images; LWZReadByte_() kept decoding with a stale code after the LZW end code when the trailing data block count was 0; and ReadImage() left LZW_STATIC_DATA uninitialised. * CVE-2026-17543: fix SQL injection in ext/pgsql. php_pgsql_add_quotes() wrapped PQescapeStringConn() output in an E'...' literal, but PQescapeStringConn() only doubles the single quote while standard_conforming_strings is on, so a trailing backslash escaped the closing quote and broke out of the literal in pg_convert()/pg_insert()/pg_update()/pg_select()/pg_delete(). Emit a plain '...' literal instead. * CVE-2026-7260: fix unbounded recursion in phar_get_link_source() on a circular symlink chain (GHSA-vc5h-9ppw-p5f3). The self-recursion is replaced by a Floyd cycle-detection walk that returns NULL for a cycle, including the phar_get_link_location() path-separator restore the walk depends on.
Updated packages:
  • alt-php72_7.2.34-89_amd64.deb
    sha:03e81c9f376df7f97261e5e40aad13d9265a4d4b
  • alt-php72-bcmath_7.2.34-89_amd64.deb
    sha:f94262215b7877d5be34a2eca1326d126d341252
  • alt-php72-cli_7.2.34-89_amd64.deb
    sha:24aa7baf6fa42bc26d68de047374b2b62b3fdfad
  • alt-php72-common_7.2.34-89_amd64.deb
    sha:f89e4a9a37b65357d72b97cfd53b4963d558e525
  • alt-php72-dba_7.2.34-89_amd64.deb
    sha:6d56b3a350e15f17965f49b63c171a48024b70ed
  • alt-php72-dev_7.2.34-89_amd64.deb
    sha:fe214c11927d85772459e1a9222eb7a1c560d1cd
  • alt-php72-enchant_7.2.34-89_amd64.deb
    sha:b5afc823df3e22a114196abef46e538fba7139f9
  • alt-php72-firebird_7.2.34-89_amd64.deb
    sha:c9363be9ec0479f52d38c4e445238d36865a24e8
  • alt-php72-gd_7.2.34-89_amd64.deb
    sha:7437c50439c9822002c7260a464f304b7863c00e
  • alt-php72-imap_7.2.34-89_amd64.deb
    sha:0f68c54112c9d527bd74fc9b719b97b49c25a602
  • alt-php72-intl_7.2.34-89_amd64.deb
    sha:8b6e6b460646f8488a1702ad6e7e19d9a85cf3c0
  • alt-php72-ldap_7.2.34-89_amd64.deb
    sha:172585662e88b9875169ce18299262e47361f4c0
  • alt-php72-mbstring_7.2.34-89_amd64.deb
    sha:eb9e517e6c57445336a4983fa2973f59c92f02b2
  • alt-php72-mysqlnd_7.2.34-89_amd64.deb
    sha:c1e8bdbe6ed35572ef55e0df811c189c1a131067
  • alt-php72-odbc_7.2.34-89_amd64.deb
    sha:36ba6b4824744cfa89a9a8b3d3856059b72c864e
  • alt-php72-opcache_7.2.34-89_amd64.deb
    sha:8d402a5fdcd29a31a55c81a859f3e09ec0cac2e6
  • alt-php72-pdo_7.2.34-89_amd64.deb
    sha:c711184b20de25290c8477c509a3d4b397d74488
  • alt-php72-pgsql_7.2.34-89_amd64.deb
    sha:021e8912413240cee357f962c0cb0cb92317bb87
  • alt-php72-php-fpm_7.2.34-89_amd64.deb
    sha:c7eed31654df7ecfb5df2ae929fcdcbb949ae5e5
  • alt-php72-process_7.2.34-89_amd64.deb
    sha:c0f18347f668c957f51adeba389dbd28ddcc9ef7
  • alt-php72-pspell_7.2.34-89_amd64.deb
    sha:86948a13e14c6a2c4d987dcc205f321723f4d451
  • alt-php72-recode_7.2.34-89_amd64.deb
    sha:c6d5cac5f43e0a6fe2c969b0b49d43bedf74f4ee
  • alt-php72-snmp_7.2.34-89_amd64.deb
    sha:ae078b6638b8d35718006d8d65342f8daf08bef5
  • alt-php72-soap_7.2.34-89_amd64.deb
    sha:8d2a097d3a076ca2494bb9c5611c9c4e35a01ea0
  • alt-php72-sodium_7.2.34-89_amd64.deb
    sha:91c1495f7428346b6c4ee656f5c8376621e6525b
  • alt-php72-tidy_7.2.34-89_amd64.deb
    sha:c9936e7008982a88f23f0894787402cc24306819
  • alt-php72-xml_7.2.34-89_amd64.deb
    sha:08922f9e538d6cb00ab575d7bdc5614f9dc97a61
  • alt-php72-xmlrpc_7.2.34-89_amd64.deb
    sha:9f6f0ca1b6da2b66034f30733483bcf3770bb767
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.