[CLSA-2026:1786395843] alt-php73: Fix of 3 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-10 21:04:16 UTC
Description:
- CVE-2026-9672: bundled libgd GIF LZW decoder read an uninitialised code table (sd->table[1][0] instead of sd->table[1][i] in the reset loop, plus an uninitialised LZW_STATIC_DATA on the stack) and kept decoding past an end-of-stream code - CVE-2026-17543: pg_insert()/pg_update()/pg_select()/pg_delete() emitted values escaped by PQescapeStringConn() inside an E'...' constant, so a trailing backslash broke out of the literal (SQL injection); emit a plain '...' constant instead - CVE-2026-7260: phar_get_link_source() followed tar symlink chains by unbounded recursion, so a phar with circular symlinks exhausted the C stack; walk the chain iteratively with Floyd cycle detection
Updated packages:
  • alt-php73-7.3.33-72.el7.x86_64.rpm
    sha:e8852534793ced9f54c1032fe087a44ffd51cc735bf4772778f4d5147f58e074
  • alt-php73-bcmath-7.3.33-72.el7.x86_64.rpm
    sha:d8d6ea24c97479e311071064f921a633b083f38a031bf39d672c46b19ce1324c
  • alt-php73-cli-7.3.33-72.el7.x86_64.rpm
    sha:c3170a2538e8bd38d8be93258c6379867ec058c373c451849aea25ced3e748ae
  • alt-php73-common-7.3.33-72.el7.x86_64.rpm
    sha:390f1c18b502c42ec52f73b8a3a95192ff0cde1f8eaafbade9814c055e35502d
  • alt-php73-dba-7.3.33-72.el7.x86_64.rpm
    sha:f4e2643e6668c3a850a39b1f18a20204d76d12d4f8a72be75ea981ce73765da6
  • alt-php73-devel-7.3.33-72.el7.x86_64.rpm
    sha:073dfec8b8a6b9a1e661f784e3a4ce1d824a71182eb152cb76bfc0648cd6e3c8
  • alt-php73-enchant-7.3.33-72.el7.x86_64.rpm
    sha:100c6ddfaafe107fc675f57f9fe4bf836cae37c6bd554da49eba39c99f25c61d
  • alt-php73-firebird-7.3.33-72.el7.x86_64.rpm
    sha:ee39471a6e8a7f42d85ff8be8979b4788751ca6cfd2ac302f6d671bd2bfd2f5b
  • alt-php73-gd-7.3.33-72.el7.x86_64.rpm
    sha:b4b158d8824bc7bdfcc1da5737bac139211bbae0f4496761f076dfcf5fd957a5
  • alt-php73-imap-7.3.33-72.el7.x86_64.rpm
    sha:0a65862989a6c230a2199175fe5dc724073d8ade3a45849cd12625e70b174a11
  • alt-php73-intl-7.3.33-72.el7.x86_64.rpm
    sha:9d87ac135586f8a50098104868114d56da5dcb9ccbd0d08335b232c7efb63298
  • alt-php73-ldap-7.3.33-72.el7.x86_64.rpm
    sha:0d7421b4d6c29a35d7349e96373132b33eab49902556d59167f63a1ef6287b83
  • alt-php73-mbstring-7.3.33-72.el7.x86_64.rpm
    sha:dd04ec4d129f8d1ad8c20d41678e878f604efdd6010a91f9ab894ed0f247fd09
  • alt-php73-mysqlnd-7.3.33-72.el7.x86_64.rpm
    sha:44842dbce3ebeef68fc568430c55c62ad81e9baa2d0a78a149f74814b7bd9d6e
  • alt-php73-odbc-7.3.33-72.el7.x86_64.rpm
    sha:105455e89aa795ead250e918f3320d87898127d3b5df43672c0fa4a7b265af1f
  • alt-php73-opcache-7.3.33-72.el7.x86_64.rpm
    sha:7287a32430cec998df4a2c4f9f8ad260cdd3eee24ae324441c157eab51ea3280
  • alt-php73-pdo-7.3.33-72.el7.x86_64.rpm
    sha:7974ff6ac2c13d3e5c9593ceb57ccf4b8bfb39018cab715b2d50a442ec93cd3b
  • alt-php73-pgsql-7.3.33-72.el7.x86_64.rpm
    sha:fcd56a6a63df95a6f3276eb3071cedfc2ee1e78ccc193207b665711c2d2c1476
  • alt-php73-php-fpm-7.3.33-72.el7.x86_64.rpm
    sha:078f1114fa071677003877759d58a8f032c8efafdf684e31d020d11211696c8e
  • alt-php73-process-7.3.33-72.el7.x86_64.rpm
    sha:1be024ec4e2f90d3df6be43ef2582fad6a02721cb4f31ff8f3b43aceb0bb5d0e
  • alt-php73-pspell-7.3.33-72.el7.x86_64.rpm
    sha:e99fb9d871a9953767aaa74a4321bf41ce6fb9709a43360bbe34163b8754937a
  • alt-php73-recode-7.3.33-72.el7.x86_64.rpm
    sha:cfe49aa29ee3a580a39db38ccaf914b4890ba5c2e5d7369b941ac1e4a771f1d2
  • alt-php73-snmp-7.3.33-72.el7.x86_64.rpm
    sha:8869e74fe7bbb4739d9ab2b886a23bdb55847dc52bdccaa1b063e8f08ad50d17
  • alt-php73-soap-7.3.33-72.el7.x86_64.rpm
    sha:bd36504b2a20955a68bfd630c57a6eb297cf142570f98ebcfbb423d4c7e84879
  • alt-php73-sodium-7.3.33-72.el7.x86_64.rpm
    sha:0b2131967580f3cc6e42d392463da09c6ea2e693830d27c2659ea675d23f01ed
  • alt-php73-tidy-7.3.33-72.el7.x86_64.rpm
    sha:3ba9242fe74f8f33d763b6c6eb7a6a436e7c7413670cfdebf72f1e463b13470c
  • alt-php73-xml-7.3.33-72.el7.x86_64.rpm
    sha:2c8f4a2962c46c51f7da829f336b12183ae91d2ffd518a857f85e95615f0337e
  • alt-php73-xmlrpc-7.3.33-72.el7.x86_64.rpm
    sha:b3eeeb4cd8d59e5d9bdbd8602db8bbf0a5a012a14fa509047d4b4a219dafdff2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.