[CLSA-2026:1786354449] alt-php81: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-10 09:34:26 UTC
Description:
- CVE-2026-17543: SQL injection in ext/pgsql. php_pgsql_add_quotes() wrapped values escaped by PQescapeStringConn() in an E'...' escape-string constant, but that escaper leaves backslashes untouched when standard_conforming_strings is on, so a trailing backslash escaped the doubling quote and broke out of the literal. Drop the E prefix so the plain '...' form matches what the escaper produces. - CVE-2026-7260: phar circular symlink crash. phar_get_link_source() followed symlink chains by tail recursion with no cycle or depth guard, so a tar phar holding circular links exhausted the C stack. Walk the chain iteratively with Floyd cycle detection and return NULL on a loop; also restore the '/' separator in phar_get_link_location() so the walk stays idempotent.
Updated packages:
  • alt-php81-8.1.34-27.el9.x86_64.rpm
    sha:b0e21e641fa4ce78e3298b3adf8d41311668af402a18caf4f0f6762bca0201b6
  • alt-php81-bcmath-8.1.34-27.el9.x86_64.rpm
    sha:7b9ac51ffb8b3c6a414930c6ee9567fd7b8cc15cefadb0aac344fc2bd44dc0c1
  • alt-php81-cli-8.1.34-27.el9.x86_64.rpm
    sha:960cbd1ec07c99d7350ac81a5a8b68751eaca9471cfc83d17814049875491039
  • alt-php81-common-8.1.34-27.el9.x86_64.rpm
    sha:a7a370080149f28194902bb21340f8ea2a4ede1bc385e9404a59db0548d4f53d
  • alt-php81-dba-8.1.34-27.el9.x86_64.rpm
    sha:663a98286a29b6f287431850d6684d6f98cf5a6ff2b4d928901593502b731bf6
  • alt-php81-devel-8.1.34-27.el9.x86_64.rpm
    sha:8e72bf4f80d66d2bf7cc42dc3143f25199a52ea1b2f6304811cd42d13b002d5a
  • alt-php81-enchant-8.1.34-27.el9.x86_64.rpm
    sha:a19d6b0d36cddf05e08e581f81b25a4555ce28d32ac6d9f94568900d4a72afa5
  • alt-php81-firebird-8.1.34-27.el9.x86_64.rpm
    sha:652a783de90a811b5962b78c1ce776e5a672abc123fd5267c3cd84cfcbdf4f0a
  • alt-php81-gd-8.1.34-27.el9.x86_64.rpm
    sha:4965b2250837baf74b865bf7f09f6819c51329e7c31c1219dc0ff9d3a9f57152
  • alt-php81-gmp-8.1.34-27.el9.x86_64.rpm
    sha:116f42146bf8905450694f3dcf9f9f1ac306a645e922d05d1064ab78c3b8f2c7
  • alt-php81-imap-8.1.34-27.el9.x86_64.rpm
    sha:049a6983b63249d2f1fc73debc077cc0810bc7c0d5747e0bf89d8d6149461e87
  • alt-php81-intl-8.1.34-27.el9.x86_64.rpm
    sha:d5bda4e2b9569852a356c2e870d113b402dba9d8271da0558ef8289c0235c390
  • alt-php81-ldap-8.1.34-27.el9.x86_64.rpm
    sha:895488718bf3ddd379ba3eb4263e7891790dfb036676f276e4929927510fce0c
  • alt-php81-mbstring-8.1.34-27.el9.x86_64.rpm
    sha:e157a6d61359853f029103ce16b7d1073479fdb6e1729d7c91ae9a97637837f3
  • alt-php81-mysqlnd-8.1.34-27.el9.x86_64.rpm
    sha:0595e9c43331e75d43debc9dd78aa6fdb51f531beb429397eeb84912d47f706a
  • alt-php81-odbc-8.1.34-27.el9.x86_64.rpm
    sha:6c0b129c558a70c1b79c16f95cc7808ce02baca03620fc8657fc6e91029420c0
  • alt-php81-opcache-8.1.34-27.el9.x86_64.rpm
    sha:779a7f6b04cc41558155bd3a124a3d08acafc706d769b8ae9eaa42ee2ed712b9
  • alt-php81-pdo-8.1.34-27.el9.x86_64.rpm
    sha:e9fbddc3a4e16e7033e8f322d360ebbec29c8a1672a9c36cf60fd950171b27b3
  • alt-php81-pgsql-8.1.34-27.el9.x86_64.rpm
    sha:94e544828dd28b667f31e2a376377e2dd95c820b98806eed0ed97fbdfd0a23a8
  • alt-php81-php-fpm-8.1.34-27.el9.x86_64.rpm
    sha:5f7660b8e0dd2c77ade2553526db73a985f36cf4a673c012c37222c906d74ea8
  • alt-php81-process-8.1.34-27.el9.x86_64.rpm
    sha:1404d6df444f5d6221cc5dc74130b6afdaba1883c1da5fa57a2ab8cbff15c8e2
  • alt-php81-pspell-8.1.34-27.el9.x86_64.rpm
    sha:4973b4eca4f10971246d9e1f1054c7f94d50726c0489bcc3896a3ac848854533
  • alt-php81-snmp-8.1.34-27.el9.x86_64.rpm
    sha:b8b97f593f05f7002daebf05065073bd0e2b65ba794a0eccbe4df34661f20659
  • alt-php81-soap-8.1.34-27.el9.x86_64.rpm
    sha:269c3f694fc079f4b8bbdad5b9926244aeb5a4a40e4edea4a0807550e9b814c9
  • alt-php81-sodium-8.1.34-27.el9.x86_64.rpm
    sha:0b7b3c7bdde9c68f41ba50714f9abc9dfd273d2d897cd56b82d2e45968ceebe2
  • alt-php81-tidy-8.1.34-27.el9.x86_64.rpm
    sha:e0d9079ff856c3cdedb3b22082d65b74d2666cdbcaf04f498ba257a58d7472ad
  • alt-php81-xml-8.1.34-27.el9.x86_64.rpm
    sha:0190953519e514fd436145a304084f2d0e1573327a9329a78e51c17b19f2869c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.