[CLSA-2026:1786521105] alt-php74: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-12 07:51:58 UTC
Description:
- CVE-2026-17543: pg_insert()/pg_update()/pg_select()/pg_delete() emitted values escaped by PQescapeStringConn() inside an E'...' constant, so a trailing backslash broke out of the literal (SQL injection); emit a plain '...' constant instead - CVE-2026-7260: phar_get_link_source() followed tar symlink chains by unbounded recursion, so a phar with circular symlinks exhausted the C stack; walk the chain iteratively with Floyd cycle detection
Updated packages:
  • alt-php74-7.4.33-68.el9.x86_64.rpm
    sha:d40301cdda5a3d4094aef3e1543083a2fb1281324bfd9f869496a3e2a52ac425
  • alt-php74-bcmath-7.4.33-68.el9.x86_64.rpm
    sha:299dcd9ee296ffb2d302c0f7d9305d5489bbfca37f314c713863de21a681a403
  • alt-php74-cli-7.4.33-68.el9.x86_64.rpm
    sha:b18c8e436dfe894354fb9f35bee620bbe71f32bdc4bdd1e88a038d4f96df94fc
  • alt-php74-common-7.4.33-68.el9.x86_64.rpm
    sha:7fbb9baab9d5dbbd35c38f407fcf31f947e3df8308799069fab4e88ca284edb2
  • alt-php74-dba-7.4.33-68.el9.x86_64.rpm
    sha:816969f80692f504948cdf7fba9fe43c1bcbcb87e0003d96ad67e6ee15ad215d
  • alt-php74-devel-7.4.33-68.el9.x86_64.rpm
    sha:0a3c2096fb5c4b221f2636a55c71710cd730fa32b7bc6bf23810ec48291dfce6
  • alt-php74-enchant-7.4.33-68.el9.x86_64.rpm
    sha:f8f7762f7ed7b4e1447611aad754a13fbd9d48e8ef5d89af3e0ff228da6b81b9
  • alt-php74-firebird-7.4.33-68.el9.x86_64.rpm
    sha:913cc41eb8634419a2ca1fa91872079c3083807d9b228e87cded8e6775d71256
  • alt-php74-gd-7.4.33-68.el9.x86_64.rpm
    sha:36dff4885f3a9a3e04610c76f45078c852afdb7e3ee50f1699ef2f2d4b4d1238
  • alt-php74-imap-7.4.33-68.el9.x86_64.rpm
    sha:33f23369281bd72acfe36f5e4f84b6d4497976b3fe1a50fc3e6c4f7243138bc6
  • alt-php74-intl-7.4.33-68.el9.x86_64.rpm
    sha:13817b7bfb471d878e9c1a923eb256239b6053e52695efca9be555a9d18e5bac
  • alt-php74-ldap-7.4.33-68.el9.x86_64.rpm
    sha:df15a09c48cc0eb5884f2b8346afe7ccfd9f24702168c47ba6a2820819082d5b
  • alt-php74-mbstring-7.4.33-68.el9.x86_64.rpm
    sha:155e78556e1bdfb5f28a01197de537f2c8da0ca2549b791c384ecf73a2894f36
  • alt-php74-mysqlnd-7.4.33-68.el9.x86_64.rpm
    sha:01fbf8bcdf1b334e5e5237e9d35a21763b124d9b890efa2ea04e22c412258b32
  • alt-php74-odbc-7.4.33-68.el9.x86_64.rpm
    sha:15cf3fd1d1bda25c4b4d44a1cb9399418acabe73218c28fdc7fe2b56a07f4801
  • alt-php74-opcache-7.4.33-68.el9.x86_64.rpm
    sha:f71614407a5dfa95de51eb27278154b5c2546f602be9966e5928c9514075de1c
  • alt-php74-pdo-7.4.33-68.el9.x86_64.rpm
    sha:22a6365980a175586300b073ebbb305875447413dc7c98affe329e10088cff9b
  • alt-php74-pgsql-7.4.33-68.el9.x86_64.rpm
    sha:1b6761f633bfefc9c50729d11676c0249ec8da8e83c66b6356b9c0032d971f30
  • alt-php74-php-fpm-7.4.33-68.el9.x86_64.rpm
    sha:b8de193e6de05037ba820bb7283fde4e1a9ec63a9cdca42f0b5afb4d409f2a96
  • alt-php74-process-7.4.33-68.el9.x86_64.rpm
    sha:700b008974cff0441feedb50b3026dd006bd368a0fb666027ca76cb2722ed0da
  • alt-php74-pspell-7.4.33-68.el9.x86_64.rpm
    sha:35ac5bd10d2151b0a3d301b1fa5dce879cac2dbad988da8243f15f068808ccba
  • alt-php74-snmp-7.4.33-68.el9.x86_64.rpm
    sha:3ce4d7a5577d426c9a9163e29381820b1386b072e6a1111413bbe57b5cf7cc84
  • alt-php74-soap-7.4.33-68.el9.x86_64.rpm
    sha:9bd589184554ebf6a120a9972aedaacf7d555520e1dd6c207f5e19e1013c132d
  • alt-php74-sodium-7.4.33-68.el9.x86_64.rpm
    sha:b346ca57bfdc694079bc18ff7e239ebe3e77ed401796971e3b8da9f8133f0163
  • alt-php74-tidy-7.4.33-68.el9.x86_64.rpm
    sha:a0e960478abc6fb21be4bdad8d0b3d0a87d73edec804abb788e86bdbffab6865
  • alt-php74-xml-7.4.33-68.el9.x86_64.rpm
    sha:f2d465632feab9457590411c60d5e42addbdaf25afa10c2e23b40f2560b1d71a
  • alt-php74-xmlrpc-7.4.33-68.el9.x86_64.rpm
    sha:fa78bdd1745b04ee706757d1e20687c5efd8c60664b6d592faee6e6771689d38
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.