[CLSA-2026:1786522335] Fix CVE(s): CVE-2026-17543, CVE-2026-7260, CVE-2026-9672
Type:
security
Severity:
Critical
Release date:
2026-08-12 08:12:29 UTC
Description:
* CVE-2026-9672: three defects in the GIF LZW decoder of the bundled libgd - the code-table reset loop wrote sd->table[1][0] instead of sd->table[1][i] so most of table[1] kept stale data, LWZReadByte_() kept decoding past the end-of-information code when the trailing data blocks drained cleanly, and ReadImage() left its LZW_STATIC_DATA uninitialised on the stack * CVE-2026-17543: SQL injection in ext/pgsql - php_pgsql_add_quotes() wrapped values in an E'...' literal, in which the backslash left unescaped by PQescapeStringConn() (the default standard_conforming_strings=on doubles only the quote) escapes the following quote and lets a payload break out; pg_convert(), pg_insert(), pg_update(), pg_delete() and pg_select() are affected. Now quoted with a plain '...' literal * CVE-2026-7260: unbounded recursion in phar_get_link_source() when a tar-based phar archive contains a circular symlink chain; resolution is now an iterative walk with Floyd cycle detection, returning NULL on a cycle
Updated packages:
  • alt-php70_7.0.33-140_amd64.deb
    sha:315ca5586a059a60f753909d4ee992eff39a5479
  • alt-php70-bcmath_7.0.33-140_amd64.deb
    sha:d38f7ce6e6866540f5cecd4c2eb6451f84930a72
  • alt-php70-cli_7.0.33-140_amd64.deb
    sha:d21b758c8f46cb8297f0ef288d4019b95781d5b0
  • alt-php70-common_7.0.33-140_amd64.deb
    sha:663e492e77a20cb408c04e404045bb16a4b6f709
  • alt-php70-dba_7.0.33-140_amd64.deb
    sha:b6f7fc374766602bfaea83b8e2a2fb93f10e9d3b
  • alt-php70-dev_7.0.33-140_amd64.deb
    sha:ac6fbad750afa4c66f028386a8f09f0d5055648a
  • alt-php70-enchant_7.0.33-140_amd64.deb
    sha:f57ec932bc7e2b87183de8d4370b8c060e217699
  • alt-php70-firebird_7.0.33-140_amd64.deb
    sha:068c413216b4eae9cef729df4648f69c954483fa
  • alt-php70-gd_7.0.33-140_amd64.deb
    sha:f865c636a930e7e2321d06dba5b20479478eb716
  • alt-php70-imap_7.0.33-140_amd64.deb
    sha:0bf5451964e48b2478c406a443f38d1961befcb2
  • alt-php70-intl_7.0.33-140_amd64.deb
    sha:a62a8b8d2e2460b46f6badd3c03dc48f8f62b8c6
  • alt-php70-ldap_7.0.33-140_amd64.deb
    sha:28cd9cd56330a786dbcbff3aef7a3ed4f0e8ab69
  • alt-php70-mbstring_7.0.33-140_amd64.deb
    sha:5bb975b0399e5eeaea1f3bb616b0476d6680f242
  • alt-php70-mcrypt_7.0.33-140_amd64.deb
    sha:b89ac023c5120f395ccced4aee9249a3e4798089
  • alt-php70-mysqlnd_7.0.33-140_amd64.deb
    sha:64d93886dba7a50cdc4d79c1a610faf1153198cf
  • alt-php70-odbc_7.0.33-140_amd64.deb
    sha:b41338f20f67dedf84c95a2bae15aead0689757f
  • alt-php70-opcache_7.0.33-140_amd64.deb
    sha:0bd7a2fd3de617734b9771f6cc9ab457189e66cf
  • alt-php70-pdo_7.0.33-140_amd64.deb
    sha:4fdcd967f9732c062559f7c64b86e7af96740563
  • alt-php70-pgsql_7.0.33-140_amd64.deb
    sha:b24463942a618c7919cea174e6873c42d4883b08
  • alt-php70-php-fpm_7.0.33-140_amd64.deb
    sha:d77493fb3ab1fba67e2f012e67814be61dcc06cd
  • alt-php70-process_7.0.33-140_amd64.deb
    sha:a791acaec602d0961fa82101c3d27632803bf6b7
  • alt-php70-pspell_7.0.33-140_amd64.deb
    sha:4aee3678aa7773a39d7528d16a78abee49ce33ad
  • alt-php70-recode_7.0.33-140_amd64.deb
    sha:a77d4c73874460a0ac47d0eeeb8341f3db694bea
  • alt-php70-snmp_7.0.33-140_amd64.deb
    sha:e30c656f5f63d1647cd7d7f7705c7112506cac11
  • alt-php70-soap_7.0.33-140_amd64.deb
    sha:ccfa434b1a58ef3fb7ba30fccbfcb8338990a5d3
  • alt-php70-tidy_7.0.33-140_amd64.deb
    sha:ab9755d388f374f60bd13b543ab46df30423298e
  • alt-php70-xml_7.0.33-140_amd64.deb
    sha:9b2195cbff67608e18a563ec9c20c6ea4825c063
  • alt-php70-xmlrpc_7.0.33-140_amd64.deb
    sha:3e1c1a499deca82af639ac72a2e0fcbdbbbb6c90
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.