Release date:
2026-08-10 11:33:18 UTC
Description:
* SECURITY UPDATE: three defects in the bundled libgd GIF LZW decoder
- debian/patches/php-7.1-CVE-2026-9672.patch: backport upstream commit
fcd691b377 in ext/gd/libgd/gd_gif_in.c - reset sd->table[1][i] instead
of sd->table[1][0] so the suffix table is fully cleared between images,
stop decoding once the LZW end code is seen instead of falling through
with a stale code, and zero-initialise LZW_STATIC_DATA in ReadImage().
- CVE-2026-9672
* SECURITY UPDATE: SQL injection in ext/pgsql via an E'...' backslash
breakout
- debian/patches/php-7.1-CVE-2026-17543.patch: backport upstream commit
ab048bd83b in ext/pgsql/pgsql.c - php_pgsql_add_quotes() no longer
emits the E prefix, since PQescapeStringConn() only doubles the single
quote and a trailing backslash could therefore escape the closing
quote of an E'...' literal. Test expectations updated accordingly and
a regression test added.
- CVE-2026-17543
* SECURITY UPDATE: phar crash on circular symlinks
- debian/patches/php-7.1-CVE-2026-7260.patch: backport upstream commit
2e0fa0a444 in ext/phar/util.c - phar_get_link_source() follows the
link chain with Floyd cycle detection via a new
phar_follow_one_link() helper instead of recursing into itself until
the C stack is exhausted, and phar_get_link_location() restores the
path separator it temporarily overwrites in entry->filename.
- CVE-2026-7260
Updated packages:
-
alt-php71_7.1.33-105_amd64.deb
sha:a565974e674dc51dfd0b87bc3f466c60341185e6
-
alt-php71-bcmath_7.1.33-105_amd64.deb
sha:927ea705a84af6bca436375e76f7441d3dc59f5f
-
alt-php71-cli_7.1.33-105_amd64.deb
sha:bdf95c59673159e127020084e21623140300afa0
-
alt-php71-common_7.1.33-105_amd64.deb
sha:92463782dde7e07eaf375aa0e00bc1e4b619e31f
-
alt-php71-dba_7.1.33-105_amd64.deb
sha:7c2a62af01d471bdb37e6871cb1759a96cf61895
-
alt-php71-dev_7.1.33-105_amd64.deb
sha:727fa4e64ddcc60ffe53edcb7a12a2036f5fbdcb
-
alt-php71-enchant_7.1.33-105_amd64.deb
sha:6cb79e49a57e2b3596e120edfb3de36c499fce1b
-
alt-php71-firebird_7.1.33-105_amd64.deb
sha:9702afee58973f3650f0449e2e3ade250eaa54ab
-
alt-php71-gd_7.1.33-105_amd64.deb
sha:fa8b3782525d9a9660a20d56f3a6e6c87efe3b94
-
alt-php71-imap_7.1.33-105_amd64.deb
sha:352a1321624ed4d3ce9847feccddfa90f0d2e860
-
alt-php71-intl_7.1.33-105_amd64.deb
sha:485bcf71dd5406b412098e9ae4e5a1c5c07d3181
-
alt-php71-ldap_7.1.33-105_amd64.deb
sha:b5778186c5663d0f658978f8a35560dc5a13e654
-
alt-php71-mbstring_7.1.33-105_amd64.deb
sha:7e5258130eac305d0cb823e374ef92c22ecf2483
-
alt-php71-mcrypt_7.1.33-105_amd64.deb
sha:a70708f63c1d253bc2214a9a05ee24b04413a803
-
alt-php71-mysqlnd_7.1.33-105_amd64.deb
sha:5e8fe132a7fcf6eea609a2229668f502b5652a30
-
alt-php71-odbc_7.1.33-105_amd64.deb
sha:a860fe4b6e0478e4dc058951c9c6f0643e5695fa
-
alt-php71-opcache_7.1.33-105_amd64.deb
sha:5d2f1c1765472730c0079cf1213e70d9d72abc01
-
alt-php71-pdo_7.1.33-105_amd64.deb
sha:3d99bda166efccc225dc64a64b409d004dbc4c5b
-
alt-php71-pgsql_7.1.33-105_amd64.deb
sha:f12b1a22cde3694914b9c6da9030fa25b3e68d6b
-
alt-php71-php-fpm_7.1.33-105_amd64.deb
sha:cba73e1c54a9bab0cee03d3c333f455c131a5d99
-
alt-php71-process_7.1.33-105_amd64.deb
sha:88ddbb6474c57c6fdd1e23a5e8a4fc7bf402007e
-
alt-php71-pspell_7.1.33-105_amd64.deb
sha:9a20a8307eaece6b67e7689c46ce475363a38d08
-
alt-php71-recode_7.1.33-105_amd64.deb
sha:7f119b1d203814f11b0f1fffe6ca3331de1234aa
-
alt-php71-snmp_7.1.33-105_amd64.deb
sha:8414a6db36d198378cef1bc7e3b8d54ba3535161
-
alt-php71-soap_7.1.33-105_amd64.deb
sha:6c8fe71d3a57185469d7208dabb90437c0067f0b
-
alt-php71-tidy_7.1.33-105_amd64.deb
sha:3fa6b4fdaae1fc6fde81cd179a43bef0993198be
-
alt-php71-xml_7.1.33-105_amd64.deb
sha:2444c2916fa2624fe550faae13a9ad5a9d618f55
-
alt-php71-xmlrpc_7.1.33-105_amd64.deb
sha:ca9731556e8e715c939e2adc0ad207afcc056d4b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.