Release date:
2026-08-11 11:40:31 UTC
Description:
* CVE-2026-9672: fix three defects in the bundled libgd GIF LZW decoder reachable from attacker-controlled GIF data via imagecreatefromgif(). The table reset cleared sd->table[1][0] instead of sd->table[1][i], so stale suffixes leaked between images; LWZReadByte_() kept decoding with a stale code after the LZW end code when the trailing data block count was 0; and ReadImage() left LZW_STATIC_DATA uninitialised.
* CVE-2026-17543: fix SQL injection in ext/pgsql. php_pgsql_add_quotes() wrapped PQescapeStringConn() output in an E'...' literal, but PQescapeStringConn() only doubles the single quote while standard_conforming_strings is on, so a trailing backslash escaped the closing quote and broke out of the literal in pg_convert()/pg_insert()/pg_update()/pg_select()/pg_delete(). Emit a plain '...' literal instead.
* CVE-2026-7260: fix unbounded recursion in phar_get_link_source() on a circular symlink chain (GHSA-vc5h-9ppw-p5f3). The self-recursion is replaced by a Floyd cycle-detection walk that returns NULL for a cycle, including the phar_get_link_location() path-separator restore the walk depends on.
Updated packages:
-
alt-php72_7.2.34-89_amd64.deb
sha:5c83a9cd816c98512e37ba04ac67b3c02ada5848
-
alt-php72-bcmath_7.2.34-89_amd64.deb
sha:905ab5635d418db2e811fa2b2d9bf0f770ee1584
-
alt-php72-cli_7.2.34-89_amd64.deb
sha:0bdf9def44cc0cd16978212b0fd688e3b2e1293e
-
alt-php72-common_7.2.34-89_amd64.deb
sha:f4b1cfd0755772a9226e95c9b79c02cb46cce4bd
-
alt-php72-dba_7.2.34-89_amd64.deb
sha:9ffea79a304473ba00c258ab3d2bdd7f22927ce1
-
alt-php72-dev_7.2.34-89_amd64.deb
sha:3639cdca2f1b7d08de693cd49380efbf99df44c4
-
alt-php72-enchant_7.2.34-89_amd64.deb
sha:75a27dcf42578d3328b277a4840f1ef12817f31b
-
alt-php72-firebird_7.2.34-89_amd64.deb
sha:8ae029d5799fd99f37aefa4524c72b73aeaf7664
-
alt-php72-gd_7.2.34-89_amd64.deb
sha:f889c508a66f53917b4297888ebefe324331afd2
-
alt-php72-imap_7.2.34-89_amd64.deb
sha:3ccdd78cb1a33bcfa03ed2940ddbd13ff4010a81
-
alt-php72-intl_7.2.34-89_amd64.deb
sha:64e327f20b4b7ab45113dd55e0f058ca5f692776
-
alt-php72-ldap_7.2.34-89_amd64.deb
sha:68a59ce9e5af9b670fddefd04b372cfea20a635c
-
alt-php72-mbstring_7.2.34-89_amd64.deb
sha:a76dcbf6567d4ae603aefd8e501c94ab1983294e
-
alt-php72-mysqlnd_7.2.34-89_amd64.deb
sha:86d6eaed1cee7640c1feebde9b080d36a2c2d4cd
-
alt-php72-odbc_7.2.34-89_amd64.deb
sha:4b51084cfdb4fd2ae892229a4a4d8b0b217eed8e
-
alt-php72-opcache_7.2.34-89_amd64.deb
sha:224cad667efbea58fd7180f97fd83c1ba8a768d3
-
alt-php72-pdo_7.2.34-89_amd64.deb
sha:73a7f4b889bb6e56c4f5a508d857b5c4591aa944
-
alt-php72-pgsql_7.2.34-89_amd64.deb
sha:77dfa41db85526d7b7fcd6f11019f948037eae83
-
alt-php72-php-fpm_7.2.34-89_amd64.deb
sha:03f8b60303282972d1d2a199669921458d76a5eb
-
alt-php72-process_7.2.34-89_amd64.deb
sha:a75b9c1dbc63d6d122344356629412842f51c8d5
-
alt-php72-pspell_7.2.34-89_amd64.deb
sha:d9efc530bfd5ba8d9107e70c7448afe045a1dea3
-
alt-php72-recode_7.2.34-89_amd64.deb
sha:dc1a728d74846d45668f040a35c9f759c44ddfbc
-
alt-php72-snmp_7.2.34-89_amd64.deb
sha:faba98dbf1e9c82ac590ff95edad9eb0665b06ce
-
alt-php72-soap_7.2.34-89_amd64.deb
sha:8e2811b526ab3243f9b9c231da0fd3295627c847
-
alt-php72-sodium_7.2.34-89_amd64.deb
sha:a6ebe735ca19099efc428c1e685ec7921e951298
-
alt-php72-tidy_7.2.34-89_amd64.deb
sha:6c1762205b0808fba7539729f410b1bd7bf0d7b1
-
alt-php72-xml_7.2.34-89_amd64.deb
sha:c5ef236ae43c5d5700015edf072bb231bad1fdc3
-
alt-php72-xmlrpc_7.2.34-89_amd64.deb
sha:ba7973af3e2a76154eba29ccf543057825128eab
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.