[CLSA-2026:1786009155] Fix CVE(s): CVE-2026-17543, CVE-2026-7260, CVE-2026-9672
Type:
security
Severity:
Critical
Release date:
2026-08-06 09:39:34 UTC
Description:
* CVE-2026-9672: three defects in the GIF LZW decoder of the bundled libgd - the code-table reset loop wrote sd->table[1][0] instead of sd->table[1][i] so most of table[1] kept stale data, LWZReadByte_() kept decoding past the end-of-information code when the trailing data blocks drained cleanly, and ReadImage() left its LZW_STATIC_DATA uninitialised on the stack * CVE-2026-17543: SQL injection in ext/pgsql - php_pgsql_add_quotes() wrapped values in an E'...' literal, in which the backslash left unescaped by PQescapeStringConn() (the default standard_conforming_strings=on doubles only the quote) escapes the following quote and lets a payload break out; pg_convert(), pg_insert(), pg_update(), pg_delete() and pg_select() are affected. Now quoted with a plain '...' literal * CVE-2026-7260: unbounded recursion in phar_get_link_source() when a tar-based phar archive contains a circular symlink chain; resolution is now an iterative walk with Floyd cycle detection, returning NULL on a cycle
Updated packages:
  • alt-php70_7.0.33-140_amd64.deb
    sha:39496b4411681230daad624946f67e6e1efa2785
  • alt-php70-bcmath_7.0.33-140_amd64.deb
    sha:8aa7f4e9b08e4a59100cc549a18b7644c70f2285
  • alt-php70-cli_7.0.33-140_amd64.deb
    sha:7193d7f8938e8773edadb26071b5db16c13e124c
  • alt-php70-common_7.0.33-140_amd64.deb
    sha:8cd8d85d026f8794e822976f74ae2c58ab9f5e96
  • alt-php70-dba_7.0.33-140_amd64.deb
    sha:46de0259be2f92e51dd207a962db7bdc90a407da
  • alt-php70-dev_7.0.33-140_amd64.deb
    sha:d371e919137ca9ab7c8a6608cb0960cda54a98bd
  • alt-php70-enchant_7.0.33-140_amd64.deb
    sha:2758cdf64d657792a850b25910644042c2437e90
  • alt-php70-firebird_7.0.33-140_amd64.deb
    sha:bc230845528da2df0df5e81c07c6f7127b382a17
  • alt-php70-gd_7.0.33-140_amd64.deb
    sha:ef491b71fc766393b171f02f47710a73cb10ce40
  • alt-php70-imap_7.0.33-140_amd64.deb
    sha:c9ae023fe8ee8fe5cb5addef8bd9635eae948908
  • alt-php70-intl_7.0.33-140_amd64.deb
    sha:9881c01c32dc1ff86b78248cea297565f16de3b7
  • alt-php70-ldap_7.0.33-140_amd64.deb
    sha:1e691708031e0db9178aba9f6197a9420b163b3b
  • alt-php70-mbstring_7.0.33-140_amd64.deb
    sha:591e662b2eee6ee63a5660b352e90314cc29db41
  • alt-php70-mcrypt_7.0.33-140_amd64.deb
    sha:6b00d9b760d9225b8b0ec5827253ccf459ae6d21
  • alt-php70-mysqlnd_7.0.33-140_amd64.deb
    sha:1512e20c59ef84472c5cf79a1a0ee78b502b351e
  • alt-php70-odbc_7.0.33-140_amd64.deb
    sha:43ae4b91d502d9e623da6e2d42fe2a66eefc72b3
  • alt-php70-opcache_7.0.33-140_amd64.deb
    sha:dd45e6e05c3375e3a6fcf5627f65c76498e9c910
  • alt-php70-pdo_7.0.33-140_amd64.deb
    sha:829e044374d4beedddbbaf74a2cbd60e21bad9ba
  • alt-php70-pgsql_7.0.33-140_amd64.deb
    sha:78067fcfc9cb4ce30a7a23e4939e21afbe4a5c77
  • alt-php70-php-fpm_7.0.33-140_amd64.deb
    sha:d715dd588a603344871c7e0d214abf2248b89d2a
  • alt-php70-process_7.0.33-140_amd64.deb
    sha:a4985203441b1ddfee868f0624827ef06b091dad
  • alt-php70-pspell_7.0.33-140_amd64.deb
    sha:07e1ae56c3209dd8e1734e56bce2763846bd9514
  • alt-php70-recode_7.0.33-140_amd64.deb
    sha:09ff8eaaba7825d7e6cbe5dafd09b836d636eb89
  • alt-php70-snmp_7.0.33-140_amd64.deb
    sha:341437970f7a109a34eac488953c0ad07cadd2d4
  • alt-php70-soap_7.0.33-140_amd64.deb
    sha:a7fa957c682f44838de68b0db03d432cd26791bb
  • alt-php70-tidy_7.0.33-140_amd64.deb
    sha:92011c2eba2e44fe6eacc36800ff2e976074ae4c
  • alt-php70-xml_7.0.33-140_amd64.deb
    sha:f3d82abfc2d1f3be3813b39c3bd90293f49758fc
  • alt-php70-xmlrpc_7.0.33-140_amd64.deb
    sha:b0cfc8ed5a6638b3e298371ea33915add0909067
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.