[CLSA-2026:1786015993] Fix CVE(s): CVE-2026-17543, CVE-2026-7260, CVE-2026-9672
Type:
security
Severity:
Critical
Release date:
2026-08-06 11:33:38 UTC
Description:
* CVE-2026-9672: fix three defects in the bundled libgd GIF LZW decoder reachable from attacker-controlled GIF data via imagecreatefromgif(). The table reset cleared sd->table[1][0] instead of sd->table[1][i], so stale suffixes leaked between images; LWZReadByte_() kept decoding with a stale code after the LZW end code when the trailing data block count was 0; and ReadImage() left LZW_STATIC_DATA uninitialised. * CVE-2026-17543: fix SQL injection in ext/pgsql. php_pgsql_add_quotes() wrapped PQescapeStringConn() output in an E'...' literal, but PQescapeStringConn() only doubles the single quote while standard_conforming_strings is on, so a trailing backslash escaped the closing quote and broke out of the literal in pg_convert()/pg_insert()/pg_update()/pg_select()/pg_delete(). Emit a plain '...' literal instead. * CVE-2026-7260: fix unbounded recursion in phar_get_link_source() on a circular symlink chain (GHSA-vc5h-9ppw-p5f3). The self-recursion is replaced by a Floyd cycle-detection walk that returns NULL for a cycle, including the phar_get_link_location() path-separator restore the walk depends on.
Updated packages:
  • alt-php72_7.2.34-89_amd64.deb
    sha:6f8408c08f107d4e0bc9a5b54ac7d054775c8e99
  • alt-php72-bcmath_7.2.34-89_amd64.deb
    sha:f065b5d8babbf9357c540f23a3d7138d461ad32a
  • alt-php72-cli_7.2.34-89_amd64.deb
    sha:a4196a96a115633b1a713e0bea44887bc545fea2
  • alt-php72-common_7.2.34-89_amd64.deb
    sha:32e5bab8cf63a3451e5519be77a6ca94d4212e96
  • alt-php72-dba_7.2.34-89_amd64.deb
    sha:f57db64159ffbe4959eaa030c922d9a438a172ed
  • alt-php72-dev_7.2.34-89_amd64.deb
    sha:14aec829d5d7fdf938edcdb0f5073eeea062b14a
  • alt-php72-enchant_7.2.34-89_amd64.deb
    sha:b853c7f997e10a9e0acce490d322776ce7cc61d0
  • alt-php72-firebird_7.2.34-89_amd64.deb
    sha:58e2cf66552a613ee93edc9a204667be4e75d088
  • alt-php72-gd_7.2.34-89_amd64.deb
    sha:507da2542e2341aaac8e9f7a8299491f9095a9b3
  • alt-php72-imap_7.2.34-89_amd64.deb
    sha:ab1c99a106041b6e740aaefc8d3266cd80a2a876
  • alt-php72-intl_7.2.34-89_amd64.deb
    sha:d49882ebb612033869babf26024049df1cffb643
  • alt-php72-ldap_7.2.34-89_amd64.deb
    sha:a8fe84024d2b6acd6f92d15fa68efd8bb2f6543a
  • alt-php72-mbstring_7.2.34-89_amd64.deb
    sha:fdf3576ce4c09b6e87a713d6c4fc8f12a6240674
  • alt-php72-mysqlnd_7.2.34-89_amd64.deb
    sha:69d302971e2ea6dbc0ace8be7730682f17fbbfc0
  • alt-php72-odbc_7.2.34-89_amd64.deb
    sha:4bc53193c39d0b25e79dc63781edc4ac5aa6c755
  • alt-php72-opcache_7.2.34-89_amd64.deb
    sha:a73eda0d95290e3e3a73ad1b7def4b6b6059f4b5
  • alt-php72-pdo_7.2.34-89_amd64.deb
    sha:e87142f14e316410ae72ec6a29567fe9cce4b241
  • alt-php72-pgsql_7.2.34-89_amd64.deb
    sha:df351aca017bb790aba98b7ae54211b5b1473901
  • alt-php72-php-fpm_7.2.34-89_amd64.deb
    sha:587cff2e9ede1dfaa249dc9734c06e545f64ba57
  • alt-php72-process_7.2.34-89_amd64.deb
    sha:901b6c1096457a933a8985d7bdbd9597dc5c5292
  • alt-php72-pspell_7.2.34-89_amd64.deb
    sha:ab507f042675697e32d0952390f341fc9c5f0261
  • alt-php72-recode_7.2.34-89_amd64.deb
    sha:af8d26fb90423f6dd6ccd3cb178ca33413fc4f4e
  • alt-php72-snmp_7.2.34-89_amd64.deb
    sha:e73b0d43c7c09e4fffca98a32c6547f591e86caf
  • alt-php72-soap_7.2.34-89_amd64.deb
    sha:a15dbdc632b0d8d755f4811632fda53905e5784e
  • alt-php72-sodium_7.2.34-89_amd64.deb
    sha:4243bb512f7214a68dd56e9f0447dafb31e58194
  • alt-php72-tidy_7.2.34-89_amd64.deb
    sha:f10cdfa5e1f26b39c962e584df38b6b34b84511d
  • alt-php72-xml_7.2.34-89_amd64.deb
    sha:3b34cde5fce943a5e0794b7e1d7be18ae4cfedd9
  • alt-php72-xmlrpc_7.2.34-89_amd64.deb
    sha:cedfb1219485a4510d0eedfaf10b8605af4f1a9d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.