[CLSA-2026:1786436288] Fix CVE(s): CVE-2026-17543, CVE-2026-7260, CVE-2026-9672
Type:
security
Severity:
Critical
Release date:
2026-08-11 08:18:21 UTC
Description:
* CVE-2026-9672: three defects in the GIF LZW decoder of the bundled libgd - the code-table reset loop wrote sd->table[1][0] instead of sd->table[1][i] so most of table[1] kept stale data, LWZReadByte_() kept decoding past the end-of-information code when the trailing data blocks drained cleanly, and ReadImage() left its LZW_STATIC_DATA uninitialised on the stack * CVE-2026-17543: SQL injection in ext/pgsql - php_pgsql_add_quotes() wrapped values in an E'...' literal, in which the backslash left unescaped by PQescapeStringConn() (the default standard_conforming_strings=on doubles only the quote) escapes the following quote and lets a payload break out; pg_convert(), pg_insert(), pg_update(), pg_delete() and pg_select() are affected. Now quoted with a plain '...' literal * CVE-2026-7260: unbounded recursion in phar_get_link_source() when a tar-based phar archive contains a circular symlink chain; resolution is now an iterative walk with Floyd cycle detection, returning NULL on a cycle
Updated packages:
  • alt-php70_7.0.33-140_amd64.deb
    sha:72d0e1eea39a93a6ea2bc140c1281f8e17e21d10
  • alt-php70-bcmath_7.0.33-140_amd64.deb
    sha:190c2c861827e6b6b0c960b90e462218984382e3
  • alt-php70-cli_7.0.33-140_amd64.deb
    sha:4af38c0d6a5d6a04aff90b34649d5a726a1fbb2b
  • alt-php70-common_7.0.33-140_amd64.deb
    sha:3e685a22730d514e0b23bb1f428e948db4d10aef
  • alt-php70-dba_7.0.33-140_amd64.deb
    sha:a2a5b164d1d36ffbc2b884e840c705a8821830d6
  • alt-php70-dev_7.0.33-140_amd64.deb
    sha:04dd1917f088a781f5f664f92410f047a728c648
  • alt-php70-enchant_7.0.33-140_amd64.deb
    sha:7326bc48ea85f6d40b6d184cc60be75bb91ecb43
  • alt-php70-firebird_7.0.33-140_amd64.deb
    sha:9f2b46e332e2402ed19516fde5863279fcaaaff3
  • alt-php70-gd_7.0.33-140_amd64.deb
    sha:b94f0577bcc20c15257a5bf1c3d6d4e0bc1cd417
  • alt-php70-imap_7.0.33-140_amd64.deb
    sha:a370012b16763edb6747d77bd9fa97b11cc98c49
  • alt-php70-intl_7.0.33-140_amd64.deb
    sha:db4cac0ee109e482f622c6401cfddb8a48af4a79
  • alt-php70-ldap_7.0.33-140_amd64.deb
    sha:4700f2dc60f5ce2e8d5376945f2ae24e882a1c42
  • alt-php70-mbstring_7.0.33-140_amd64.deb
    sha:5fde6c9750a12cb07903c9bce0137caf2f7d0c05
  • alt-php70-mcrypt_7.0.33-140_amd64.deb
    sha:48d02265bce4306a1b3d29b36737f729d7d76dee
  • alt-php70-mysqlnd_7.0.33-140_amd64.deb
    sha:c6162343eb4c9e5571f1cd3eb4ac4be69f59c947
  • alt-php70-odbc_7.0.33-140_amd64.deb
    sha:1b31ba86141d82fd4e66684db006a51b89c774c7
  • alt-php70-opcache_7.0.33-140_amd64.deb
    sha:a292c3bec086c7b1af78f14eeb6b7809181cf175
  • alt-php70-pdo_7.0.33-140_amd64.deb
    sha:9e5fccdf68bbd7331e3c466adaa4236888a4d2cb
  • alt-php70-pgsql_7.0.33-140_amd64.deb
    sha:171936510048b33356f2ae4919407223774c442e
  • alt-php70-php-fpm_7.0.33-140_amd64.deb
    sha:e4b7946c78d5cb00ff25b2e16d7a29773eb0862f
  • alt-php70-process_7.0.33-140_amd64.deb
    sha:c9eef476140ecc5116648e7103cdc97d7e98e4c9
  • alt-php70-pspell_7.0.33-140_amd64.deb
    sha:cfa22c4877188eeb31abf2a8acec160d083f71a6
  • alt-php70-recode_7.0.33-140_amd64.deb
    sha:4f6efdbb2ccc649e1dcca4449b8059296de10ae5
  • alt-php70-snmp_7.0.33-140_amd64.deb
    sha:ce212ff757d88fbbe7fbddf20de6a7602f96ef8e
  • alt-php70-soap_7.0.33-140_amd64.deb
    sha:1073e3f24a1fd22a3a7d4b2fefca40039e218ee5
  • alt-php70-tidy_7.0.33-140_amd64.deb
    sha:a08156f3487253eb7151fbf0eabfc6c132ecd30d
  • alt-php70-xml_7.0.33-140_amd64.deb
    sha:f9a6b0b507704db3d8a340afb0d5fb408872bd0e
  • alt-php70-xmlrpc_7.0.33-140_amd64.deb
    sha:a1bddb1128fa445968828a74cebce338a94d5df8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.