Release date:
2026-08-13 02:02:23 UTC
Description:
* SECURITY UPDATE: three defects in the bundled libgd GIF LZW decoder
- debian/patches/php-7.1-CVE-2026-9672.patch: backport upstream commit
fcd691b377 in ext/gd/libgd/gd_gif_in.c - reset sd->table[1][i] instead
of sd->table[1][0] so the suffix table is fully cleared between images,
stop decoding once the LZW end code is seen instead of falling through
with a stale code, and zero-initialise LZW_STATIC_DATA in ReadImage().
- CVE-2026-9672
* SECURITY UPDATE: SQL injection in ext/pgsql via an E'...' backslash
breakout
- debian/patches/php-7.1-CVE-2026-17543.patch: backport upstream commit
ab048bd83b in ext/pgsql/pgsql.c - php_pgsql_add_quotes() no longer
emits the E prefix, since PQescapeStringConn() only doubles the single
quote and a trailing backslash could therefore escape the closing
quote of an E'...' literal. Test expectations updated accordingly and
a regression test added.
- CVE-2026-17543
* SECURITY UPDATE: phar crash on circular symlinks
- debian/patches/php-7.1-CVE-2026-7260.patch: backport upstream commit
2e0fa0a444 in ext/phar/util.c - phar_get_link_source() follows the
link chain with Floyd cycle detection via a new
phar_follow_one_link() helper instead of recursing into itself until
the C stack is exhausted, and phar_get_link_location() restores the
path separator it temporarily overwrites in entry->filename.
- CVE-2026-7260
Updated packages:
-
alt-php71_7.1.33-105_amd64.deb
sha:68f5f3f809aa29e99d4086918b236722798744ce
-
alt-php71-bcmath_7.1.33-105_amd64.deb
sha:1e9d1ab76553c478d065173f734f6e4b0cffe02b
-
alt-php71-cli_7.1.33-105_amd64.deb
sha:2ec52623326ae5ebd78a526b96f3fdf6041f113f
-
alt-php71-common_7.1.33-105_amd64.deb
sha:f38ded23911d6f9a6a6d6c391db0d2944fde4462
-
alt-php71-dba_7.1.33-105_amd64.deb
sha:fdb9d8c375e1d4283b1917273a69f5a838741495
-
alt-php71-dev_7.1.33-105_amd64.deb
sha:7b1cbe976b11a9ec6c377989b1a12183150aa7c8
-
alt-php71-enchant_7.1.33-105_amd64.deb
sha:3de7761cf33df60fbf3f73c7d7787504743e9151
-
alt-php71-firebird_7.1.33-105_amd64.deb
sha:b65e750ec56343d353d5959af390a9de95d637cc
-
alt-php71-gd_7.1.33-105_amd64.deb
sha:47c3dc42712d5b875d4f1c672a14c9f6f3241382
-
alt-php71-imap_7.1.33-105_amd64.deb
sha:60c643848d3fb15f51b84a6f6b9b48ac0117b31d
-
alt-php71-intl_7.1.33-105_amd64.deb
sha:25af4cfb332534aa7649fd30fa06ba7fe7fafbe8
-
alt-php71-ldap_7.1.33-105_amd64.deb
sha:3becbad16976e2c45101cdd176c71d5b3f4c8470
-
alt-php71-mbstring_7.1.33-105_amd64.deb
sha:8bb0dfc10ec306b935eb53cf35caa832c360e5e9
-
alt-php71-mcrypt_7.1.33-105_amd64.deb
sha:301164fd1727df03a6531f6e35a5ac2a5c944239
-
alt-php71-mysqlnd_7.1.33-105_amd64.deb
sha:1a8bb5eea5798467fb60b5a40125b33ac101d039
-
alt-php71-odbc_7.1.33-105_amd64.deb
sha:83654ad44c460a61092131b169e3cc467b0010e8
-
alt-php71-opcache_7.1.33-105_amd64.deb
sha:3f88129409c1dcaa8e2ea8e1ae2728e27065c6eb
-
alt-php71-pdo_7.1.33-105_amd64.deb
sha:5073d68c5561216bdfabb7bfe215372fd063608f
-
alt-php71-pgsql_7.1.33-105_amd64.deb
sha:220f0c8f09c9daec67e4e8650b2f0720ef8e8110
-
alt-php71-php-fpm_7.1.33-105_amd64.deb
sha:eace984443cb04b1e4329df5d9716d8efd08da3e
-
alt-php71-process_7.1.33-105_amd64.deb
sha:a9dc8d18463e638ede0935985cf1b547be9b6235
-
alt-php71-pspell_7.1.33-105_amd64.deb
sha:0d2ae577692a847099223143b87b365b4a96daf2
-
alt-php71-recode_7.1.33-105_amd64.deb
sha:60c980d18faf67e6a464cf94551310a6873b4d8d
-
alt-php71-snmp_7.1.33-105_amd64.deb
sha:cb8ee87a095f531e53ef2cfb2d18568f3cd61cbb
-
alt-php71-soap_7.1.33-105_amd64.deb
sha:c49e977b1cf2f97a35b0183805f549b785b989b6
-
alt-php71-tidy_7.1.33-105_amd64.deb
sha:e22837c6c291c05631eab9edf73ea0657b658aa3
-
alt-php71-xml_7.1.33-105_amd64.deb
sha:baf945ae0489a5e3c8fa0bdafe9dea5288a96a60
-
alt-php71-xmlrpc_7.1.33-105_amd64.deb
sha:7939c621fdfd5397a629aad016ae44156d149e05
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.