[CLSA-2026:1786596355] alt-php74: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-13 04:46:06 UTC
Description:
- CVE-2026-17543: pg_insert()/pg_update()/pg_select()/pg_delete() emitted values escaped by PQescapeStringConn() inside an E'...' constant, so a trailing backslash broke out of the literal (SQL injection); emit a plain '...' constant instead - CVE-2026-7260: phar_get_link_source() followed tar symlink chains by unbounded recursion, so a phar with circular symlinks exhausted the C stack; walk the chain iteratively with Floyd cycle detection
Updated packages:
  • alt-php74-7.4.33-68.el10.x86_64.rpm
    sha:6c097220c77f56007959fd245dab419e61e8f19d78c4e5c808637875b83315f5
  • alt-php74-bcmath-7.4.33-68.el10.x86_64.rpm
    sha:f1c72927f9ab2d911608e5af8de8cb71ad65f76eba70dcb9e470c7353922e778
  • alt-php74-cli-7.4.33-68.el10.x86_64.rpm
    sha:af0d6708648fb466de043a91948bf77947ad3156f308d1fdbe0bcea9cc350057
  • alt-php74-common-7.4.33-68.el10.x86_64.rpm
    sha:4311a74b5f1a7ffe2d84d69e6f92f8b12db0c191a415cc7e75d9d41923533163
  • alt-php74-dba-7.4.33-68.el10.x86_64.rpm
    sha:98ca5a63fdd2f3b0df3d676973eb16b3f4ece5c977ff3ef7b0e45e57583bb04e
  • alt-php74-devel-7.4.33-68.el10.x86_64.rpm
    sha:04f42dbf0a21db7490d2be9825a58beeaf0efe26e4d296886bfad7499902d897
  • alt-php74-enchant-7.4.33-68.el10.x86_64.rpm
    sha:65ed3e2c6df92d28803a7c03cd258171447791f439bb6cbc7e5841182db0dc3a
  • alt-php74-firebird-7.4.33-68.el10.x86_64.rpm
    sha:30c6ed49df9d873438d7c8a8c143c6ed148bcbc751a25c40accc0be1f84c0848
  • alt-php74-gd-7.4.33-68.el10.x86_64.rpm
    sha:687024fad9a79fdff37c05048383e43f6575ccc805c04b1e902135f84521947e
  • alt-php74-imap-7.4.33-68.el10.x86_64.rpm
    sha:f46392700147e451761f8059986d736e2af42c022710be7dce135ca59bbad07f
  • alt-php74-intl-7.4.33-68.el10.x86_64.rpm
    sha:29b91b12eb70100110cc252563a2ede6515997cb5f52747faba1e2987a4baed6
  • alt-php74-ldap-7.4.33-68.el10.x86_64.rpm
    sha:7c43c0e77ad568753e6c68a5d013f32992bd630989bb44c1e02e1536ff2b4b8a
  • alt-php74-mbstring-7.4.33-68.el10.x86_64.rpm
    sha:753e156024d748cc4866056a8a46210bea78a883a7250d6122c447932b67fdd6
  • alt-php74-mysqlnd-7.4.33-68.el10.x86_64.rpm
    sha:3fdd656be62e5bcd3fd2b5baef35496543d014176703331667c3c6377c96ce90
  • alt-php74-odbc-7.4.33-68.el10.x86_64.rpm
    sha:09f8269bd0b5b8f66a7d07cc7eabff77476659f2036a29b1680f22878eb5df95
  • alt-php74-opcache-7.4.33-68.el10.x86_64.rpm
    sha:3b33281200398ba191a2be2f353a4926a7791acf9562ee2f611e445a76eda3fc
  • alt-php74-pdo-7.4.33-68.el10.x86_64.rpm
    sha:6bd7f0df7f1b08e41218b47a05604c6cca28b5599e03445f38dc8fedb6abfa4f
  • alt-php74-pgsql-7.4.33-68.el10.x86_64.rpm
    sha:e9f3b0f91fcd399a6caf8d86d19aa830aeb66adf8f3b9e34fc59c57641ac19b5
  • alt-php74-php-fpm-7.4.33-68.el10.x86_64.rpm
    sha:f2b962813d925971a04c6d0540986a2ee09de073137d66c746a89c04b6ac9764
  • alt-php74-process-7.4.33-68.el10.x86_64.rpm
    sha:a3dd37fd90aca0190cf3d391b45a82b64db75d9df85c3e8b7379888fd1bd7a52
  • alt-php74-pspell-7.4.33-68.el10.x86_64.rpm
    sha:252cd3dfdf45c0c99821d9b29dcb2dec99e979221666015da0a2bed814b5c3a0
  • alt-php74-snmp-7.4.33-68.el10.x86_64.rpm
    sha:03899bd7282d8ca9e9aeeb2e3724ede870f9934a83c6a47438d7cf0c00dea08b
  • alt-php74-soap-7.4.33-68.el10.x86_64.rpm
    sha:5117048343fd0ae4d32da3578b41ecbb5c9ff76d9af0319b9552893d8f21e887
  • alt-php74-sodium-7.4.33-68.el10.x86_64.rpm
    sha:e527ff75bcd4c9b5da3aab8bc0b478722888881a6c32a8708f7edf27b202c2a1
  • alt-php74-tidy-7.4.33-68.el10.x86_64.rpm
    sha:ccf3f3fbfe47e59d0cce0fb76a4cffac6b30f2bd2f502b18b3391578d5069122
  • alt-php74-xml-7.4.33-68.el10.x86_64.rpm
    sha:3eb6b32472c76dfeb10d8a70c78979c8392d3360ed508bbb2ef291745418b084
  • alt-php74-xmlrpc-7.4.33-68.el10.x86_64.rpm
    sha:84eb6827d83522cc75ad2bac81884f058fcd05a7edb7305a8fb45030ddbe355d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.