[CLSA-2026:1786445383] alt-php80: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-11 10:49:55 UTC
Description:
- CVE-2026-17543: SQL injection in ext/pgsql. php_pgsql_add_quotes() wrapped PQescapeStringConn() output in an E'...' escape-string constant, where a trailing backslash escapes the doubling quote and breaks out of the literal; emit a plain '...' literal instead - CVE-2026-7260: stack exhaustion in ext/phar. phar_get_link_source() followed symlink chains by unbounded tail recursion, so a tar-based phar with circular symlinks crashed the process; walk the chain iteratively with Floyd cycle detection and return NULL on a loop
Updated packages:
  • alt-php80-8.0.30-58.el6.x86_64.rpm
    sha:a03ef3e2cad0409fde831f3440b782e97b992a10534ad23d6b19a229000cbd3c
  • alt-php80-bcmath-8.0.30-58.el6.x86_64.rpm
    sha:057ca53657fd3ab5c835653a1241c45411d4e293bab81009745c88c210501d8c
  • alt-php80-cli-8.0.30-58.el6.x86_64.rpm
    sha:71c3cb2c48e609a075c38cb43bd8c2c7ec3269f44d3bbe77d3dedd7fa7e013c6
  • alt-php80-common-8.0.30-58.el6.x86_64.rpm
    sha:01af4db1798bff36edd5fc488b4a0141dc1f513a8834d5d28d6d814ef156716a
  • alt-php80-dba-8.0.30-58.el6.x86_64.rpm
    sha:c1498a71265b38cc45395f5b1bbb034af145e8f8d6ec8d2fd606b1dc7f65f70f
  • alt-php80-devel-8.0.30-58.el6.x86_64.rpm
    sha:ce9f38d54ce36af0bf9941a53235ddd77e469cf003114e7a3fbec9aa9999a401
  • alt-php80-enchant-8.0.30-58.el6.x86_64.rpm
    sha:23d58e7752e893509c6d43b160a5fa582b865ddbdc2ef4f63aaa8f8cd030f48a
  • alt-php80-firebird-8.0.30-58.el6.x86_64.rpm
    sha:405324ea1a9f2d269af3c151f5a8237b24c25674599c18fadaf9bb0b761d6037
  • alt-php80-gd-8.0.30-58.el6.x86_64.rpm
    sha:9a623ff063aec9b9e0a436d22cfbd9ca6e0009006a4b683caa80b3787c9e1829
  • alt-php80-imap-8.0.30-58.el6.x86_64.rpm
    sha:3839ef918c97a2a54f75e70a4baaec079bffe52a336dd0d6da0015c898987162
  • alt-php80-intl-8.0.30-58.el6.x86_64.rpm
    sha:2247e7e5ccc8436f102e5b074e88d1b1778286e406a97d3a943b3676fbf76907
  • alt-php80-ldap-8.0.30-58.el6.x86_64.rpm
    sha:1fee1fb84a02236db2ae60ebd1257224c960baa2179482c9fe91bffcfe8f664d
  • alt-php80-mbstring-8.0.30-58.el6.x86_64.rpm
    sha:37f5b6ec2c549709ff6d2cecde9bf9c3fc77303e8576d85a79b1c341db920dc8
  • alt-php80-mysqlnd-8.0.30-58.el6.x86_64.rpm
    sha:4c8eec0b9ec1b99808587defde806fbd85101ad7baab9c282203f6bd7d450704
  • alt-php80-odbc-8.0.30-58.el6.x86_64.rpm
    sha:cf25a2f8ecb1c087f3e01bcae44a53bd3c8415ea30a4b4f1a9bbe88ea8eea4b3
  • alt-php80-opcache-8.0.30-58.el6.x86_64.rpm
    sha:ac18c26a4d6f640e5adcbcd6d7108bdffd98769e0a5eb086acb38f876095007e
  • alt-php80-pdo-8.0.30-58.el6.x86_64.rpm
    sha:95f819b952675bc54ff7924b69acd520a1675ac09277e973cef735232dce525f
  • alt-php80-pgsql-8.0.30-58.el6.x86_64.rpm
    sha:76bda531241e0c669594b60a724897e4d5313d0b118e7446e23ba0534e3bb876
  • alt-php80-php-fpm-8.0.30-58.el6.x86_64.rpm
    sha:9368550e1973a91b936c3c547c5dba9896b9155490686446e3a2268e1aab9335
  • alt-php80-process-8.0.30-58.el6.x86_64.rpm
    sha:5c152447bfceb1a327298e2179c179b3a9c9b42725a49106120487d9a48ddafb
  • alt-php80-pspell-8.0.30-58.el6.x86_64.rpm
    sha:2911e6a1e8a0970c20be374350335c6ef31da30a753c0c807f06a436083810bf
  • alt-php80-snmp-8.0.30-58.el6.x86_64.rpm
    sha:7370c37fd8aaab7461cae793b59ac8edfb5268463b1dbace9d80c075af404d52
  • alt-php80-soap-8.0.30-58.el6.x86_64.rpm
    sha:cf04e366f22be6f18259840bc87eed167af2d67b0407c512faa02b91c4e0584c
  • alt-php80-sodium-8.0.30-58.el6.x86_64.rpm
    sha:bda1e97a9f92b0d17ed5aa63a7464bb0d750d45ec318e6dc3ace742b7686e8cd
  • alt-php80-tidy-8.0.30-58.el6.x86_64.rpm
    sha:b4fc071c2e0b839795bfd916bb92f7f9583fd6cf82d6c1256f2872fc04574e41
  • alt-php80-xml-8.0.30-58.el6.x86_64.rpm
    sha:60c78556d5f15b3feea0b8b4b9cc65db04519c2116077f938933180b2166b057
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.