[CLSA-2026:1786597355] alt-php74: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-13 05:02:46 UTC
Description:
- CVE-2026-17543: pg_insert()/pg_update()/pg_select()/pg_delete() emitted values escaped by PQescapeStringConn() inside an E'...' constant, so a trailing backslash broke out of the literal (SQL injection); emit a plain '...' constant instead - CVE-2026-7260: phar_get_link_source() followed tar symlink chains by unbounded recursion, so a phar with circular symlinks exhausted the C stack; walk the chain iteratively with Floyd cycle detection
Updated packages:
  • alt-php74-7.4.33-68.el6.x86_64.rpm
    sha:b12f594e66c7267fb4acf850c97c656f4e7143fcd19ef71a58e3ab80cfaf6462
  • alt-php74-bcmath-7.4.33-68.el6.x86_64.rpm
    sha:8f93aca6963733f5db1535d15d7968666df1f35b442decd1b1eaf0a205232618
  • alt-php74-cli-7.4.33-68.el6.x86_64.rpm
    sha:53e6452d7ab2e32b23d63f1d5add263fbedc82dd66393c89c07e6b918b970fc0
  • alt-php74-common-7.4.33-68.el6.x86_64.rpm
    sha:acc500fb16a4a4f36e0c0d24849f95c755f59a2a3113bbe1a9097f6fc34144c4
  • alt-php74-dba-7.4.33-68.el6.x86_64.rpm
    sha:bd2de89226f80a3fb50d6f07cf09f860b731d9a265b811eca6b95a8c5359dc2b
  • alt-php74-devel-7.4.33-68.el6.x86_64.rpm
    sha:5b35599ddeeb10cd9a3ab5889aa80e12d28f7c96c1e14b4e4338948c12388573
  • alt-php74-enchant-7.4.33-68.el6.x86_64.rpm
    sha:e13e3190c427456163a5e50f88e67a527bd065b61deb3ccf9958176cd84659b0
  • alt-php74-firebird-7.4.33-68.el6.x86_64.rpm
    sha:eaef55e77b21c4659c082160c15e8ac987c3c30d0e60589e2ae596f960b82d8c
  • alt-php74-gd-7.4.33-68.el6.x86_64.rpm
    sha:bdaa608c3294dde54b61e6a230d28f63a8181321cb284a26c16421cd10bac61f
  • alt-php74-imap-7.4.33-68.el6.x86_64.rpm
    sha:5c96f60c5f6f1886b51f55898746a0e9040c6433352a128998bfbf69942a7e67
  • alt-php74-intl-7.4.33-68.el6.x86_64.rpm
    sha:98631750fd37ec5faf52e19e00bd7fcc7c33503b1fb82d6db1c31c6d257e64fa
  • alt-php74-ldap-7.4.33-68.el6.x86_64.rpm
    sha:db219b863181d7c7b6cdd9bff482c15f87c38fcf4cbec1172d40afcddadfb27b
  • alt-php74-mbstring-7.4.33-68.el6.x86_64.rpm
    sha:9a2e0e24a4ec196a90b5b28bbb4a8b1e28a7969157d34a6507a0552cfffb4c13
  • alt-php74-mysqlnd-7.4.33-68.el6.x86_64.rpm
    sha:a5615cd2f150ed1b66a6402164f2587e03db1ef23441c1e47e26afced62a44d8
  • alt-php74-odbc-7.4.33-68.el6.x86_64.rpm
    sha:885702e461bbcffa1756f2741874170503965719a06967d69655feab00a40e06
  • alt-php74-opcache-7.4.33-68.el6.x86_64.rpm
    sha:dec55cefb527d7c01a78ceb293abc13004a16d35148ab311aa10347cb3e30b86
  • alt-php74-pdo-7.4.33-68.el6.x86_64.rpm
    sha:8ec2f98b156ba66b78817ac3451bdf85fc3c636cbbbe7870473807146cb2ec51
  • alt-php74-pgsql-7.4.33-68.el6.x86_64.rpm
    sha:4e5b1fc03b743d04b55430146b851f13d4986a5c5f7a0ed325bdada570feda93
  • alt-php74-php-fpm-7.4.33-68.el6.x86_64.rpm
    sha:2300a5d18658afef7158955c1545329c252f9b92294dde511a0cbe09c2f0a2e9
  • alt-php74-process-7.4.33-68.el6.x86_64.rpm
    sha:0227e6fd2cd97777aab1dc91e7b4de9475dbb7c544971b090af67896d6d6616e
  • alt-php74-pspell-7.4.33-68.el6.x86_64.rpm
    sha:73c308f20fca48d983e540bc93e45416aa864c100bf1b6de8cf1a3b86cf1149c
  • alt-php74-snmp-7.4.33-68.el6.x86_64.rpm
    sha:f9a789a32d549de7deb45cb862258a7fbf08f23440f7dc501f2d40c5ad9b01dd
  • alt-php74-soap-7.4.33-68.el6.x86_64.rpm
    sha:a015a01323479cc0e0dce835acd42fad2e9137131126cfcd56d1d61b73e41da0
  • alt-php74-sodium-7.4.33-68.el6.x86_64.rpm
    sha:0d78571d9154420606c6624c569d149b621b656f8ffe133da028f16f39baa368
  • alt-php74-tidy-7.4.33-68.el6.x86_64.rpm
    sha:d722335b65ebb06404263f493fbd6892054987e979704af680618fcfcfeb2e2c
  • alt-php74-xml-7.4.33-68.el6.x86_64.rpm
    sha:8926c65213ff40c7008501e63423f086f2188ec0b54ce81fbed919b89bbd06b9
  • alt-php74-xmlrpc-7.4.33-68.el6.x86_64.rpm
    sha:9af0f0d5ceaad354b2ced920d451e3840c4bfe6f2a8eea77d9ac257f565661e5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.