[CLSA-2026:1786386058] alt-php80: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-10 18:21:44 UTC
Description:
- CVE-2026-17543: SQL injection in ext/pgsql. php_pgsql_add_quotes() wrapped PQescapeStringConn() output in an E'...' escape-string constant, where a trailing backslash escapes the doubling quote and breaks out of the literal; emit a plain '...' literal instead - CVE-2026-7260: stack exhaustion in ext/phar. phar_get_link_source() followed symlink chains by unbounded tail recursion, so a tar-based phar with circular symlinks crashed the process; walk the chain iteratively with Floyd cycle detection and return NULL on a loop
Updated packages:
  • alt-php80-8.0.30-58.el9.x86_64.rpm
    sha:f0a9e27b9b85a0a5e565121b6a5f75eedfdf4e311244867318167f959da11f6d
  • alt-php80-bcmath-8.0.30-58.el9.x86_64.rpm
    sha:99b3278346569dcd6839de770e792c06102eec051aa9bfe3626f97e4700fb1b7
  • alt-php80-cli-8.0.30-58.el9.x86_64.rpm
    sha:f5f26d9b34eb08fe2628a4697df7fee8e06ef806d226322d12382a13bbac7d62
  • alt-php80-common-8.0.30-58.el9.x86_64.rpm
    sha:d601e430b2a96395c62a6ba7bcdcd438bd181d1756c528528036fd5d9d400dcd
  • alt-php80-dba-8.0.30-58.el9.x86_64.rpm
    sha:ceae7d29c4895f29479e17fd677f491dc6b75df1f0d417399d5bc4c7ca0edf56
  • alt-php80-devel-8.0.30-58.el9.x86_64.rpm
    sha:ab2546bc18add2a337589cfe30b05ca6b53d4c7050e18a95fea538a004d6293e
  • alt-php80-enchant-8.0.30-58.el9.x86_64.rpm
    sha:cb0a4862669a07fdd907483bf570b181f692adccd0aa88d83cdb368027d7a187
  • alt-php80-firebird-8.0.30-58.el9.x86_64.rpm
    sha:e306dcbda7bcb0289a976779c393d0994469ec80cb4559e7199c0ef1cb46428b
  • alt-php80-gd-8.0.30-58.el9.x86_64.rpm
    sha:6edb830db05fe9ae2be30a69ad76b2d68487d1d8819d7853e1b8c257e86209cc
  • alt-php80-imap-8.0.30-58.el9.x86_64.rpm
    sha:149db300b49a2aeb2c12954f848e6a7b701eb85ae7329c8d3bfb7e0ae78eeae5
  • alt-php80-intl-8.0.30-58.el9.x86_64.rpm
    sha:ed6b37f09bdb224d4406a7d0dbdd694f8ebaa5f3ac72fac0b0cac1eb36a75bd6
  • alt-php80-ldap-8.0.30-58.el9.x86_64.rpm
    sha:fb3cdcda96362457fcfcd0cc651fa399a3fd2fe4c7f1ddc7f97acf5847160e27
  • alt-php80-mbstring-8.0.30-58.el9.x86_64.rpm
    sha:6d7813dc0f068bcf03fa1733ec3b18c973f27e9d2e480672644c05f8dc798738
  • alt-php80-mysqlnd-8.0.30-58.el9.x86_64.rpm
    sha:38b6554c52548b3b2362c15abee6c4788a4530ac72951efd2f03cbf1d973c604
  • alt-php80-odbc-8.0.30-58.el9.x86_64.rpm
    sha:d288c7458018b1f710978a23ed7e132ccd0465d5e752e20e8abc243663409c30
  • alt-php80-opcache-8.0.30-58.el9.x86_64.rpm
    sha:765dc09b92a2f08a75227f39acbcb361a6e949af9dd89cea8eeeac3496e3e376
  • alt-php80-pdo-8.0.30-58.el9.x86_64.rpm
    sha:33b71bc39b053695855b4453f606718283a0497afced3976ba7a931d8bab4df9
  • alt-php80-pgsql-8.0.30-58.el9.x86_64.rpm
    sha:48ddb5f24709b194f57be6e783bc2f7b2cf351b3b29f3a5ffc9b9fb3287026ac
  • alt-php80-php-fpm-8.0.30-58.el9.x86_64.rpm
    sha:ca3dc1ef2e5f0822136fb26e5d71dff6e144f8c17afab5ff0fcc71a6efc0816a
  • alt-php80-process-8.0.30-58.el9.x86_64.rpm
    sha:d60f0ea8b91195aa9a6a936e8e19b5522503604f1c6d1dd07b916cb1b7ead862
  • alt-php80-pspell-8.0.30-58.el9.x86_64.rpm
    sha:863d9429cb7bfa3894332b9849fca0b6ae644a652c4bbc3cbdf03ad27e9e45a5
  • alt-php80-snmp-8.0.30-58.el9.x86_64.rpm
    sha:d98ce37ceaf767c494b16a462b403872de2f6ec0df668442a6700472a4283d14
  • alt-php80-soap-8.0.30-58.el9.x86_64.rpm
    sha:66160c578537f491737963e35a4f8328c27c5af1d3a41cb6b036f1a4d875001f
  • alt-php80-sodium-8.0.30-58.el9.x86_64.rpm
    sha:6e0136ee65c2df3ed4dc127251494d0266ebceb6434799b8bf9bc210ad8e285a
  • alt-php80-tidy-8.0.30-58.el9.x86_64.rpm
    sha:9f48d6f5d5417a6193043d450f9dc38cc85e275573bc0878bb953bcdc6fb9af1
  • alt-php80-xml-8.0.30-58.el9.x86_64.rpm
    sha:d1162b5527c4e20b194ca6ff4c4c5b8de4ff0323e2eee8dbff797871ba150b9a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.