Release date:
2026-08-10 21:37:32 UTC
Description:
* SECURITY UPDATE: three defects in the bundled libgd GIF LZW decoder
- debian/patches/php-7.1-CVE-2026-9672.patch: backport upstream commit
fcd691b377 in ext/gd/libgd/gd_gif_in.c - reset sd->table[1][i] instead
of sd->table[1][0] so the suffix table is fully cleared between images,
stop decoding once the LZW end code is seen instead of falling through
with a stale code, and zero-initialise LZW_STATIC_DATA in ReadImage().
- CVE-2026-9672
* SECURITY UPDATE: SQL injection in ext/pgsql via an E'...' backslash
breakout
- debian/patches/php-7.1-CVE-2026-17543.patch: backport upstream commit
ab048bd83b in ext/pgsql/pgsql.c - php_pgsql_add_quotes() no longer
emits the E prefix, since PQescapeStringConn() only doubles the single
quote and a trailing backslash could therefore escape the closing
quote of an E'...' literal. Test expectations updated accordingly and
a regression test added.
- CVE-2026-17543
* SECURITY UPDATE: phar crash on circular symlinks
- debian/patches/php-7.1-CVE-2026-7260.patch: backport upstream commit
2e0fa0a444 in ext/phar/util.c - phar_get_link_source() follows the
link chain with Floyd cycle detection via a new
phar_follow_one_link() helper instead of recursing into itself until
the C stack is exhausted, and phar_get_link_location() restores the
path separator it temporarily overwrites in entry->filename.
- CVE-2026-7260
Updated packages:
-
alt-php71_7.1.33-105_amd64.deb
sha:d7ee6e31a1e7b59cbcd71bd6b47b1335c2cd788c
-
alt-php71-bcmath_7.1.33-105_amd64.deb
sha:a41110374b1ea857901fe111d96d5bd52423ec05
-
alt-php71-cli_7.1.33-105_amd64.deb
sha:925875e6416db25de54bc919c1594ebe0b66d39a
-
alt-php71-common_7.1.33-105_amd64.deb
sha:e0d0052746fa83b5be54c5a152969ab0d6ce2a5a
-
alt-php71-dba_7.1.33-105_amd64.deb
sha:70bdf4df497eff74f54668a52a31819ac9a1b359
-
alt-php71-dev_7.1.33-105_amd64.deb
sha:ce5348246738bd353211314873dced19bd99a10e
-
alt-php71-enchant_7.1.33-105_amd64.deb
sha:b0a0b68f05e8d1a311a1bbf39d78491ab8a50ec3
-
alt-php71-firebird_7.1.33-105_amd64.deb
sha:e8cc25441f3351a7ede9c33c01321bdf5e6c85ea
-
alt-php71-gd_7.1.33-105_amd64.deb
sha:31c31ba6c20e9a41a0943289d6c87a2d63445a53
-
alt-php71-imap_7.1.33-105_amd64.deb
sha:473945eccca7dc82e7a8b6d407fb2e01cab9b95c
-
alt-php71-intl_7.1.33-105_amd64.deb
sha:e3994f9b16cc90e88ee3d652c20d5594ef62cfd7
-
alt-php71-ldap_7.1.33-105_amd64.deb
sha:25c9ce9815cfbd23a8c7ef497a802a49d85c1a80
-
alt-php71-mbstring_7.1.33-105_amd64.deb
sha:188260c915e9d609c70b526759c05bfd9bbbc6db
-
alt-php71-mcrypt_7.1.33-105_amd64.deb
sha:f252086ed35da4a2e501b5f8effc0a3988ef08a8
-
alt-php71-mysqlnd_7.1.33-105_amd64.deb
sha:f2fb4752cb7e0eda7235e149c8e22a52cd9dc1b7
-
alt-php71-odbc_7.1.33-105_amd64.deb
sha:7b47d4d1780910fcb2639b82f2af018cc47d6aab
-
alt-php71-opcache_7.1.33-105_amd64.deb
sha:9d550e4f6c51321085ee4e0c9ccdd9637e977e6c
-
alt-php71-pdo_7.1.33-105_amd64.deb
sha:438916e236b542cec782ad11185dcfbbe6da3bb6
-
alt-php71-pgsql_7.1.33-105_amd64.deb
sha:1ae012ced1b286b614cea126b5c155c1564bce37
-
alt-php71-php-fpm_7.1.33-105_amd64.deb
sha:ab301204fa62b602361b35dd063ccd5b516c15a0
-
alt-php71-process_7.1.33-105_amd64.deb
sha:da9bc57f15aadd2bedbfb1aa87ae6412796c3b7a
-
alt-php71-pspell_7.1.33-105_amd64.deb
sha:292fd7ac9761ffbff2b4040a6d02f9bc4788e8d5
-
alt-php71-recode_7.1.33-105_amd64.deb
sha:4b33dd8d3e3c21651c8c40a2df26899ae023b16f
-
alt-php71-snmp_7.1.33-105_amd64.deb
sha:3f6c0ab836442da31670f5399ddcf302a792e8b4
-
alt-php71-soap_7.1.33-105_amd64.deb
sha:f5e10559f991e81c99f0068aa5a683606bce47c7
-
alt-php71-tidy_7.1.33-105_amd64.deb
sha:45094b24ca3e463b70f1b2f7a02b0762f911963c
-
alt-php71-xml_7.1.33-105_amd64.deb
sha:ff7fb6467f91353f763293b2fdf0452543d505ed
-
alt-php71-xmlrpc_7.1.33-105_amd64.deb
sha:e70b82cc594ff3c567f0113b726eaf74b06c68c2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.