Release date:
2026-08-06 11:15:08 UTC
Description:
* CVE-2026-9672: fix three defects in the bundled libgd GIF LZW decoder reachable from attacker-controlled GIF data via imagecreatefromgif(). The table reset cleared sd->table[1][0] instead of sd->table[1][i], so stale suffixes leaked between images; LWZReadByte_() kept decoding with a stale code after the LZW end code when the trailing data block count was 0; and ReadImage() left LZW_STATIC_DATA uninitialised.
* CVE-2026-17543: fix SQL injection in ext/pgsql. php_pgsql_add_quotes() wrapped PQescapeStringConn() output in an E'...' literal, but PQescapeStringConn() only doubles the single quote while standard_conforming_strings is on, so a trailing backslash escaped the closing quote and broke out of the literal in pg_convert()/pg_insert()/pg_update()/pg_select()/pg_delete(). Emit a plain '...' literal instead.
* CVE-2026-7260: fix unbounded recursion in phar_get_link_source() on a circular symlink chain (GHSA-vc5h-9ppw-p5f3). The self-recursion is replaced by a Floyd cycle-detection walk that returns NULL for a cycle, including the phar_get_link_location() path-separator restore the walk depends on.
Updated packages:
-
alt-php72_7.2.34-89_amd64.deb
sha:5c83a9cd816c98512e37ba04ac67b3c02ada5848
-
alt-php72-bcmath_7.2.34-89_amd64.deb
sha:ed10d75e7b23ee2702440d586acaacf71fd3a513
-
alt-php72-cli_7.2.34-89_amd64.deb
sha:f162eae78e26e9687fe1970aef32a208732e4254
-
alt-php72-common_7.2.34-89_amd64.deb
sha:85b308e836f0096d21c75284e6256e40b2fd6ca5
-
alt-php72-dba_7.2.34-89_amd64.deb
sha:3221e5266380f4c60980d546a6fcd017a82a520d
-
alt-php72-dev_7.2.34-89_amd64.deb
sha:40e2f39b969f1523ae38e086d5aa6cfb4d250424
-
alt-php72-enchant_7.2.34-89_amd64.deb
sha:76482bcdd8b20e1b37a4e309498aec73804eea45
-
alt-php72-firebird_7.2.34-89_amd64.deb
sha:b6a3d6059eac43ea4d3a49a253c58ee8fb45f900
-
alt-php72-gd_7.2.34-89_amd64.deb
sha:627d771a4a25ce4a43b30292c19c9d411cf0db02
-
alt-php72-imap_7.2.34-89_amd64.deb
sha:de8ce694843fe6708c8e28c02f42f77a43b736e2
-
alt-php72-intl_7.2.34-89_amd64.deb
sha:83004b1ed45ef08f018d25ea65dc03c08b8475e8
-
alt-php72-ldap_7.2.34-89_amd64.deb
sha:41732c883fe8df0df5ebc969999bdb0402126285
-
alt-php72-mbstring_7.2.34-89_amd64.deb
sha:31eff8b56647516356c76cf0488dd020d9044c08
-
alt-php72-mysqlnd_7.2.34-89_amd64.deb
sha:fae719caa292f64948aff570911b2e8046436e3e
-
alt-php72-odbc_7.2.34-89_amd64.deb
sha:a76939b7786ee5ee58b593d953d529d391a06b70
-
alt-php72-opcache_7.2.34-89_amd64.deb
sha:6c21bb5e1ca2fc703951884cb452d0cb24694deb
-
alt-php72-pdo_7.2.34-89_amd64.deb
sha:f52067280a242308c8fd688db051bc7f41af69a1
-
alt-php72-pgsql_7.2.34-89_amd64.deb
sha:5f4e3a1d3f2726b760ae3fbaa3c0fee6ca2fe28d
-
alt-php72-php-fpm_7.2.34-89_amd64.deb
sha:2cb87a82cca134fc7cedaee3b8a84ffe7ee21610
-
alt-php72-process_7.2.34-89_amd64.deb
sha:3c88e42afe36b0667e9305644e6cfb79476537b1
-
alt-php72-pspell_7.2.34-89_amd64.deb
sha:100d648050377481c2bdb19a0951c8b1c6ecc24d
-
alt-php72-recode_7.2.34-89_amd64.deb
sha:345e4309d1a393d41560ce7ff6ed9975ebd1f26d
-
alt-php72-snmp_7.2.34-89_amd64.deb
sha:872b2c2a95d105474e576e11c1e7845dc5d13818
-
alt-php72-soap_7.2.34-89_amd64.deb
sha:abc5ebed87ac0b1e47ac5a2105fe35dc1e5809b2
-
alt-php72-sodium_7.2.34-89_amd64.deb
sha:9fec1e79e73f4bab5fb1c1020320e44b9126abbb
-
alt-php72-tidy_7.2.34-89_amd64.deb
sha:91283945a401286ceb4183ec2a09fadf12b9ccb0
-
alt-php72-xml_7.2.34-89_amd64.deb
sha:7a266bd0c26136c06e48da4a8467495a8d55bc59
-
alt-php72-xmlrpc_7.2.34-89_amd64.deb
sha:06755f15d0a9d36077ea303788eee406117053ea
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.