Release date:
2026-08-10 21:47:39 UTC
Description:
* SECURITY UPDATE: three defects in the bundled libgd GIF LZW decoder
- debian/patches/php-7.1-CVE-2026-9672.patch: backport upstream commit
fcd691b377 in ext/gd/libgd/gd_gif_in.c - reset sd->table[1][i] instead
of sd->table[1][0] so the suffix table is fully cleared between images,
stop decoding once the LZW end code is seen instead of falling through
with a stale code, and zero-initialise LZW_STATIC_DATA in ReadImage().
- CVE-2026-9672
* SECURITY UPDATE: SQL injection in ext/pgsql via an E'...' backslash
breakout
- debian/patches/php-7.1-CVE-2026-17543.patch: backport upstream commit
ab048bd83b in ext/pgsql/pgsql.c - php_pgsql_add_quotes() no longer
emits the E prefix, since PQescapeStringConn() only doubles the single
quote and a trailing backslash could therefore escape the closing
quote of an E'...' literal. Test expectations updated accordingly and
a regression test added.
- CVE-2026-17543
* SECURITY UPDATE: phar crash on circular symlinks
- debian/patches/php-7.1-CVE-2026-7260.patch: backport upstream commit
2e0fa0a444 in ext/phar/util.c - phar_get_link_source() follows the
link chain with Floyd cycle detection via a new
phar_follow_one_link() helper instead of recursing into itself until
the C stack is exhausted, and phar_get_link_location() restores the
path separator it temporarily overwrites in entry->filename.
- CVE-2026-7260
Updated packages:
-
alt-php71_7.1.33-105_amd64.deb
sha:a565974e674dc51dfd0b87bc3f466c60341185e6
-
alt-php71-bcmath_7.1.33-105_amd64.deb
sha:78f844bc2ad5a9697d5d0aa7ea6740e8a6546504
-
alt-php71-cli_7.1.33-105_amd64.deb
sha:b5223f5ae3d7ac9f639ebce85ef972f9e34ba397
-
alt-php71-common_7.1.33-105_amd64.deb
sha:787c3e12f047d6f0151ca5e894efc11fdbeff32a
-
alt-php71-dba_7.1.33-105_amd64.deb
sha:fe39d5ce7fa51588e0189a35f5179eaf09446ceb
-
alt-php71-dev_7.1.33-105_amd64.deb
sha:04d5182212eaa66ead7cac47400798fd0a313f7c
-
alt-php71-enchant_7.1.33-105_amd64.deb
sha:2ed6cc4690c73eabac1302c7427ca25feb2dc6b5
-
alt-php71-firebird_7.1.33-105_amd64.deb
sha:4e926941e63211f545cd71050a325c83e0f2c077
-
alt-php71-gd_7.1.33-105_amd64.deb
sha:cdb0c226f88681c08d8ca01bcd098d6b1fa664f0
-
alt-php71-imap_7.1.33-105_amd64.deb
sha:fc57c2970f144178c4bac53f6269cd372ab9c45e
-
alt-php71-intl_7.1.33-105_amd64.deb
sha:2c44ddaff9bbeec5bf1032b0c8af12040ca55974
-
alt-php71-ldap_7.1.33-105_amd64.deb
sha:47666e37d7c66fbd60765a7ce7f06ef21ea7c3c2
-
alt-php71-mbstring_7.1.33-105_amd64.deb
sha:df4fd1ea6280e3f4f1c8eb9786a9f33e21606fed
-
alt-php71-mcrypt_7.1.33-105_amd64.deb
sha:afe47760443d60a39f446e6906bd1a423b17e8e7
-
alt-php71-mysqlnd_7.1.33-105_amd64.deb
sha:aafd77a8214e64a96e70659e6e9c9ac07089b46e
-
alt-php71-odbc_7.1.33-105_amd64.deb
sha:051faa3c3d1a33cd2d3491ba9b8fbb2b5ceba7ed
-
alt-php71-opcache_7.1.33-105_amd64.deb
sha:1d63e1a0a2a17969d55005b42da9550feb5809ca
-
alt-php71-pdo_7.1.33-105_amd64.deb
sha:ef0b2686b14529d3c50c630165910a0b97b3557d
-
alt-php71-pgsql_7.1.33-105_amd64.deb
sha:2309c4d94f1c93c3f2717e32d514ccb41360c4aa
-
alt-php71-php-fpm_7.1.33-105_amd64.deb
sha:3ff9ace1e5cc0d945a6e87b655e547dfe964e95f
-
alt-php71-process_7.1.33-105_amd64.deb
sha:1c95ada148cb71dffe95e269d8c2891118553500
-
alt-php71-pspell_7.1.33-105_amd64.deb
sha:f1b4471a3cf19591f0815fa10fffb50492ffddc9
-
alt-php71-recode_7.1.33-105_amd64.deb
sha:3df23f75d0a9eb708900f51ea298b7f673313ab8
-
alt-php71-snmp_7.1.33-105_amd64.deb
sha:ad0e7bc7ddd06f4de0c47f1278e268782282396a
-
alt-php71-soap_7.1.33-105_amd64.deb
sha:f47dedf27899e740443a3112fd4559059926e058
-
alt-php71-tidy_7.1.33-105_amd64.deb
sha:367a7a2ce6b3f44a32a0724cbea0bc35ee2dbbd2
-
alt-php71-xml_7.1.33-105_amd64.deb
sha:2660a28ae05edc8b9d297cb87ddc628769230d5a
-
alt-php71-xmlrpc_7.1.33-105_amd64.deb
sha:4f1c6a736d29f7eddbc0e1857c35a8df44c1430e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.