[CLSA-2026:1786016547] Fix CVE(s): CVE-2026-17543, CVE-2026-7260, CVE-2026-9672
Type:
security
Severity:
Critical
Release date:
2026-08-06 11:43:01 UTC
Description:
* CVE-2026-9672: fix three defects in the bundled libgd GIF LZW decoder reachable from attacker-controlled GIF data via imagecreatefromgif(). The table reset cleared sd->table[1][0] instead of sd->table[1][i], so stale suffixes leaked between images; LWZReadByte_() kept decoding with a stale code after the LZW end code when the trailing data block count was 0; and ReadImage() left LZW_STATIC_DATA uninitialised. * CVE-2026-17543: fix SQL injection in ext/pgsql. php_pgsql_add_quotes() wrapped PQescapeStringConn() output in an E'...' literal, but PQescapeStringConn() only doubles the single quote while standard_conforming_strings is on, so a trailing backslash escaped the closing quote and broke out of the literal in pg_convert()/pg_insert()/pg_update()/pg_select()/pg_delete(). Emit a plain '...' literal instead. * CVE-2026-7260: fix unbounded recursion in phar_get_link_source() on a circular symlink chain (GHSA-vc5h-9ppw-p5f3). The self-recursion is replaced by a Floyd cycle-detection walk that returns NULL for a cycle, including the phar_get_link_location() path-separator restore the walk depends on.
Updated packages:
  • alt-php72_7.2.34-89_amd64.deb
    sha:cabe0f5ec12186b81c3c15b71594ad533b38f994
  • alt-php72-bcmath_7.2.34-89_amd64.deb
    sha:7d5184cf2d789ed8f665bf6be268b22cbe5230df
  • alt-php72-cli_7.2.34-89_amd64.deb
    sha:3d3d51ac99c4d965d86b43da23acd3352c9ddb31
  • alt-php72-common_7.2.34-89_amd64.deb
    sha:65f5554625f532cef70f5ecc740029bd1b12a108
  • alt-php72-dba_7.2.34-89_amd64.deb
    sha:aa5305f10ae1b1f43d40e25ce4c7c65d6faf2803
  • alt-php72-dev_7.2.34-89_amd64.deb
    sha:496ca4b935558e2b4c42163aeb9ca711e63c7a1b
  • alt-php72-enchant_7.2.34-89_amd64.deb
    sha:5690ab77faae3715a0c6213d4ef5caf4fa1a266a
  • alt-php72-firebird_7.2.34-89_amd64.deb
    sha:a78490de28d99bb91c94f24361b56406de03eb17
  • alt-php72-gd_7.2.34-89_amd64.deb
    sha:8278405256b529604b4325e61c5d692c45b21255
  • alt-php72-imap_7.2.34-89_amd64.deb
    sha:13ccf48fcd057363ba8ec45f1317edd9ad6f1903
  • alt-php72-intl_7.2.34-89_amd64.deb
    sha:807e7233f3acce141d9eed8eae8de757479bfe87
  • alt-php72-ldap_7.2.34-89_amd64.deb
    sha:fde6b6da1a81286bbb6f522ac6ea9aed95380dfd
  • alt-php72-mbstring_7.2.34-89_amd64.deb
    sha:03b5f5771a7cce426056c71f476799f88f383c81
  • alt-php72-mysqlnd_7.2.34-89_amd64.deb
    sha:e1f320942d7670bc6c40a0b50d8dc22bb2e07458
  • alt-php72-odbc_7.2.34-89_amd64.deb
    sha:43d6c48643f43814607b6a371403ff94ebf3bf9c
  • alt-php72-opcache_7.2.34-89_amd64.deb
    sha:ca0309c62658d6959c4a9fdbf0b6d18c7f927d49
  • alt-php72-pdo_7.2.34-89_amd64.deb
    sha:f730a447aa956530544aac8cbff2ebb331d0c993
  • alt-php72-pgsql_7.2.34-89_amd64.deb
    sha:560598bad39d91f30852a3a727fbe2b285108db4
  • alt-php72-php-fpm_7.2.34-89_amd64.deb
    sha:a56349065aecd54f9f7ca05ccf1551b3f33060bc
  • alt-php72-process_7.2.34-89_amd64.deb
    sha:3513c6ee4f6b2a7d4a7fec2ef586636369ca16b2
  • alt-php72-pspell_7.2.34-89_amd64.deb
    sha:80d36d257f9999a4287347d5a1848f546c23c7e8
  • alt-php72-recode_7.2.34-89_amd64.deb
    sha:9ebdc59f9f37ca726f05afefb9e9526a66fcc15a
  • alt-php72-snmp_7.2.34-89_amd64.deb
    sha:7e46ae514f79174aa724b3a707be64f9586ca5e5
  • alt-php72-soap_7.2.34-89_amd64.deb
    sha:691aebf3aa49ef399c1eafcd5771a968caa73b9e
  • alt-php72-sodium_7.2.34-89_amd64.deb
    sha:0ae41efd9881e357c428bdae4042572a6bfeeec3
  • alt-php72-tidy_7.2.34-89_amd64.deb
    sha:82b14e10082ef71c8f536ced2b6f62c0c38e23ac
  • alt-php72-xml_7.2.34-89_amd64.deb
    sha:a14918c6d580858972d302aa679047c062e12de7
  • alt-php72-xmlrpc_7.2.34-89_amd64.deb
    sha:27344b72163dc0f18dbea661ab18518679aab869
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.