[CLSA-2026:1786524655] Fix CVE(s): CVE-2026-17543, CVE-2026-7260, CVE-2026-9672
Type:
security
Severity:
Critical
Release date:
2026-08-12 08:51:06 UTC
Description:
* CVE-2026-9672: three defects in the GIF LZW decoder of the bundled libgd - the code-table reset loop wrote sd->table[1][0] instead of sd->table[1][i] so most of table[1] kept stale data, LWZReadByte_() kept decoding past the end-of-information code when the trailing data blocks drained cleanly, and ReadImage() left its LZW_STATIC_DATA uninitialised on the stack * CVE-2026-17543: SQL injection in ext/pgsql - php_pgsql_add_quotes() wrapped values in an E'...' literal, in which the backslash left unescaped by PQescapeStringConn() (the default standard_conforming_strings=on doubles only the quote) escapes the following quote and lets a payload break out; pg_convert(), pg_insert(), pg_update(), pg_delete() and pg_select() are affected. Now quoted with a plain '...' literal * CVE-2026-7260: unbounded recursion in phar_get_link_source() when a tar-based phar archive contains a circular symlink chain; resolution is now an iterative walk with Floyd cycle detection, returning NULL on a cycle
Updated packages:
  • alt-php70_7.0.33-140_amd64.deb
    sha:6979b3fba87cfb30261093872aa58602e8570576
  • alt-php70-bcmath_7.0.33-140_amd64.deb
    sha:3c4c75a2e3851882dee19691426fc0ce12e7d352
  • alt-php70-cli_7.0.33-140_amd64.deb
    sha:22dab57d59a1a6c378c45d70f04492ad5b9f01dc
  • alt-php70-common_7.0.33-140_amd64.deb
    sha:0d9bb2e3d42040ccfa9ba2b1f93a332acd3c9a1b
  • alt-php70-dba_7.0.33-140_amd64.deb
    sha:c95c5a62d8e366c9642afbf95886625c517d9233
  • alt-php70-dev_7.0.33-140_amd64.deb
    sha:2668ac25b4d42ed16f2216b6712151ed88b990fe
  • alt-php70-enchant_7.0.33-140_amd64.deb
    sha:851560e069a367ffe6a345928266d5a9bc43928a
  • alt-php70-firebird_7.0.33-140_amd64.deb
    sha:040f44e349c8d62cb476f8cc4055bc74e464d34d
  • alt-php70-gd_7.0.33-140_amd64.deb
    sha:fa3c80fcfb8236002df60616a39107e9d486dc81
  • alt-php70-imap_7.0.33-140_amd64.deb
    sha:d7b97a9fb040d720354ea830282fc3971c94d8e3
  • alt-php70-intl_7.0.33-140_amd64.deb
    sha:40bd6eb677bef47cc904d2a5e696f1a844862067
  • alt-php70-ldap_7.0.33-140_amd64.deb
    sha:e4f12bf7b122342e1c29bbe6544550ce58cf87dc
  • alt-php70-mbstring_7.0.33-140_amd64.deb
    sha:ddcfb217c03b2f7cc490ee3ec156b2dace8831b2
  • alt-php70-mcrypt_7.0.33-140_amd64.deb
    sha:2e1c53b75f55d96d525f15191dfac37cae2e5d36
  • alt-php70-mysqlnd_7.0.33-140_amd64.deb
    sha:29d2034365b3ab539d770447fe94e6e6557d0cb9
  • alt-php70-odbc_7.0.33-140_amd64.deb
    sha:24e43577ce7634e4d5c72271e76c941c4549b41c
  • alt-php70-opcache_7.0.33-140_amd64.deb
    sha:8234036d70a245b8d3019b876c923c1fa5385dce
  • alt-php70-pdo_7.0.33-140_amd64.deb
    sha:7fbe39383030bc743146a3cc2657c03a37c2f09c
  • alt-php70-pgsql_7.0.33-140_amd64.deb
    sha:debb680adb1b18ad5b91922341b12103447c4303
  • alt-php70-php-fpm_7.0.33-140_amd64.deb
    sha:23df9e1f0de10d295c0fe74898bfede7f730ed06
  • alt-php70-process_7.0.33-140_amd64.deb
    sha:19346a679ce991de93805f4342857f170e20b7b2
  • alt-php70-pspell_7.0.33-140_amd64.deb
    sha:6cdd5bc9c371348c6b6ec4085a35f7fb83c872cc
  • alt-php70-recode_7.0.33-140_amd64.deb
    sha:c9e41627e07a76b52e8ad2a04a61691a9525f681
  • alt-php70-snmp_7.0.33-140_amd64.deb
    sha:d08e943632f6581013c7ccc47a7d0fad78567e8b
  • alt-php70-soap_7.0.33-140_amd64.deb
    sha:d29df59beb98b472a026dfe59a2577a30c4c0f69
  • alt-php70-tidy_7.0.33-140_amd64.deb
    sha:32dad8049b662e6243e2231690c6a46f81493443
  • alt-php70-xml_7.0.33-140_amd64.deb
    sha:d4593140c695846114c1bc2249de270276a8be42
  • alt-php70-xmlrpc_7.0.33-140_amd64.deb
    sha:b14d2e6b23ee6b43c3cd4b398450557b9581c85f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.