[CLSA-2026:1786447403] php: Fix of 3 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-11 11:23:33 UTC
Description:
- CVE-2026-7260: fix stack exhaustion on circular symlinks in tar-based phar archives; also backport upstream bug #69720 (NULL pointer dereference in phar_get_fp_offset()), without which the fix only relocates the crash - CVE-2026-17543: fix SQL injection in ext/pgsql via backslash breakout from E'...' literals - CVE-2026-9672: fix bundled libgd GIF decoder LZW table reset, end-code handling and uninitialised state
Updated packages:
  • php-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:9e4a020b6b40caf7c99ea90fde6206fdfbb8eba86df255ac9924f6fe78db309b
  • php-bcmath-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:f8a8c08ad21d74e27aba239dbd3072842c58f971b4ee38f306b8cb6c1324278e
  • php-cli-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:5dbb1844165351852521656e05c5f3efe21b3e2a73c8481ffc17edf60d8d42be
  • php-common-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:dcd89d2a2d4836a7a73b9a658335052ad5975e777a9025b8205c550946e96b97
  • php-dba-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:52d2880cea2d71fa69d2d7afc4c408692ab057daf0387feea9df43ac252d6ae3
  • php-devel-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:084c484bd6a4a89908f095889f62a58d5d97489aa7200910b8feca78097d7e64
  • php-embedded-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:9da26e55ad9713323cc202094c26e8641c64f0e87bf804f81d820a4c016327ac
  • php-enchant-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:665c2074722609ebd588eff603ebd41cefdbcbe6fe4d871bb98c287be5944c6f
  • php-fpm-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:cbad831cf8b30fdaa93cac2a337f80bc5f61ae943ae9a5036450484ed4d5dce4
  • php-gd-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:33981c3a32e41fa00c05d739303a6bd8f7d539a0c87798b77adbb75b44614563
  • php-intl-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:e40c26447b38b2235d11dadecd2852fdfc0a1fe1ae58e0c6d3c336dada97eceb
  • php-ldap-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:4af7709765cd132c66155b3df341ce21fa1e7018f0c15b9a238c7a83966b218d
  • php-mbstring-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:4e57731e61f51f3ef10ff735a36968bf4f866d9f820f058eea3e4954cafac708
  • php-mysql-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:8c75842f89814ff00727dfa1d2c6315165a425b7a7f51643fc09c4fac6f732d6
  • php-mysqlnd-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:ca24b51806065a377a1e0f45136597b9336706837bb7827951f811d9889a332e
  • php-odbc-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:73960f9818dd4f40c15c916f3ed0d858722ce23a9de3f4bccc8d3d120f2a01aa
  • php-pdo-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:d9e8beedfdcc3ef3bdde19f3a3190c7ca8a6ea247111d9a877ce7223b80fdba6
  • php-pgsql-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:73cce6e14ab6d6fdc33afb4cc39275bd00315df02f40ae603d06b4ba00ba19ce
  • php-process-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:be03779c0485e50db084f140c121942eee444b21870c3cc3196ea4841843482b
  • php-pspell-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:d313ac72f9fece7143b76107500a2a8db355152b586d1082715989d3577d5186
  • php-recode-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:926595518484a058dfacfa10c8c2d13349325721f299b063370d0c74d734d247
  • php-snmp-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:5ce42299f90569d1853775a1ce32c85f1ae3d4fdfdae8192f70b109ee959ef98
  • php-soap-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:b851e4a31e4ca9bef2b7eb306c943cef764e454ce105d08e00b397cee275a847
  • php-xml-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:120dfd8759d576803bfe3c84bd7be4e31e662bcbbe0bfc3e16304c3e8f4bb581
  • php-xmlrpc-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:723dd079aa46adb44ac32eb6136bbd30cea116c7fd6ef32c02a0c88020926489
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.