[CLSA-2026:1786447704] php: Fix of 3 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-11 11:28:34 UTC
Description:
- CVE-2026-7260: fix stack exhaustion on circular symlinks in tar-based phar archives; also backport upstream bug #69720 (NULL pointer dereference in phar_get_fp_offset()), without which the fix only relocates the crash - CVE-2026-17543: fix SQL injection in ext/pgsql via backslash breakout from E'...' literals - CVE-2026-9672: fix bundled libgd GIF decoder LZW table reset, end-code handling and uninitialised state
Updated packages:
  • php-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:9c1224fb6a73a465b8bb099c743be01defb363512ec211d685046ef3e8b05d7c
  • php-bcmath-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:59db9021039fe714f595e41d43edfb879eb12ccfb49500577fa242f9a376b390
  • php-cli-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:14e6f27df7740915b51cefc25d237c2ee9715a2ada5d00f8ac26e31d2c47c094
  • php-common-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:95b8d5b5e18703b3916b236a04c517407af8e0631b2e936f9b9209b00d583a4d
  • php-dba-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:d8bf5a0449063f2a0b9acd75f4260e85b5abd044615f6290023a44eb20ed0d21
  • php-devel-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:1ab0c500c571d50918106f5ec5d3f7cbd56ed9dd4f3db5fa2ec04675b4b083bd
  • php-embedded-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:f28500114331901361bbf26969a7f889b300a43870807360ec464c589de4d8c1
  • php-enchant-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:d35fb8efd682aeabdc2c4414fc2c38956595c63acd51d4b520ecf08450df20ce
  • php-fpm-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:83969d1bd68203425ac6f9ec8ada290f477b8da97c899ea4e24275536a7ae237
  • php-gd-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:02d936dda6384ecf683fd9975e8494b70b254058c8eecc2752d0334a143dac19
  • php-intl-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:ed44addc3b99713929bbd7b2beb718ea0b64a6eb19684070836273312ae57593
  • php-ldap-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:e0bc08082dca956681888234c3574ba3c5c81af5762cee02eaab8ea2652876e9
  • php-mbstring-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:f903648fbfef0e5323701ab0d6d07281e9e966628614c0da4a62bf59221d2cde
  • php-mysql-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:414472836586fbe517a7a5d93e92b32271b655af9f51aea871858ff999eae1b6
  • php-mysqlnd-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:729223e9d01352d942e23db5bcad71bd5eb0008150d1f45226731b6fa512dd3e
  • php-odbc-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:323d78a6fcda601e703f89ab023640218bce5a0d445127b1dfd8871b91e93684
  • php-pdo-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:5a8432593b7c8cef4ea76a387709012cffbfa5367813a86cd094880ed20cc04b
  • php-pgsql-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:9f486c6c6971a07579bd8bad8833867ee9265cdb647627cc54474ba6a2fec959
  • php-process-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:4afbc181eb30482f7a65dd57d96705565a7379e5b126ebf621664f01b5cdebb2
  • php-pspell-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:2672cd68875ab2b2c8335f62665dc1befb335cc41ebb2dedc3f72cf30cf1d5c0
  • php-recode-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:5efa13337b453c293dc3e20db9d84a90651e362b47de68dad58835b5ecca2c71
  • php-snmp-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:80f06407952548d1bc5eac30f55da093f4fd71327c61088ec662e59c91db706c
  • php-soap-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:6f0b19b5d2bcc75438a2912de48175f91bdb2cb722b219a6470ee8663b3306e6
  • php-xml-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:67c5f54dbe515b8d4b02a289e321f3f8684a43257fb6d5d1475046cfe07b5f71
  • php-xmlrpc-5.4.16-48.el7.tuxcare.els19.x86_64.rpm
    sha:f3011c196fbe91f81a01d96531f3cab96eb3c423f1fdb5c7bc747e6abf9f8a11
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.