Описание
ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW)
php [8.2.32-1]
- rebase to 8.2.32
php-pecl-apcu [5.1.23-1]
- update to 5.1.23 for PHP 8.2 RHEL-14699
php-pecl-rrd [2.0.3-4]
- build for PHP 8.1 #2070040
[2.0.3-3]
- Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688
[2.0.3-2]
- Rebuilt for RHEL 9 BETA for openssl 3.0 Related: rhbz#1971065
[2.0.3-1]
- update to 2.0.3
[2.0.2-1]
- update to 2.0.2
[2.0.1-17]
- Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937
[2.0.1-16]
[2.0.1-15]
php-pecl-xdebug3 [3.2.2-2]
- drop inet_ntoa usage using upstream patch
[3.2.2-1]
- update to 3.2.2 for PHP 8.2 RHEL-14699
php-pecl-zip [1.22.3-1]
- update to 1.22.3 for PHP 8.2 RHEL-14699
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
Module php:8.2 is enabled
php
8.2.32-1.module+el9.8.0+90965+26b10baf
php-bcmath
8.2.32-1.module+el9.8.0+90965+26b10baf
php-cli
8.2.32-1.module+el9.8.0+90965+26b10baf
php-common
8.2.32-1.module+el9.8.0+90965+26b10baf
php-dba
8.2.32-1.module+el9.8.0+90965+26b10baf
php-dbg
8.2.32-1.module+el9.8.0+90965+26b10baf
php-devel
8.2.32-1.module+el9.8.0+90965+26b10baf
php-embedded
8.2.32-1.module+el9.8.0+90965+26b10baf
php-enchant
8.2.32-1.module+el9.8.0+90965+26b10baf
php-ffi
8.2.32-1.module+el9.8.0+90965+26b10baf
php-fpm
8.2.32-1.module+el9.8.0+90965+26b10baf
php-gd
8.2.32-1.module+el9.8.0+90965+26b10baf
php-gmp
8.2.32-1.module+el9.8.0+90965+26b10baf
php-intl
8.2.32-1.module+el9.8.0+90965+26b10baf
php-ldap
8.2.32-1.module+el9.8.0+90965+26b10baf
php-mbstring
8.2.32-1.module+el9.8.0+90965+26b10baf
php-mysqlnd
8.2.32-1.module+el9.8.0+90965+26b10baf
php-odbc
8.2.32-1.module+el9.8.0+90965+26b10baf
php-opcache
8.2.32-1.module+el9.8.0+90965+26b10baf
php-pdo
8.2.32-1.module+el9.8.0+90965+26b10baf
php-pgsql
8.2.32-1.module+el9.8.0+90965+26b10baf
php-process
8.2.32-1.module+el9.8.0+90965+26b10baf
php-snmp
8.2.32-1.module+el9.8.0+90965+26b10baf
php-soap
8.2.32-1.module+el9.8.0+90965+26b10baf
php-xml
8.2.32-1.module+el9.8.0+90965+26b10baf
apcu-panel
5.1.23-1.module+el9.4.0+90261+af5cc950
php-pecl-apcu
5.1.23-1.module+el9.4.0+90261+af5cc950
php-pecl-apcu-devel
5.1.23-1.module+el9.4.0+90261+af5cc950
php-pecl-rrd
2.0.3-4.module+el9.4.0+90261+af5cc950
php-pecl-xdebug3
3.2.2-2.module+el9.4.0+90261+af5cc950
php-pecl-zip
1.22.3-1.module+el9.4.0+90261+af5cc950
Oracle Linux x86_64
Module php:8.2 is enabled
apcu-panel
5.1.23-1.module+el9.4.0+90261+af5cc950
php
8.2.32-1.module+el9.8.0+90965+26b10baf
php-bcmath
8.2.32-1.module+el9.8.0+90965+26b10baf
php-cli
8.2.32-1.module+el9.8.0+90965+26b10baf
php-common
8.2.32-1.module+el9.8.0+90965+26b10baf
php-dba
8.2.32-1.module+el9.8.0+90965+26b10baf
php-dbg
8.2.32-1.module+el9.8.0+90965+26b10baf
php-devel
8.2.32-1.module+el9.8.0+90965+26b10baf
php-embedded
8.2.32-1.module+el9.8.0+90965+26b10baf
php-enchant
8.2.32-1.module+el9.8.0+90965+26b10baf
php-ffi
8.2.32-1.module+el9.8.0+90965+26b10baf
php-fpm
8.2.32-1.module+el9.8.0+90965+26b10baf
php-gd
8.2.32-1.module+el9.8.0+90965+26b10baf
php-gmp
8.2.32-1.module+el9.8.0+90965+26b10baf
php-intl
8.2.32-1.module+el9.8.0+90965+26b10baf
php-ldap
8.2.32-1.module+el9.8.0+90965+26b10baf
php-mbstring
8.2.32-1.module+el9.8.0+90965+26b10baf
php-mysqlnd
8.2.32-1.module+el9.8.0+90965+26b10baf
php-odbc
8.2.32-1.module+el9.8.0+90965+26b10baf
php-opcache
8.2.32-1.module+el9.8.0+90965+26b10baf
php-pdo
8.2.32-1.module+el9.8.0+90965+26b10baf
php-pecl-apcu
5.1.23-1.module+el9.4.0+90261+af5cc950
php-pecl-apcu-devel
5.1.23-1.module+el9.4.0+90261+af5cc950
php-pecl-rrd
2.0.3-4.module+el9.4.0+90261+af5cc950
php-pecl-xdebug3
3.2.2-2.module+el9.4.0+90261+af5cc950
php-pecl-zip
1.22.3-1.module+el9.4.0+90261+af5cc950
php-pgsql
8.2.32-1.module+el9.8.0+90965+26b10baf
php-process
8.2.32-1.module+el9.8.0+90965+26b10baf
php-snmp
8.2.32-1.module+el9.8.0+90965+26b10baf
php-soap
8.2.32-1.module+el9.8.0+90965+26b10baf
php-xml
8.2.32-1.module+el9.8.0+90965+26b10baf
Связанные CVE
Связанные уязвимости
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...