Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-48197

Опубликовано: 07 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-48197: php:8.3 security, bug fix, and enhancement update (LOW)

php [8.3.32-1]

  • rebase to 8.3.32

php-pecl-apcu [5.1.23-1]

  • update to 5.1.23 for PHP 8.2 RHEL-14699

[5.1.21-1]

  • update to 5.1.21 for PHP 8.1 #2070040

php-pecl-redis6 [6.1.0-3]

  • use valkey for tests

[6.1.0-2]

  • ignore 1 ONLINE test

[6.1.0-1]

  • RHEL build

[6.1.0-1]

  • update to 6.1.0
  • drop patch merged upstream

[6.1.0~RC2-1]

[6.0.2-3]

  • cleanup and modernize spec file

[6.0.2-2]

  • use valkey on Fedora 41
  • add upstream patch for PHP 8.4

php-pecl-rrd [2.0.3-4]

  • build for PHP 8.1 #2070040

[2.0.3-3]

  • Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688

[2.0.3-2]

  • Rebuilt for RHEL 9 BETA for openssl 3.0 Related: rhbz#1971065

[2.0.3-1]

  • update to 2.0.3

[2.0.2-1]

  • update to 2.0.2

[2.0.1-17]

  • Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937

[2.0.1-16]

[2.0.1-15]

php-pecl-xdebug3 [3.3.1-1]

  • update to 3.3.1 for PHP 8.3

[3.2.2-2]

  • drop inet_ntoa usage using upstream patch

[3.2.2-1]

  • update to 3.2.2 for PHP 8.2 RHEL-14699

php-pecl-zip [1.22.3-1]

  • update to 1.22.3 for PHP 8.2 RHEL-14699

[1.20.1-1]

  • update to 1.20.1 for PHP 8.1 #2070040

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

Module php:8.3 is enabled

apcu-panel

5.1.23-1.module+el9.8.0+90982+92b8b4c7

php

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-bcmath

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-cli

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-common

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-dba

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-dbg

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-devel

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-embedded

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-enchant

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-ffi

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-fpm

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-gd

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-gmp

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-intl

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-ldap

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-mbstring

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-mysqlnd

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-odbc

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-opcache

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-pdo

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-pecl-apcu

5.1.23-1.module+el9.8.0+90982+92b8b4c7

php-pecl-apcu-devel

5.1.23-1.module+el9.8.0+90982+92b8b4c7

php-pecl-redis6

6.1.0-3.module+el9.8.0+90982+92b8b4c7

php-pecl-rrd

2.0.3-4.module+el9.8.0+90982+92b8b4c7

php-pecl-xdebug3

3.3.1-1.module+el9.8.0+90982+92b8b4c7

php-pecl-zip

1.22.3-1.module+el9.8.0+90982+92b8b4c7

php-pgsql

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-process

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-snmp

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-soap

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-xml

8.3.32-1.module+el9.8.0+90982+92b8b4c7

Oracle Linux x86_64

Module php:8.3 is enabled

apcu-panel

5.1.23-1.module+el9.8.0+90982+92b8b4c7

php

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-bcmath

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-cli

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-common

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-dba

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-dbg

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-devel

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-embedded

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-enchant

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-ffi

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-fpm

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-gd

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-gmp

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-intl

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-ldap

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-mbstring

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-mysqlnd

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-odbc

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-opcache

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-pdo

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-pecl-apcu

5.1.23-1.module+el9.8.0+90982+92b8b4c7

php-pecl-apcu-devel

5.1.23-1.module+el9.8.0+90982+92b8b4c7

php-pecl-redis6

6.1.0-3.module+el9.8.0+90982+92b8b4c7

php-pecl-rrd

2.0.3-4.module+el9.8.0+90982+92b8b4c7

php-pecl-xdebug3

3.3.1-1.module+el9.8.0+90982+92b8b4c7

php-pecl-zip

1.22.3-1.module+el9.8.0+90982+92b8b4c7

php-pgsql

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-process

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-snmp

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-soap

8.3.32-1.module+el9.8.0+90982+92b8b4c7

php-xml

8.3.32-1.module+el9.8.0+90982+92b8b4c7

Связанные CVE

Связанные уязвимости

CVSS3: 5.6
ubuntu
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
redhat
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
nvd
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
msrc
2 месяца назад

ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD

CVSS3: 5.6
debian
2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...