Описание
Security update for php8
This update for php8 fixes the following issues
- Update to version 8.3.32
- CVE-2026-12184: Failure to setup TLS with a remote server can result in a remote DoS (bsc#1270712).
- CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw (bsc#1270351).
Список пакетов
SUSE Linux Enterprise Module for Web and Scripting 15 SP7
apache2-mod_php8-8.3.32-150700.3.15.1
php8-8.3.32-150700.3.15.1
php8-bcmath-8.3.32-150700.3.15.1
php8-bz2-8.3.32-150700.3.15.1
php8-calendar-8.3.32-150700.3.15.1
php8-cli-8.3.32-150700.3.15.1
php8-ctype-8.3.32-150700.3.15.1
php8-curl-8.3.32-150700.3.15.1
php8-dba-8.3.32-150700.3.15.1
php8-devel-8.3.32-150700.3.15.1
php8-dom-8.3.32-150700.3.15.1
php8-embed-8.3.32-150700.3.15.1
php8-enchant-8.3.32-150700.3.15.1
php8-exif-8.3.32-150700.3.15.1
php8-fastcgi-8.3.32-150700.3.15.1
php8-fileinfo-8.3.32-150700.3.15.1
php8-fpm-8.3.32-150700.3.15.1
php8-ftp-8.3.32-150700.3.15.1
php8-gd-8.3.32-150700.3.15.1
php8-gettext-8.3.32-150700.3.15.1
php8-gmp-8.3.32-150700.3.15.1
php8-iconv-8.3.32-150700.3.15.1
php8-intl-8.3.32-150700.3.15.1
php8-ldap-8.3.32-150700.3.15.1
php8-mbstring-8.3.32-150700.3.15.1
php8-mysql-8.3.32-150700.3.15.1
php8-odbc-8.3.32-150700.3.15.1
php8-opcache-8.3.32-150700.3.15.1
php8-openssl-8.3.32-150700.3.15.1
php8-pcntl-8.3.32-150700.3.15.1
php8-pdo-8.3.32-150700.3.15.1
php8-pgsql-8.3.32-150700.3.15.1
php8-phar-8.3.32-150700.3.15.1
php8-posix-8.3.32-150700.3.15.1
php8-readline-8.3.32-150700.3.15.1
php8-shmop-8.3.32-150700.3.15.1
php8-snmp-8.3.32-150700.3.15.1
php8-soap-8.3.32-150700.3.15.1
php8-sockets-8.3.32-150700.3.15.1
php8-sodium-8.3.32-150700.3.15.1
php8-sqlite-8.3.32-150700.3.15.1
php8-sysvmsg-8.3.32-150700.3.15.1
php8-sysvsem-8.3.32-150700.3.15.1
php8-sysvshm-8.3.32-150700.3.15.1
php8-test-8.3.32-150700.3.15.1
php8-tidy-8.3.32-150700.3.15.1
php8-tokenizer-8.3.32-150700.3.15.1
php8-xmlreader-8.3.32-150700.3.15.1
php8-xmlwriter-8.3.32-150700.3.15.1
php8-xsl-8.3.32-150700.3.15.1
php8-zip-8.3.32-150700.3.15.1
php8-zlib-8.3.32-150700.3.15.1
Ссылки
- Link for SUSE-SU-2026:3164-1
- E-Mail link for SUSE-SU-2026:3164-1
- SUSE Security Ratings
- SUSE Bug 1270351
- SUSE Bug 1270712
- SUSE CVE CVE-2026-12184 page
- SUSE CVE CVE-2026-14355 page
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:apache2-mod_php8-8.3.32-150700.3.15.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-8.3.32-150700.3.15.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bcmath-8.3.32-150700.3.15.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bz2-8.3.32-150700.3.15.1
Ссылки
- CVE-2026-12184
- SUSE Bug 1270712
Описание
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:apache2-mod_php8-8.3.32-150700.3.15.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-8.3.32-150700.3.15.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bcmath-8.3.32-150700.3.15.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bz2-8.3.32-150700.3.15.1
Ссылки
- CVE-2026-14355
- SUSE Bug 1270351