Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3165-1

Опубликовано: 21 июл. 2026
Источник: suse-cvrf

Описание

Security update for php7

This update for php7 fixes the following issue

  • CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw (bsc#1270351).

Список пакетов

SUSE Linux Enterprise Module for Legacy 15 SP7
apache2-mod_php7-7.4.33-150400.4.63.1
php7-7.4.33-150400.4.63.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
apache2-mod_php7-7.4.33-150400.4.63.1
php7-7.4.33-150400.4.63.1
php7-bcmath-7.4.33-150400.4.63.1
php7-bz2-7.4.33-150400.4.63.1
php7-calendar-7.4.33-150400.4.63.1
php7-cli-7.4.33-150400.4.63.1
php7-ctype-7.4.33-150400.4.63.1
php7-curl-7.4.33-150400.4.63.1
php7-dba-7.4.33-150400.4.63.1
php7-dom-7.4.33-150400.4.63.1
php7-embed-7.4.33-150400.4.63.1
php7-enchant-7.4.33-150400.4.63.1
php7-exif-7.4.33-150400.4.63.1
php7-fastcgi-7.4.33-150400.4.63.1
php7-fileinfo-7.4.33-150400.4.63.1
php7-fpm-7.4.33-150400.4.63.1
php7-ftp-7.4.33-150400.4.63.1
php7-gd-7.4.33-150400.4.63.1
php7-gettext-7.4.33-150400.4.63.1
php7-gmp-7.4.33-150400.4.63.1
php7-iconv-7.4.33-150400.4.63.1
php7-intl-7.4.33-150400.4.63.1
php7-json-7.4.33-150400.4.63.1
php7-ldap-7.4.33-150400.4.63.1
php7-mbstring-7.4.33-150400.4.63.1
php7-mysql-7.4.33-150400.4.63.1
php7-odbc-7.4.33-150400.4.63.1
php7-opcache-7.4.33-150400.4.63.1
php7-openssl-7.4.33-150400.4.63.1
php7-pcntl-7.4.33-150400.4.63.1
php7-pdo-7.4.33-150400.4.63.1
php7-pgsql-7.4.33-150400.4.63.1
php7-phar-7.4.33-150400.4.63.1
php7-posix-7.4.33-150400.4.63.1
php7-readline-7.4.33-150400.4.63.1
php7-shmop-7.4.33-150400.4.63.1
php7-snmp-7.4.33-150400.4.63.1
php7-soap-7.4.33-150400.4.63.1
php7-sockets-7.4.33-150400.4.63.1
php7-sodium-7.4.33-150400.4.63.1
php7-sqlite-7.4.33-150400.4.63.1
php7-sysvmsg-7.4.33-150400.4.63.1
php7-sysvsem-7.4.33-150400.4.63.1
php7-sysvshm-7.4.33-150400.4.63.1
php7-test-7.4.33-150400.4.63.1
php7-tidy-7.4.33-150400.4.63.1
php7-tokenizer-7.4.33-150400.4.63.1
php7-xmlreader-7.4.33-150400.4.63.1
php7-xmlrpc-7.4.33-150400.4.63.1
php7-xmlwriter-7.4.33-150400.4.63.1
php7-xsl-7.4.33-150400.4.63.1
php7-zip-7.4.33-150400.4.63.1
php7-zlib-7.4.33-150400.4.63.1

Описание

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.


Затронутые продукты
SUSE Linux Enterprise Module for Legacy 15 SP7:apache2-mod_php7-7.4.33-150400.4.63.1
SUSE Linux Enterprise Module for Legacy 15 SP7:php7-7.4.33-150400.4.63.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:apache2-mod_php7-7.4.33-150400.4.63.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:php7-7.4.33-150400.4.63.1

Ссылки