Описание
Security update for php7
This update for php7 fixes the following issue
- CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw (bsc#1270351).
Список пакетов
SUSE Linux Enterprise Module for Legacy 15 SP7
apache2-mod_php7-7.4.33-150400.4.63.1
php7-7.4.33-150400.4.63.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
apache2-mod_php7-7.4.33-150400.4.63.1
php7-7.4.33-150400.4.63.1
php7-bcmath-7.4.33-150400.4.63.1
php7-bz2-7.4.33-150400.4.63.1
php7-calendar-7.4.33-150400.4.63.1
php7-cli-7.4.33-150400.4.63.1
php7-ctype-7.4.33-150400.4.63.1
php7-curl-7.4.33-150400.4.63.1
php7-dba-7.4.33-150400.4.63.1
php7-dom-7.4.33-150400.4.63.1
php7-embed-7.4.33-150400.4.63.1
php7-enchant-7.4.33-150400.4.63.1
php7-exif-7.4.33-150400.4.63.1
php7-fastcgi-7.4.33-150400.4.63.1
php7-fileinfo-7.4.33-150400.4.63.1
php7-fpm-7.4.33-150400.4.63.1
php7-ftp-7.4.33-150400.4.63.1
php7-gd-7.4.33-150400.4.63.1
php7-gettext-7.4.33-150400.4.63.1
php7-gmp-7.4.33-150400.4.63.1
php7-iconv-7.4.33-150400.4.63.1
php7-intl-7.4.33-150400.4.63.1
php7-json-7.4.33-150400.4.63.1
php7-ldap-7.4.33-150400.4.63.1
php7-mbstring-7.4.33-150400.4.63.1
php7-mysql-7.4.33-150400.4.63.1
php7-odbc-7.4.33-150400.4.63.1
php7-opcache-7.4.33-150400.4.63.1
php7-openssl-7.4.33-150400.4.63.1
php7-pcntl-7.4.33-150400.4.63.1
php7-pdo-7.4.33-150400.4.63.1
php7-pgsql-7.4.33-150400.4.63.1
php7-phar-7.4.33-150400.4.63.1
php7-posix-7.4.33-150400.4.63.1
php7-readline-7.4.33-150400.4.63.1
php7-shmop-7.4.33-150400.4.63.1
php7-snmp-7.4.33-150400.4.63.1
php7-soap-7.4.33-150400.4.63.1
php7-sockets-7.4.33-150400.4.63.1
php7-sodium-7.4.33-150400.4.63.1
php7-sqlite-7.4.33-150400.4.63.1
php7-sysvmsg-7.4.33-150400.4.63.1
php7-sysvsem-7.4.33-150400.4.63.1
php7-sysvshm-7.4.33-150400.4.63.1
php7-test-7.4.33-150400.4.63.1
php7-tidy-7.4.33-150400.4.63.1
php7-tokenizer-7.4.33-150400.4.63.1
php7-xmlreader-7.4.33-150400.4.63.1
php7-xmlrpc-7.4.33-150400.4.63.1
php7-xmlwriter-7.4.33-150400.4.63.1
php7-xsl-7.4.33-150400.4.63.1
php7-zip-7.4.33-150400.4.63.1
php7-zlib-7.4.33-150400.4.63.1
Ссылки
- Link for SUSE-SU-2026:3165-1
- E-Mail link for SUSE-SU-2026:3165-1
- SUSE Security Ratings
- SUSE Bug 1270351
- SUSE CVE CVE-2026-14355 page
Описание
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
Затронутые продукты
SUSE Linux Enterprise Module for Legacy 15 SP7:apache2-mod_php7-7.4.33-150400.4.63.1
SUSE Linux Enterprise Module for Legacy 15 SP7:php7-7.4.33-150400.4.63.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:apache2-mod_php7-7.4.33-150400.4.63.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:php7-7.4.33-150400.4.63.1
Ссылки
- CVE-2026-14355
- SUSE Bug 1270351