Описание
Security update for php8
This update for php8 fixes the following issues:
Update to version 8.3.33.
Security issues fixed:
- CVE-2026-7260: circular symbolic links in phar archives can lead to unbounded recursion and cause C stack exhaustion (bsc#1273077).
- CVE-2026-9672: security issues in
libgd(bsc#1273078). - CVE-2026-17543: improper escaping of backslashes in user-provided parameters allows for trivial SQL injection in
ext-pgsql(bsc#1273075).
Список пакетов
SUSE Linux Enterprise Module for Web and Scripting 15 SP7
apache2-mod_php8-8.3.33-150700.3.18.1
php8-8.3.33-150700.3.18.1
php8-bcmath-8.3.33-150700.3.18.1
php8-bz2-8.3.33-150700.3.18.1
php8-calendar-8.3.33-150700.3.18.1
php8-cli-8.3.33-150700.3.18.1
php8-ctype-8.3.33-150700.3.18.1
php8-curl-8.3.33-150700.3.18.1
php8-dba-8.3.33-150700.3.18.1
php8-devel-8.3.33-150700.3.18.1
php8-dom-8.3.33-150700.3.18.1
php8-embed-8.3.33-150700.3.18.1
php8-enchant-8.3.33-150700.3.18.1
php8-exif-8.3.33-150700.3.18.1
php8-fastcgi-8.3.33-150700.3.18.1
php8-fileinfo-8.3.33-150700.3.18.1
php8-fpm-8.3.33-150700.3.18.1
php8-ftp-8.3.33-150700.3.18.1
php8-gd-8.3.33-150700.3.18.1
php8-gettext-8.3.33-150700.3.18.1
php8-gmp-8.3.33-150700.3.18.1
php8-iconv-8.3.33-150700.3.18.1
php8-intl-8.3.33-150700.3.18.1
php8-ldap-8.3.33-150700.3.18.1
php8-mbstring-8.3.33-150700.3.18.1
php8-mysql-8.3.33-150700.3.18.1
php8-odbc-8.3.33-150700.3.18.1
php8-opcache-8.3.33-150700.3.18.1
php8-openssl-8.3.33-150700.3.18.1
php8-pcntl-8.3.33-150700.3.18.1
php8-pdo-8.3.33-150700.3.18.1
php8-pgsql-8.3.33-150700.3.18.1
php8-phar-8.3.33-150700.3.18.1
php8-posix-8.3.33-150700.3.18.1
php8-readline-8.3.33-150700.3.18.1
php8-shmop-8.3.33-150700.3.18.1
php8-snmp-8.3.33-150700.3.18.1
php8-soap-8.3.33-150700.3.18.1
php8-sockets-8.3.33-150700.3.18.1
php8-sodium-8.3.33-150700.3.18.1
php8-sqlite-8.3.33-150700.3.18.1
php8-sysvmsg-8.3.33-150700.3.18.1
php8-sysvsem-8.3.33-150700.3.18.1
php8-sysvshm-8.3.33-150700.3.18.1
php8-test-8.3.33-150700.3.18.1
php8-tidy-8.3.33-150700.3.18.1
php8-tokenizer-8.3.33-150700.3.18.1
php8-xmlreader-8.3.33-150700.3.18.1
php8-xmlwriter-8.3.33-150700.3.18.1
php8-xsl-8.3.33-150700.3.18.1
php8-zip-8.3.33-150700.3.18.1
php8-zlib-8.3.33-150700.3.18.1
Ссылки
- Link for SUSE-SU-2026:3509-1
- E-Mail link for SUSE-SU-2026:3509-1
- SUSE Security Ratings
- SUSE Bug 1273075
- SUSE Bug 1273077
- SUSE Bug 1273078
- SUSE CVE CVE-2026-17543 page
- SUSE CVE CVE-2026-7260 page
- SUSE CVE CVE-2026-9672 page
Описание
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:apache2-mod_php8-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bcmath-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bz2-8.3.33-150700.3.18.1
Ссылки
- CVE-2026-17543
- SUSE Bug 1273075
Описание
Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:apache2-mod_php8-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bcmath-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bz2-8.3.33-150700.3.18.1
Ссылки
- CVE-2026-7260
- SUSE Bug 1273077
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:apache2-mod_php8-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bcmath-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bz2-8.3.33-150700.3.18.1
Ссылки
- CVE-2026-9672
- SUSE Bug 1273078