Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3509-1

Опубликовано: 05 авг. 2026
Источник: suse-cvrf

Описание

Security update for php8

This update for php8 fixes the following issues:

Update to version 8.3.33.

Security issues fixed:

  • CVE-2026-7260: circular symbolic links in phar archives can lead to unbounded recursion and cause C stack exhaustion (bsc#1273077).
  • CVE-2026-9672: security issues in libgd (bsc#1273078).
  • CVE-2026-17543: improper escaping of backslashes in user-provided parameters allows for trivial SQL injection in ext-pgsql (bsc#1273075).

Список пакетов

SUSE Linux Enterprise Module for Web and Scripting 15 SP7
apache2-mod_php8-8.3.33-150700.3.18.1
php8-8.3.33-150700.3.18.1
php8-bcmath-8.3.33-150700.3.18.1
php8-bz2-8.3.33-150700.3.18.1
php8-calendar-8.3.33-150700.3.18.1
php8-cli-8.3.33-150700.3.18.1
php8-ctype-8.3.33-150700.3.18.1
php8-curl-8.3.33-150700.3.18.1
php8-dba-8.3.33-150700.3.18.1
php8-devel-8.3.33-150700.3.18.1
php8-dom-8.3.33-150700.3.18.1
php8-embed-8.3.33-150700.3.18.1
php8-enchant-8.3.33-150700.3.18.1
php8-exif-8.3.33-150700.3.18.1
php8-fastcgi-8.3.33-150700.3.18.1
php8-fileinfo-8.3.33-150700.3.18.1
php8-fpm-8.3.33-150700.3.18.1
php8-ftp-8.3.33-150700.3.18.1
php8-gd-8.3.33-150700.3.18.1
php8-gettext-8.3.33-150700.3.18.1
php8-gmp-8.3.33-150700.3.18.1
php8-iconv-8.3.33-150700.3.18.1
php8-intl-8.3.33-150700.3.18.1
php8-ldap-8.3.33-150700.3.18.1
php8-mbstring-8.3.33-150700.3.18.1
php8-mysql-8.3.33-150700.3.18.1
php8-odbc-8.3.33-150700.3.18.1
php8-opcache-8.3.33-150700.3.18.1
php8-openssl-8.3.33-150700.3.18.1
php8-pcntl-8.3.33-150700.3.18.1
php8-pdo-8.3.33-150700.3.18.1
php8-pgsql-8.3.33-150700.3.18.1
php8-phar-8.3.33-150700.3.18.1
php8-posix-8.3.33-150700.3.18.1
php8-readline-8.3.33-150700.3.18.1
php8-shmop-8.3.33-150700.3.18.1
php8-snmp-8.3.33-150700.3.18.1
php8-soap-8.3.33-150700.3.18.1
php8-sockets-8.3.33-150700.3.18.1
php8-sodium-8.3.33-150700.3.18.1
php8-sqlite-8.3.33-150700.3.18.1
php8-sysvmsg-8.3.33-150700.3.18.1
php8-sysvsem-8.3.33-150700.3.18.1
php8-sysvshm-8.3.33-150700.3.18.1
php8-test-8.3.33-150700.3.18.1
php8-tidy-8.3.33-150700.3.18.1
php8-tokenizer-8.3.33-150700.3.18.1
php8-xmlreader-8.3.33-150700.3.18.1
php8-xmlwriter-8.3.33-150700.3.18.1
php8-xsl-8.3.33-150700.3.18.1
php8-zip-8.3.33-150700.3.18.1
php8-zlib-8.3.33-150700.3.18.1

Описание

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.


Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:apache2-mod_php8-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bcmath-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bz2-8.3.33-150700.3.18.1

Ссылки

Описание

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.


Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:apache2-mod_php8-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bcmath-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bz2-8.3.33-150700.3.18.1

Ссылки

Описание

unknown


Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:apache2-mod_php8-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bcmath-8.3.33-150700.3.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7:php8-bz2-8.3.33-150700.3.18.1

Ссылки