Описание
Security update for php8
This update for php8 fixes the following issues
- Update to versio 8.4.23
- CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw (bsc#1270351).
Список пакетов
openSUSE Leap 16.0
apache2-mod_php8-8.4.23-160000.1.1
php8-8.4.23-160000.1.1
php8-bcmath-8.4.23-160000.1.1
php8-bz2-8.4.23-160000.1.1
php8-calendar-8.4.23-160000.1.1
php8-cli-8.4.23-160000.1.1
php8-ctype-8.4.23-160000.1.1
php8-curl-8.4.23-160000.1.1
php8-dba-8.4.23-160000.1.1
php8-devel-8.4.23-160000.1.1
php8-dom-8.4.23-160000.1.1
php8-embed-8.4.23-160000.1.1
php8-enchant-8.4.23-160000.1.1
php8-exif-8.4.23-160000.1.1
php8-fastcgi-8.4.23-160000.1.1
php8-ffi-8.4.23-160000.1.1
php8-fileinfo-8.4.23-160000.1.1
php8-fpm-8.4.23-160000.1.1
php8-fpm-apache-8.4.23-160000.1.1
php8-ftp-8.4.23-160000.1.1
php8-gd-8.4.23-160000.1.1
php8-gettext-8.4.23-160000.1.1
php8-gmp-8.4.23-160000.1.1
php8-iconv-8.4.23-160000.1.1
php8-intl-8.4.23-160000.1.1
php8-ldap-8.4.23-160000.1.1
php8-mbstring-8.4.23-160000.1.1
php8-mysql-8.4.23-160000.1.1
php8-odbc-8.4.23-160000.1.1
php8-opcache-8.4.23-160000.1.1
php8-openssl-8.4.23-160000.1.1
php8-pcntl-8.4.23-160000.1.1
php8-pdo-8.4.23-160000.1.1
php8-pgsql-8.4.23-160000.1.1
php8-phar-8.4.23-160000.1.1
php8-posix-8.4.23-160000.1.1
php8-readline-8.4.23-160000.1.1
php8-shmop-8.4.23-160000.1.1
php8-snmp-8.4.23-160000.1.1
php8-soap-8.4.23-160000.1.1
php8-sockets-8.4.23-160000.1.1
php8-sodium-8.4.23-160000.1.1
php8-sqlite-8.4.23-160000.1.1
php8-sysvmsg-8.4.23-160000.1.1
php8-sysvsem-8.4.23-160000.1.1
php8-sysvshm-8.4.23-160000.1.1
php8-test-8.4.23-160000.1.1
php8-tidy-8.4.23-160000.1.1
php8-tokenizer-8.4.23-160000.1.1
php8-xmlreader-8.4.23-160000.1.1
php8-xmlwriter-8.4.23-160000.1.1
php8-xsl-8.4.23-160000.1.1
php8-zip-8.4.23-160000.1.1
php8-zlib-8.4.23-160000.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1270351
- SUSE Bug 1270712
- SUSE CVE CVE-2026-12184 page
- SUSE CVE CVE-2026-14355 page
Описание
unknown
Затронутые продукты
openSUSE Leap 16.0:apache2-mod_php8-8.4.23-160000.1.1
openSUSE Leap 16.0:php8-8.4.23-160000.1.1
openSUSE Leap 16.0:php8-bcmath-8.4.23-160000.1.1
openSUSE Leap 16.0:php8-bz2-8.4.23-160000.1.1
Ссылки
- CVE-2026-12184
- SUSE Bug 1270712
Описание
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
Затронутые продукты
openSUSE Leap 16.0:apache2-mod_php8-8.4.23-160000.1.1
openSUSE Leap 16.0:php8-8.4.23-160000.1.1
openSUSE Leap 16.0:php8-bcmath-8.4.23-160000.1.1
openSUSE Leap 16.0:php8-bz2-8.4.23-160000.1.1
Ссылки
- CVE-2026-14355
- SUSE Bug 1270351