Bug#1143153: php8.4: CVE-2026-7260 CVE-2026-17543 CVE-2026-17544

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Source: php8.4
Version: 8.4.23-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>, [email protected]

Hi Ondrej,

The following vulnerabilities were published for php8.4.

I guess they are important enough to make as well a DSA. There is as a
well a libgd2 update, but I have made a aseparate bug about it.

CVE-2026-7260[0]:
| Circular symbolic links in phar archives could lead to unbounded
| recursion, exhausting the C stack and crashing the PHP process, in
| PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33,
| from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.


CVE-2026-17543[1]:
| Improper escaping of backslashes in attacker-provided parameters
| would allow for trivial SQL injection in PHP versions from 8.2.*
| before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24,
| and from 8.5.* before 8.5.9.


CVE-2026-17544[2]:
| Attacker-provided inputs to bccomp() could lead to an out-of-bounds
| write with stack and heap corruption in PHP versions from 8.4.*
| before 8.4.24 and from 8.5.* before 8.5.9.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-7260
    https://www.cve.org/CVERecord?id=CVE-2026-7260
[1] https://security-tracker.debian.org/tracker/CVE-2026-17543
    https://www.cve.org/CVERecord?id=CVE-2026-17543
[2] https://security-tracker.debian.org/tracker/CVE-2026-17544
    https://www.cve.org/CVERecord?id=CVE-2026-17544

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.