[CLSA-2026:1786590197] Fix CVE(s): CVE-2026-17543, CVE-2026-7260, CVE-2026-9672
Type:
security
Severity:
Critical
Release date:
2026-08-14 07:01:31 UTC
Description:
* CVE-2026-9672: fix three defects in the bundled libgd GIF LZW decoder reachable from attacker-controlled GIF data via imagecreatefromgif(). The table reset cleared sd->table[1][0] instead of sd->table[1][i], so stale suffixes leaked between images; LWZReadByte_() kept decoding with a stale code after the LZW end code when the trailing data block count was 0; and ReadImage() left LZW_STATIC_DATA uninitialised. * CVE-2026-17543: fix SQL injection in ext/pgsql. php_pgsql_add_quotes() wrapped PQescapeStringConn() output in an E'...' literal, but PQescapeStringConn() only doubles the single quote while standard_conforming_strings is on, so a trailing backslash escaped the closing quote and broke out of the literal in pg_convert()/pg_insert()/pg_update()/pg_select()/pg_delete(). Emit a plain '...' literal instead. * CVE-2026-7260: fix unbounded recursion in phar_get_link_source() on a circular symlink chain (GHSA-vc5h-9ppw-p5f3). The self-recursion is replaced by a Floyd cycle-detection walk that returns NULL for a cycle, including the phar_get_link_location() path-separator restore the walk depends on.
Updated packages:
  • alt-php72_7.2.34-89_amd64.deb
    sha:03e81c9f376df7f97261e5e40aad13d9265a4d4b
  • alt-php72-bcmath_7.2.34-89_amd64.deb
    sha:f89c7a6a5fac0f40b29bef12c072d457e955b1fa
  • alt-php72-cli_7.2.34-89_amd64.deb
    sha:2f9d61ae5ccbaeb0650d4dbcfeeecaee0995b35c
  • alt-php72-common_7.2.34-89_amd64.deb
    sha:446de46e4458cca82efb96285c0772bfb501ef55
  • alt-php72-dba_7.2.34-89_amd64.deb
    sha:4d3565a2532e012c37e9fc85b4889b0fe10f5aff
  • alt-php72-dev_7.2.34-89_amd64.deb
    sha:05fe829b701656b6bf42bcf24a06bcfc07a82dc5
  • alt-php72-enchant_7.2.34-89_amd64.deb
    sha:1f7d4123cd01b0a6c895e6439900fb6a9d5e73d9
  • alt-php72-firebird_7.2.34-89_amd64.deb
    sha:cc2cf693fe4941194a461d87fb0f39418a968a03
  • alt-php72-gd_7.2.34-89_amd64.deb
    sha:0327ef9f2a44a6869b3468fce20fc2fdbaefb773
  • alt-php72-imap_7.2.34-89_amd64.deb
    sha:cfecd899c506ae99003e5b059f6f3dddcffb4c55
  • alt-php72-intl_7.2.34-89_amd64.deb
    sha:f9c74a6af3f4a8edf75dfafd7549fc6c8d6d37ad
  • alt-php72-ldap_7.2.34-89_amd64.deb
    sha:7c3b388f7a9a6b86ae6272f1e49aa0c7d8445c69
  • alt-php72-mbstring_7.2.34-89_amd64.deb
    sha:5424a0abe91e581474a8c94ef136e303848781b1
  • alt-php72-mysqlnd_7.2.34-89_amd64.deb
    sha:b4453080be528c11b2f0a767156576bfdc8399d2
  • alt-php72-odbc_7.2.34-89_amd64.deb
    sha:dfc80f775a1210db08a6aa3fe1e3c947e10c575d
  • alt-php72-opcache_7.2.34-89_amd64.deb
    sha:b8a3956586be00b97babc0e51f656b622ba0e651
  • alt-php72-pdo_7.2.34-89_amd64.deb
    sha:50e8e1abcf90c80300f7fb521e1e8a13a616aa19
  • alt-php72-pgsql_7.2.34-89_amd64.deb
    sha:1e548e6634411eb8bf7950e9f1313478bd3af860
  • alt-php72-php-fpm_7.2.34-89_amd64.deb
    sha:1b199352645d03a732f83dece5b361ac51a5d0e7
  • alt-php72-process_7.2.34-89_amd64.deb
    sha:8a3929fe7989b87cbb0d4c1318c78ce6ca8eeae2
  • alt-php72-pspell_7.2.34-89_amd64.deb
    sha:a6255b0c1df8b0dade000b8d165f57caeb3003b5
  • alt-php72-recode_7.2.34-89_amd64.deb
    sha:836590c4fb4706eb4975e393e5b907910690a9a9
  • alt-php72-snmp_7.2.34-89_amd64.deb
    sha:815daca1fe6abc8a73c0eed150f4a346d3e1cd7f
  • alt-php72-soap_7.2.34-89_amd64.deb
    sha:109b41300aa23a1cf5889f613d492d9ee06d3ba7
  • alt-php72-sodium_7.2.34-89_amd64.deb
    sha:09b0736f91111cfb5cfa2f473c1acd358b8c65d0
  • alt-php72-tidy_7.2.34-89_amd64.deb
    sha:2073f58f9ed5b7848babcf710d2e8fb2aa2c4f21
  • alt-php72-xml_7.2.34-89_amd64.deb
    sha:4cf2dc44dc05f3433e060848ca681da124146e0a
  • alt-php72-xmlrpc_7.2.34-89_amd64.deb
    sha:497774f0f1cfbaa40c4a9e9a71fdc3bb7b084576
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.