php:8.2 security update
エラータID: AXSA:2026-124:01
PHP is an HTML-embedded scripting language commonly used with the Apache HTTP
Server.
Security Fix(es):
php: pgsql extension does not check for errors during escaping
(CVE-2025-1735)
php: NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace
Prefix (CVE-2025-6491)
php: PHP Hostname Null Character Vulnerability (CVE-2025-1220)
php: heap-based buffer overflow in array_merge() (CVE-2025-14178)
php: PHP: Information disclosure via getimagesize() function when reading
multi-chunk images (CVE-2025-14177)
php: PHP: Denial of Service via invalid character sequence in PDO PostgreSQL
prepared statement (CVE-2025-14180)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
CVE(s):
CVE-2025-1220
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.
CVE-2025-1735
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server rejects the string as invalid.
CVE-2025-6491
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.
CVE-2025-14177
In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.
CVE-2025-14178
In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server.
CVE-2025-14180
In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled, an invalid character sequence (such as \x99) in a prepared statement parameter may cause the quoting function PQescapeStringConn to return NULL, leading to a null pointer dereference in pdo_parse_params() function. This may lead to crashes (segmentation fault) and affect the availability of the target server.
Modularity name: "php"
Stream name: "8.2"
Update packages.
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.
In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.
In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server.
In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled, an invalid character sequence (such as \x99) in a prepared statement parameter may cause the quoting function PQescapeStringConn to return NULL, leading to a null pointer dereference in pdo_parse_params() function. This may lead to crashes (segmentation fault) and affect the availability of the target server.
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server rejects the string as invalid.
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.
N/A
SRPMS
- libzip-1.7.3-1.module+el8+1949+3bbc4295.src.rpm
MD5: d378d1d6abdb60f01a20db8edd594e65
SHA-256: e5de799ff9c9fe896f53884890b525f48a7fcdca322a9f5280e63ac5c65fff86
Size: 746.87 kB - php-pear-1.10.14-1.module+el8+1949+3bbc4295.src.rpm
MD5: 252c2077ce472fdbde54863dbb804bc4
SHA-256: f44f896951b0722462188b6e863a57ef995cc15ed2c24ad24da7dc615f64288d
Size: 380.78 kB - php-pecl-apcu-5.1.23-1.module+el8+1949+3bbc4295.src.rpm
MD5: 52d8abe1ec26b746f8a79318c20f905c
SHA-256: 54ce1c1ea6a2d51beace85f843940af304fef5ac659c346d3c96d368ae82cca5
Size: 105.42 kB - php-pecl-rrd-2.0.3-1.module+el8+1949+3bbc4295.src.rpm
MD5: 2de85a6c014cbe914cd0d8fa7beee5c6
SHA-256: 6101771acc5f4cd9b3a08fe21c4c313830f9ab663fe9eb2bd8464c11a7d566ec
Size: 33.67 kB - php-pecl-xdebug3-3.2.2-2.module+el8+1949+3bbc4295.src.rpm
MD5: d1369db5e7c2b6dd4d4c1619ef267928
SHA-256: 1d15053a0797130753c86031e86b31126c99965fa4ca6ba3ac3877a9b94c818b
Size: 465.77 kB - php-pecl-zip-1.22.3-1.module+el8+1949+3bbc4295.src.rpm
MD5: 41f32dd8a70b5e4228a52c330b24c563
SHA-256: ceec2efc54158296384af4af1f75dcc0f15c26c6d06b824956aecbdff91d11fe
Size: 368.62 kB - php-8.2.30-1.module+el8+1949+3bbc4295.src.rpm
MD5: 7f2dc35021321f426656c10a6d4c1655
SHA-256: 20f1b2f6e49bfd73f1ab701d2441f03949ee98dae5e487305d1f85b28d485d95
Size: 11.76 MB
Asianux Server 8 for x86_64
- apcu-panel-5.1.23-1.module+el8+1949+3bbc4295.noarch.rpm
MD5: 0a5ba0fe98da5b0bda432cb58b722a90
SHA-256: 615a8786c7c2e62345a651be6f21147010ff7f60501dce07e013303c13dad5ec
Size: 22.84 kB - libzip-1.7.3-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 118ea2598e08ad0d000deef01f5e4045
SHA-256: 73aee68829767ca29d39c6ad1c37f8b374c2144305a1691ac1d68c8182301466
Size: 65.99 kB - libzip-debugsource-1.7.3-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 16fa05d0f0ecdaedcfc852874929fe1e
SHA-256: d7a537e338cc17fac7a3125019f79da2a94a26732497658ddcbd2c5fcdde748e
Size: 104.79 kB - libzip-devel-1.7.3-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: d2e12a070a229227c0527510ea6e9881
SHA-256: 52523239f8b4781fb47c45292f00d6aa8a9f58797bd846612e5a5653017b9ace
Size: 188.59 kB - libzip-tools-1.7.3-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 51fb15e532d2eeb80b767709f2e7f3c9
SHA-256: 61320c0b2135ae67a5d019e1d661bad08b03d88b3cc37f550221d72c4b668a7d
Size: 43.14 kB - php-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 96c0af4e3ac205dbffbc7d3b5ee9ff82
SHA-256: fac3634f8e9e0b2f4ae3a6848f0688b19e888736a426a51ac4cec4ff9ab3fa08
Size: 1.80 MB - php-bcmath-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 658c89cdbd01dc740d821d9be3511ab1
SHA-256: f6df1664552c86dd6e84f1518bea018d310fddeea047436aadc4e025ac3b408e
Size: 80.17 kB - php-cli-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: c60e13e64d51011b48ebd4ad0c903c9d
SHA-256: 20e4fa76c002fe3c30a9c524c0437a341a8d72d84c712ed3034aab378187772e
Size: 3.64 MB - php-common-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: d542be2d85771d40cf5b302c597bf13a
SHA-256: 7bf65f4be68ab9c20e62a89688b8d51c4f2898d896f22f08bd29e06dcac1d726
Size: 748.72 kB - php-dba-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 26b90549fb9feec1955e198c3b9e1770
SHA-256: 9ad0f3d51c213ad85f08467fb85a817790904b9ccfbfae4898150b14a456ae6c
Size: 80.67 kB - php-dbg-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 72989ac432f615cf7b0e646dd350ccc1
SHA-256: e0d1ccf5a5c04bef4ea066f80f2a635162a42278998324cf05e45ae2a9e91922
Size: 1.89 MB - php-debugsource-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: cf9f0c584dcb19bd80bf36bd427285af
SHA-256: ca3540669469b89f9e5a0021fe63b5982e3f84bff6f1233dc0cf7e0b7886b374
Size: 4.58 MB - php-devel-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 412991f92fdab5bf243c71acb0e2c8aa
SHA-256: e4b080d5ed3bee09230cd0c6b902f65a263eedec7d7b1ba49919cafec6aa16d0
Size: 826.66 kB - php-embedded-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 0f307775df325d52807ac5ce27fd4425
SHA-256: 43654c192667cedf31b2a209d3fed5b47addc29fac73cf5b6af390492b5f1726
Size: 1.79 MB - php-enchant-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 852a7bd709cc34711ef24cc887322b14
SHA-256: f6c8c165cd753895337149692641b3ae77880b6e18409bdf95a13399245de470
Size: 64.71 kB - php-ffi-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 00968d276356f910e6893b386d44f105
SHA-256: 79b98f4b5a7e6fa864074121aaeab7e4e9eabd1bdf8f231fb9eee2aa312df3c6
Size: 121.58 kB - php-fpm-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: ddd2384ecad192cab9219901f842d4d5
SHA-256: c340a357b3df85ad3a6e59ccf2e5be1ce6f2b961e14be5d6b11811198f9298e0
Size: 1.89 MB - php-gd-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 9cae8ccf0376c3699657dc4187d71ec0
SHA-256: b4e3f54a6e2bd9f924dca6ceec4ccbe3aae270f269f796a92db07b31e339fbbe
Size: 86.00 kB - php-gmp-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 13beb5dc26ff0925a6d5688310a6b6b5
SHA-256: dd2fb045713baa2af41ab4b0947efa4b615e1921d136554f4218ce31a799f531
Size: 79.00 kB - php-intl-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 9f9e10c0401dba4c93b1dc42ae481c7a
SHA-256: 7c31a51de66ca1a0023667941311f74895b29b313a9d7a4a6200eed755d997a3
Size: 205.74 kB - php-ldap-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: a1beb4190b681569bb783aa4713dceef
SHA-256: 5503a2fa1d033df180159d5061a49072844875826bb6dd0ed42d7bed8c5a574f
Size: 87.56 kB - php-mbstring-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 8cfde250b854ae21fe200c5ca0c27317
SHA-256: 2aef2d583955136afc7e68fd3d92e820ff63164f8d3d2917ccdb562f74d7a75a
Size: 528.18 kB - php-mysqlnd-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 4673c24a7a05ee9c8abeb959eda2d287
SHA-256: fd9e2025e3f5e6a8184ef43f9c856e30d32a2ae2ca3dc7cc033e756b1efa2f73
Size: 188.45 kB - php-odbc-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: d35ca4ce654e1577661ec3f9db8e3ab5
SHA-256: 8e56b46b6974ab70c73bde816cf5cd4b454ca10d4fbecb42718f0b5a231d9f4d
Size: 91.82 kB - php-opcache-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: bc73d7d8e301379bffc7ea7e9607f173
SHA-256: da90ee98ca6dc3e5456ce3a1e0549162a7674d89d33fd597e9136a2ed54f5610
Size: 414.96 kB - php-pdo-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: ca39070fd3b11d8d6ca9b878ae759af8
SHA-256: 15c07d5abd3e3a64b1f40b6c1c16b83490696a355a71d121e95d7a0c2aad33ec
Size: 133.27 kB - php-pear-1.10.14-1.module+el8+1949+3bbc4295.noarch.rpm
MD5: 1ca00996933eb85b238713975322235a
SHA-256: 18dd6811fb9c4900afe00b4a53a975afec96d60f1d1425845eb2b184ca35db47
Size: 360.82 kB - php-pecl-apcu-5.1.23-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 627843be79f8f32fa461c04552e98526
SHA-256: 839f08ef58582b6253938acd959dd80d0716bf0c88ff314763b6838bd44fccb6
Size: 62.51 kB - php-pecl-apcu-debugsource-5.1.23-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 5d710330582b576104fe538aec59d5ae
SHA-256: 3e53ab4546e71c5d9d988732c51db18e5b7f6c406a6ea6c0f6db4e88779a504c
Size: 51.53 kB - php-pecl-apcu-devel-5.1.23-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 2d8d842ec1c335f345e9294aa476268e
SHA-256: bbd8e4a6900c54defddca2c2250d01732363f18c02e9986e31396aca15185eb0
Size: 45.82 kB - php-pecl-rrd-2.0.3-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 748611e57abff3ae802e643199f5b915
SHA-256: 13a40af70354d005053ad3916511821d048d2316fa9b0b3b10c918560f61bab8
Size: 30.75 kB - php-pecl-rrd-debugsource-2.0.3-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 4e05b0095dfeae4af16d2b3b163224e4
SHA-256: 217594c09991d89e9daadc1531605b4aba6e2c5488811bb8c4a7e742f8cdb7ed
Size: 22.49 kB - php-pecl-xdebug3-3.2.2-2.module+el8+1949+3bbc4295.x86_64.rpm
MD5: a2d228388e24a8332c190e208f6e7b35
SHA-256: 1fbef01ea7ec375bb7efe03ca2bc8465255d6c70a368d8c9c2373f93cfd05104
Size: 211.61 kB - php-pecl-xdebug3-debugsource-3.2.2-2.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 94d940f6ebaf9619f251be1a48b70587
SHA-256: c48614d5d64439906a0f976464d15e0210eda847af74cd77080afb0690ba173c
Size: 159.66 kB - php-pecl-zip-1.22.3-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: a18eaacc26a3d339b41457ac7057ebb6
SHA-256: 6fea3a6dd69f1a7cb0465733a24db59d1069643ba61178d159b9c413becbb0fb
Size: 59.57 kB - php-pecl-zip-debugsource-1.22.3-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 6db219ee0473583176c1c452eb2a8c88
SHA-256: 26d717e091c27e99892b436e1d5cd905facd2ab6cea73f17d65bab91bf129f24
Size: 36.09 kB - php-pgsql-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: a67308f30679d4984f8c69b6b37b7c88
SHA-256: fe88f8c01f8cbd73f243c4f4cfecaee8ef6127a8248c5f9a2aa8cc24bddd8dc4
Size: 121.86 kB - php-process-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 2f2dae915a175c790aff34bfda8f71d2
SHA-256: cd43c752ea77d44b2083d218a60ad8c095ab0cecd0aec230d47032b3f4e79c61
Size: 86.83 kB - php-snmp-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 9baf822274b854cea3f5bb703348f78d
SHA-256: fe4aa470599fce49ef62664659eadfea3b1e4dddf1e6b7dadb08976421910fef
Size: 78.15 kB - php-soap-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 326dec54f94a3645f1edf6d90485e90a
SHA-256: 56a1fcf226fa8acb1302f0744215a8734055074220d91864fea5c26b68892543
Size: 184.59 kB - php-xml-8.2.30-1.module+el8+1949+3bbc4295.x86_64.rpm
MD5: 76e6a1f3ee114e4d824395ea24893e26
SHA-256: cc2c89df2f18ab3f40271ed1ba0c0f0137f69a925c9e3716e3d1a800a7a3aad1
Size: 189.07 kB