|
|
Log in / Subscribe / Register

Ubuntu alert USN-7953-1 (php7.2, php7.4, php8.1, php8.3, php8.4)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7953-1] PHP vulnerabilities
Date:  Mon, 12 Jan 2026 10:01:55 +0000
Message-ID:  <E1vfEkF-0005WL-VO@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7953-1 January 12, 2026 php7.2, php7.4, php8.1, php8.3, php8.4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in PHP. Software Description: - php8.4: HTML-embedded scripting language interpreter - php8.3: HTML-embedded scripting language interpreter - php8.1: HTML-embedded scripting language interpreter - php7.4: HTML-embedded scripting language interpreter - php7.2: HTML-embedded scripting language interpreter Details: It was discovered that PHP incorrectly handled memory while reading images in multi-chunk mode. An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 24.04 LTS, Ubuntu 25.04 and Ubuntu 25.10. (CVE-2025-14177) It was discovered that PHP incorrectly handled memory when element count exceeds 32-bit limit. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-14178) It was discovered that PHP incorrectly handled memory when using the PDO PostgreSQL driver. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.04 and Ubuntu 25.10. (CVE-2025-14180) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 php8.4 8.4.11-1ubuntu1.1 Ubuntu 25.04 php8.4 8.4.5-1ubuntu1.2 Ubuntu 24.04 LTS php8.3 8.3.6-0ubuntu0.24.04.6 Ubuntu 22.04 LTS php8.1 8.1.2-1ubuntu2.23 Ubuntu 20.04 LTS php7.4 7.4.3-4ubuntu2.29+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS php7.2 7.2.24-0ubuntu0.18.04.17+esm12 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7953-1 CVE-2025-14177, CVE-2025-14178, CVE-2025-14180 Package Information: https://launchpad.net/ubuntu/+source/php8.4/8.4.11-1ubunt... https://launchpad.net/ubuntu/+source/php8.4/8.4.5-1ubuntu1.2 https://launchpad.net/ubuntu/+source/php8.3/8.3.6-0ubuntu... https://launchpad.net/ubuntu/+source/php8.1/8.1.2-1ubuntu...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmlkxgIACgkQcpJm3tlz hgFyUg//VZA/sjaO6e+kwMrUm8Me+9wrOk089PAFgcbtxEUUBOYML9ivlvWO1ROC LkaF9tw0C86dL4oYX/rmlzD/VSlNdqlSHTud7LnHrxiZBj0bE9V9E7/EwWp7h/00 9Ankoz/EqUBZO3OvEZNHsTggLtNVuqG4AbehMLZAlnWbN/oBmlI6sNlutxSv5vGt crk+9oe8bCOPiDQi1QPmcF9wzk8a3SecaTSo/ibxoKuLpPClR0dExGUmMERLP7+L FHbvKdrTgrEC71V9Sbe1VgnSbUcK2EpnTCj2cJnUSldxQFq7Nno6xJKW0ZZhM0Ey SKEgzJHrxLAsWLSagvxCn+BwUM4o6qFjvx/8Owhn1nm5mfabtc4ADOpCEc+bf2A/ a7vmDeNo+4ziwRDA3Pt9TyclUrNWWDLXmCWSQmxG2fUsuIGousoJs4Xs8pQDtWqQ UIhacHSAtPvnqmBJLnXiqRuHxs9OBC7a+9yqDciL+Wqn+SNtsydFnLOgISFDolZ2 junqv/trpsYv3MEOVL6C1ueu6zMdK81lDkAEJYCyu+goS5eDAgZbTQQEgRzX6vtO Z0Kz81pnmUkDjVA3Yo4EQev7or/R6LQBX7rp1E4AbCVZb+DnBKfM90GhrfU8JtQO ejVnQgHeu8ylMhuURfE/9A0SWqezqmHylZPMimzUtJXQ1EMAk34= =kvxc -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds