|
|
Log in / Subscribe / Register

Debian alert DLA-4586-1 (php7.4)

From:  Guilhem Moulin <guilhem@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4586-1] php7.4 security update
Date:  Sat, 16 May 2026 00:59:04 +0200
Message-ID:  <agelOHMhvK328yq0@debian.org>

------------------------------------------------------------------------- Debian LTS Advisory DLA-4586-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin May 16, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : php7.4 Version : 7.4.33-1+deb11u11 CVE ID : CVE-2026-6722 CVE-2026-6735 CVE-2026-7258 CVE-2026-7261 CVE-2026-7262 CVE-2026-7568 Debian Bug : 1136054 Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in remote code execution, information disclosure, denial of service. CVE-2026-6722 A use-after-free issue was discovered in the SOAP extension which may lead to remote code execution when an apache:Map node contains duplicate key. CVE-2026-6735 Conrad Draper discovered that the request URI within the PHP-FPM status page was improperly sanitized, thereby allowing cross-site scripting (XSS). CVE-2026-7258 An out-of-bounds read issue was discovered in `urldecode()`, which may lead to denial of service on some platforms. CVE-2026-7261 Ilia Alshanetsky discovered a use-after-free issue after header parsing failure when SoapServer is configured with SOAP_PERSISTENCE_SESSION, which may lead to denial of service. CVE-2026-7262 Ilia Alshanetsky discovered a NULL pointer deference issue in SOAP apache:Map decoder with missing `<value>` element, thereby leading to denial of service. CVE-2026-7568 Aleksey Solovev discovered a signed integer overflow in the `metaphone()` function from the PHP standard library. For Debian 11 bullseye, these problems have been fixed in version 7.4.33-1+deb11u11. We recommend that you upgrade your php7.4 packages. For the detailed security status of php7.4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php7.4 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmoHpTYACgkQ05pJnDwh pVJW9Q/+OA0rl++k3+2K4HD2zx/fD2I7EEAH4RjXmevXGEHAphZPvdGyYrn74nPY fBQSduae9mqhlprG4IwEzY6/hGUjiNLF+7lOJg6ajoI6nazkmkc2dX/Rp5AmmXkP uB61sXuWw6Zr4iOBlZ49IEp37NP5IH+kTac0pLuQAL2NsiVFZ00fp9Bw+VUU904S Mm3/ySrgrlo6Om6ctG5Yp1CJsfBoQitA2tGF9vsdKtsbZaizBa4Sc6qSQ8Vrls0+ 9t6FAuujbu8d5EfNeBL0Tazlp5ruTXT5SDbeJD5p4BX/5gYfcyjODtYb+pIKPEAz Xz6IUlMDc/xzCrkQTttRYHpVXJ18PqoLTqB6LMxWDptHt8xexNbyqrcil//Bj2a9 hVxZ0lm9XVTpK3B46TDrQe+dvserUYyONtY+YzXwO65Z1LP6+2eYKrf23yAzqDZW jxQ+/4gH/cIMmegbNFJTGlX3O7yjAfrnbAO7Ucw5DByWeYXGa6RMi3oRgFD9uyew k3TDl5/ISBEajC8/yccdjg6TQ3YvFIhnkPJs3e+jGtmHkmy/J1oFR19GGAcAhs5a g9vDl7mnbKGRvPyi8qCDr5+Uj0gtbnwNHjoA7VdTWbDuvZFEXcVpCo5UwoA5Nk0S MQrXCcgt78KIL1UN3PrRz13wxOsu3s9YTMAoCOnFqXiwZt3bmxQ= =/N58 -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds