Advisories ยป MGASA-2026-0458

Updated php package fixes security vulnerabilities

Publication date: 28 Sep 2026
Modification date: 28 Sep 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-91768 , CVE-2025-1218 , CVE-2026-91769 , CVE-2026-91767 , CVE-2026-6103 , CVE-2026-91765 , CVE-2025-14181 , CVE-2026-92842 , CVE-2026-91766 , CVE-2026-93682

Description

FILTER_SANITIZE_ENCODED does not encode 0xFF
IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address
comparison
Various packet overreads in mysqlnd wire protocol
TLS hostname verification falls back to CN after SAN mismatch
Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted
server certificate wildcard CN
Integer overflow in phar_tar_number() allowing TAR archive entry
injection
Unbounded recursion in server-side cleanup_xml_node()
Integer overflow to buffer overflow in SOAP HTTP parsing)
Out-of-bounds read in convert.* stream filters when line-break-chars
contains NUL
ross-origin credential leak in HTTP stream wrapper redirects
Out-of-bounds read in the HTTP stream wrapper when following a redirect
with an empty Location header
                

References

SRPMS

9/core