Updated php package fixes security vulnerabilities
Publication date: 28 Sep 2026Modification date: 28 Sep 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-91768 , CVE-2025-1218 , CVE-2026-91769 , CVE-2026-91767 , CVE-2026-6103 , CVE-2026-91765 , CVE-2025-14181 , CVE-2026-92842 , CVE-2026-91766 , CVE-2026-93682
Description
FILTER_SANITIZE_ENCODED does not encode 0xFF
IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address
comparison
Various packet overreads in mysqlnd wire protocol
TLS hostname verification falls back to CN after SAN mismatch
Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted
server certificate wildcard CN
Integer overflow in phar_tar_number() allowing TAR archive entry
injection
Unbounded recursion in server-side cleanup_xml_node()
Integer overflow to buffer overflow in SOAP HTTP parsing)
Out-of-bounds read in convert.* stream filters when line-break-chars
contains NUL
ross-origin credential leak in HTTP stream wrapper redirects
Out-of-bounds read in the HTTP stream wrapper when following a redirect
with an empty Location header
References
- https://bugs.mageia.org/show_bug.cgi?id=36367
- https://www.php.net/ChangeLog-8.php#8.2.34
- https://www.cve.org/CVERecord?id=CVE-2026-91768
- https://www.cve.org/CVERecord?id=CVE-2025-1218
- https://www.cve.org/CVERecord?id=CVE-2026-91769
- https://www.cve.org/CVERecord?id=CVE-2026-91767
- https://www.cve.org/CVERecord?id=CVE-2026-6103
- https://www.cve.org/CVERecord?id=CVE-2026-91765
- https://www.cve.org/CVERecord?id=CVE-2025-14181
- https://www.cve.org/CVERecord?id=CVE-2026-92842
- https://www.cve.org/CVERecord?id=CVE-2026-91766
- https://www.cve.org/CVERecord?id=CVE-2026-93682
SRPMS
9/core
- php-8.2.34-1.mga9