stable

php-8.4.16-1.fc43

FEDORA-2025-7e9290d67f created by remi a month ago for Fedora 43

PHP version 8.4.16 (18 Dec 2025)

Core:

  • Sync all boost.context files with release 1.86.0. (mvorisek)
  • Fixed bug GH-20435 (SensitiveParameter doesn't work for named argument passing to variadic parameter). (ndossche)
  • Fixed bug GH-20286 (use-after-destroy during userland stream_close()). (ndossche, David Carlier)

Bz2:

  • Fix assertion failures resulting in crashes with stream filter object parameters. (ndossche)

Date:

  • Fix crashes when trying to instantiate uninstantiable classes via date static constructors. (ndossche)

DOM:

  • Fix memory leak when edge case is hit when registering xpath callback. (ndossche)
  • Fixed bug GH-20395 (querySelector and querySelectorAll requires elements in $selectors to be lowercase). (ndossche)
  • Fix missing NUL byte check on C14NFile(). (ndossche)

Fibers:

  • Fixed bug GH-20483 (ASAN stack overflow with fiber.stack_size INI small value). (David Carlier)

FTP:

  • Fixed bug GH-20601 (ftp_connect overflow on timeout). (David Carlier)

GD:

  • Fixed bug GH-20511 (imagegammacorrect out of range input/output values). (David Carlier)
  • Fixed bug GH-20602 (imagescale overflow with large height values). (David Carlier)

Intl:

  • Fixed bug GH-20426 (Spoofchecker::setRestrictionLevel() error message suggests missing constants). (DanielEScherzer)

LibXML:

  • Fix some deprecations on newer libxml versions regarding input buffer/parser handling. (ndossche)

MbString:

  • Fixed bug GH-20491 (SLES15 compile error with mbstring oniguruma). (ndossche)
  • Fixed bug GH-20492 (mbstring compile warning due to non-strings). (ndossche)

MySQLnd:

  • Fixed bug GH-20528 (Regression breaks mysql connexion using an IPv6 address enclosed in square brackets). (Remi)

Opcache:

  • Fixed bug GH-20329 (opcache.file_cache broken with full interned string buffer). (Arnaud)

PDO:

Phar:

  • Fixed bug GH-20442 (Phar does not respect case-insensitiveness of __halt_compiler() when reading stub). (ndossche, TimWolla)
  • Fix broken return value of fflush() for phar file entries. (ndossche)
  • Fix assertion failure when fseeking a phar file out of bounds. (ndossche)

PHPDBG:

  • Fixed ZPP type violation in phpdbg_get_executable() and phpdbg_end_oplog(). (Girgias)

SPL:

  • Fixed bug GH-20614 (SplFixedArray incorrectly handles references in deserialization). (ndossche)

Standard:

  • Fix memory leak in array_diff() with custom type checks. (ndossche)
  • Fixed bug GH-20583 (Stack overflow in http_build_query via deep structures). (ndossche)
  • Fixed GHSA-www2-q4fc-65wf (Null byte termination in dns_get_record()). (ndossche)
  • Fixed GHSA-h96m-rvf9-jgm2 (Heap buffer overflow in array_merge()). (CVE-2025-14178) (ndossche)
  • Fixed GHSA-3237-qqm7-mfv7 (Information Leak of Memory in getimagesize). (CVE-2025-14177) (ndossche)

Tidy:

  • Fixed bug GH-20374 (PHP with tidy and custom-tags). (ndossche)

XML:

  • Fixed bug GH-20439 (xml_set_default_handler() does not properly handle special characters in attributes when passing data to callback). (ndossche)

Zlib:

  • Fix assertion failures resulting in crashes with stream filter object parameters. (ndossche)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2025-7e9290d67f

This update has been submitted for testing by remi.

a month ago

This update's test gating status has been changed to 'waiting'.

a month ago

This update's test gating status has been changed to 'passed'.

a month ago
User Icon imabug provided feedback a month ago
karma
karma

This update has been pushed to testing.

a month ago

This update can be pushed to stable now if the maintainer wishes

a month ago

This update has been submitted for stable by remi.

a month ago

This update has been pushed to stable.

a month ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
2
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
a month ago
in testing
a month ago
in stable
a month ago
approved
a month ago

Automated Test Results