stable

php-8.4.24-1.fc43

FEDORA-2026-d755ca77c4 created by remi 2 weeks ago for Fedora 43

PHP version 8.4.24 (30 Jul 2026)

BCMath:

Calendar:

  • Fixed bug GH-22602 (gregoriantojd() and juliantojd() integer overflow with INT_MAX year). (arshidkv12)

Date:

  • Update timelib to 2022.17. (Derick)
  • Fixed bug GH-19803 (Parsing a string with a single white space does create an error). (Derick)
  • Fixed Unix timestamps in February of the year 0 are misparsed with @-notation. (LukasGelbmann)
  • Fixed bug GH-11310 (__debugInfo does nothing on userland classes extending Date classes). (Derick)

DBA:

  • Fixed OOB read on malformed length field in dba flatfile handler. (alhudz)

DOM:

  • Fixed bug GH-22570 (Stack overflow when serializing a deeply nested Dom\XMLDocument). (iliaal)

Exif:

  • Fixed bug GH-11020 (exif_read_data() emits a spurious "Illegal IFD size" warning when an IFD is not followed by a next-IFD offset). (Eyüp Can Akman)

Hash:

  • Fixed bug GH-18173 (ext/hash relies on implementation-defined malloc alignment). (iliaal)

Intl:

  • Fixed Locale::lookup() and locale_lookup() to return NULL instead of the fallback locale when a language tag cannot be canonicalized. (Weilin Du)
  • Fixed memory leaks when calling Collator::__construct() or Spoofchecker::__construct() twice. (Weilin Du)
  • Fixed IntlChar methods leaving stale global error state after successful calls. (Xuyang Zhang)

ODBC:

  • Fixed bug GH-22668 (Heap buffer over-read when a column value exceeds the driver-reported display size). (iliaal)

OpenSSL:

  • Fixed timeout for supplemental read at end of a blocking stream in SSL stream wrapper. (ilutov)

PDO_ODBC:

  • Fixed bug GH-20726 (Crash with ODBC connection pooling when the DSN carries no credentials). (iliaal)
  • Fixed bug GH-22667 (Heap buffer over-read when a column value exceeds the driver-reported display size). (iliaal)
  • Fixed bug GH-22666 (Heap buffer overflow when an output parameter value is longer than the declared maxlen). (iliaal)
  • Fixed bug GH-22665 (Out-of-bounds write when the ODBC driver reports a diagnostic message length beyond the error buffer). (iliaal)

PGSQL:

  • Fixed GHSA-7qpv-r5mr-78m4 (SQL injection via E'...' backslash breakout). (CVE-2026-17543) (ilutov)

Phar:

  • Fixed inconsistent handling of the magic ".phar" directory. Paths such as "/.phar" remain protected, while non-magic paths that merely start with ".phar" are handled consistently across file and directory creation, copying, ArrayAccess, stream lookup, directory iteration and extraction. (Weilin Du)
  • Fixed GHSA-vc5h-9ppw-p5f3 (Crash via recursive symlinks). (CVE-2026-7260) (Jakub Zelenka)

PHPDBG:

  • Fixed bug GH-17387 (Trivial crash in phpdbg lexer). (iliaal)
  • Fixed fleaked lowercased lookup keys in phpdbg_resolve_opline_break. (jorgsowa)
  • Fixed off-by-one in phpdbg_safe_class_lookup() causing class lookups to always fail during phpdbg's signal-safe interruption path. (jorgsowa)

Reflection:

  • Fixed bug GH-22324 (Ignore leading namespace separator in ReflectionParameter::__construct()). (jorgsowa)
  • Fixed bug GH-22441 (ReflectionClass::hasProperty() and getProperty() ignore dynamic properties shadowing a private parent property). (iliaal)
  • Fixed bug GH-22658 (ReflectionConstant::__toString() with a string value with null bytes truncates output). (DanielEScherzer)
  • Fixed bug GH-22681 (Reflection*::__toString() truncates on null bytes). (DanielEScherzer)

Session:

  • Fixed bug GH-21314 (Different session garbage collector behavior between PHP 8.3 and PHP 8.5). (jorgsowa)

SPL:

  • Fix class_parents for classes with leading slash in non-autoload mode. (jorgsowa)
  • Ignore leading back-slash in class_parents(), class_implements(), and class_uses(). (jorgsowa)
  • Fixed bug GH-16217 (SplFileObject::fputcsv() on an uninitialized object segfaults). (iliaal)

Standard:

  • Fixed bug GH-22360 (convert.base64-encode corruption on incremental flush). (David Carlier)
  • Fixed bug GH-22395 (base_convert() outputs at most 64 characters). (Weilin Du)
  • Fixed integer overflow in getimagesize() and getimagesizefromstring() when parsing an IFF chunk with a size of INT_MAX. (David Carlier, Weilin Du)
  • Fixed bug GH-22678 (Use-after-free in array_multisort() when the comparator mutates the array being sorted). (azchin, iliaal)

Streams:

  • Fixed bug GH-22617 (persistent stream keys truncated at null bytes, causing distinct abstract unix domain sockets to share a resource). (David Carlier)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-d755ca77c4

This update has been submitted for testing by remi.

2 weeks ago

This update's test gating status has been changed to 'waiting'.

2 weeks ago

This update's test gating status has been changed to 'passed'.

2 weeks ago

This update has been pushed to testing.

2 weeks ago

remi edited this update.

a week ago

This update has been submitted for stable by bodhi.

a week ago

This update has been pushed to stable.

a week ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
2 weeks ago
in testing
2 weeks ago
in stable
a week ago
modified
a week ago
approved
a week ago
BZ#2511423 CVE-2026-17544 php: PHP: Arbitrary code execution via out-of-bounds write in bccomp() [fedora-all]
0
0

Automated Test Results