Merge version 8.4.21-1~deb13u1+rpi1 and 8.4.24-1~deb13u1 to produce 8.4.24-1~deb13u1... trixie-staging archive/raspbian/8.4.24-1_deb13u1+rpi1 raspbian/8.4.24-1_deb13u1+rpi1
authorRaspbian automatic forward porter <root@raspbian.org>
Sat, 5 Sep 2026 17:20:17 +0000 (18:20 +0100)
committerRaspbian automatic forward porter <root@raspbian.org>
Sat, 5 Sep 2026 17:20:17 +0000 (18:20 +0100)
1  2 
debian/changelog

index 4155ecab37110f967a5dad47c958989f81e404e5,492756df4ddf387dbff8124c0424159981f2d31c..699a46796485c756a9a12c0a5a85869935f01054
@@@ -1,9 -1,19 +1,26 @@@
- php8.4 (8.4.21-1~deb13u1+rpi1) trixie-staging; urgency=medium
++php8.4 (8.4.24-1~deb13u1+rpi1) trixie-staging; urgency=medium
 +
 +  [changes brought forward from 8.4.11-1+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Fri, 17 Oct 2025 01:23:38 +0000]
 +  * Fix fpu setting for raspbian.
 +
-  -- Raspbian forward porter <root@raspbian.org>  Thu, 21 May 2026 06:14:58 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Sat, 05 Sep 2026 17:20:16 +0000
++
+ php8.4 (8.4.24-1~deb13u1) trixie-security; urgency=high
+   * New upstream version 8.4.24 (Closes: #1143153)
+    + [CVE-2026-17544]: Out-of-bounds write in bccomp()
+    + [CVE-2026-17543]: SQL injection via E'...' backslash breakout
+    + [CVE-2026-7260]: Crash via recursive symlinks
+  -- Ondřej Surý <ondrej@debian.org>  Fri, 31 Jul 2026 07:11:11 +0200
+ php8.4 (8.4.23-1~deb13u1) trixie-security; urgency=high
+   * New upstream version 8.4.23
+    + [CVE-2026-14355]: Memory corruption (zend_mm_heap corrupted) in
+      openssl_encrypt with AES-WRAP-PAD.
+  -- Ondřej Surý <ondrej@debian.org>  Fri, 03 Jul 2026 14:26:56 +0200
  
  php8.4 (8.4.21-1~deb13u1) trixie-security; urgency=high