- php8.4 (8.4.21-1~deb13u1+rpi1) trixie-staging; urgency=medium
++php8.4 (8.4.24-1~deb13u1+rpi1) trixie-staging; urgency=medium
+
+ [changes brought forward from 8.4.11-1+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Fri, 17 Oct 2025 01:23:38 +0000]
+ * Fix fpu setting for raspbian.
+
- -- Raspbian forward porter <root@raspbian.org> Thu, 21 May 2026 06:14:58 +0000
++ -- Raspbian forward porter <root@raspbian.org> Sat, 05 Sep 2026 17:20:16 +0000
++
+ php8.4 (8.4.24-1~deb13u1) trixie-security; urgency=high
+
+ * New upstream version 8.4.24 (Closes: #1143153)
+ + [CVE-2026-17544]: Out-of-bounds write in bccomp()
+ + [CVE-2026-17543]: SQL injection via E'...' backslash breakout
+ + [CVE-2026-7260]: Crash via recursive symlinks
+
+ -- Ondřej Surý <ondrej@debian.org> Fri, 31 Jul 2026 07:11:11 +0200
+
+ php8.4 (8.4.23-1~deb13u1) trixie-security; urgency=high
+
+ * New upstream version 8.4.23
+ + [CVE-2026-14355]: Memory corruption (zend_mm_heap corrupted) in
+ openssl_encrypt with AES-WRAP-PAD.
+
+ -- Ondřej Surý <ondrej@debian.org> Fri, 03 Jul 2026 14:26:56 +0200
php8.4 (8.4.21-1~deb13u1) trixie-security; urgency=high