From: Raspbian automatic forward porter Date: Sat, 5 Sep 2026 17:20:17 +0000 (+0100) Subject: Merge version 8.4.21-1~deb13u1+rpi1 and 8.4.24-1~deb13u1 to produce 8.4.24-1~deb13u1... X-Git-Tag: archive/raspbian/8.4.24-1_deb13u1+rpi1^0 X-Git-Url: https://dgit.raspbian.org/%22http:/www.example.com/cgi//%22https:/www.geocaching.com/profile/%22http:/www.example.com/cgi/%22https:/www.geocaching.com/profile?a=commitdiff_plain;h=513671529014bdb78cd41f0c823f45b8098b55d8;p=php8.4.git Merge version 8.4.21-1~deb13u1+rpi1 and 8.4.24-1~deb13u1 to produce 8.4.24-1~deb13u1+rpi1 --- 513671529014bdb78cd41f0c823f45b8098b55d8 diff --cc debian/changelog index 4155ecab,492756df..699a4679 --- a/debian/changelog +++ b/debian/changelog @@@ -1,9 -1,19 +1,26 @@@ - php8.4 (8.4.21-1~deb13u1+rpi1) trixie-staging; urgency=medium ++php8.4 (8.4.24-1~deb13u1+rpi1) trixie-staging; urgency=medium + + [changes brought forward from 8.4.11-1+rpi1 by Peter Michael Green at Fri, 17 Oct 2025 01:23:38 +0000] + * Fix fpu setting for raspbian. + - -- Raspbian forward porter Thu, 21 May 2026 06:14:58 +0000 ++ -- Raspbian forward porter Sat, 05 Sep 2026 17:20:16 +0000 ++ + php8.4 (8.4.24-1~deb13u1) trixie-security; urgency=high + + * New upstream version 8.4.24 (Closes: #1143153) + + [CVE-2026-17544]: Out-of-bounds write in bccomp() + + [CVE-2026-17543]: SQL injection via E'...' backslash breakout + + [CVE-2026-7260]: Crash via recursive symlinks + + -- Ondřej Surý Fri, 31 Jul 2026 07:11:11 +0200 + + php8.4 (8.4.23-1~deb13u1) trixie-security; urgency=high + + * New upstream version 8.4.23 + + [CVE-2026-14355]: Memory corruption (zend_mm_heap corrupted) in + openssl_encrypt with AES-WRAP-PAD. + + -- Ondřej Surý Fri, 03 Jul 2026 14:26:56 +0200 php8.4 (8.4.21-1~deb13u1) trixie-security; urgency=high