- php8.4 (8.4.24-1~deb13u1+rpi1) trixie-staging; urgency=medium
++php8.4 (8.4.26-1~deb13u1+rpi1) trixie-staging; urgency=medium
+
+ [changes brought forward from 8.4.11-1+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Fri, 17 Oct 2025 01:23:38 +0000]
+ * Fix fpu setting for raspbian.
+
- -- Raspbian forward porter <root@raspbian.org> Sat, 05 Sep 2026 17:20:16 +0000
++ -- Raspbian forward porter <root@raspbian.org> Sat, 03 Oct 2026 04:47:48 +0000
++
+ php8.4 (8.4.26-1~deb13u1) trixie-security; urgency=high
+
+ * New upstream version 8.4.26
+ + [CVE-2026-91768]: IPv6 ACL bypass in FastCGI listen.allowed_clients
+ due to partial address comparison.
+ + [CVE-2025-1218]: Various packet overreads in mysqlnd wire protocol.
+ + [CVE-2026-91769]: TLS hostname verification falls back to CN after
+ SAN mismatch.
+ + [CVE-2026-91767]: Heap buffer overflow in
+ php_openssl_matches_wildcard_name() on crafted server certificate
+ wildcard CN.
+ + [CVE-2026-6103]: Integer overflow in phar_tar_number() allowing TAR
+ archive entry injection.
+ + [CVE-2026-91765]: Unbounded recursion in server-side
+ cleanup_xml_node().
+ + [CVE-2025-14181]: Integer overflow to buffer overflow in SOAP HTTP
+ parsing.
+ + [CVE-2026-93682]: Out-of-bounds read in the HTTP stream wrapper when
+ following a redirect with an empty Location header.
+ + [CVE-2026-92842]: Out-of-bounds read in convert.* stream filters when
+ line-break-chars contains NUL.
+ + [CVE-2026-91766]: Cross-origin credential leak in HTTP stream wrapper
+ redirects.
+ + [CVE-2026-17545]: Reserved device names are not rejected before file
+ and stream I/O.
+
+ -- Ondřej Surý <ondrej@debian.org> Thu, 24 Sep 2026 19:16:18 +0200
php8.4 (8.4.24-1~deb13u1) trixie-security; urgency=high