]> dgit.raspbian.org Git - php8.4.git/commitdiff
Merge version 8.4.24-1~deb13u1+rpi1 and 8.4.26-1~deb13u1 to produce 8.4.26-1~deb13u1... trixie-staging archive/raspbian/8.4.26-1_deb13u1+rpi1 raspbian/8.4.26-1_deb13u1+rpi1
authorRaspbian automatic forward porter <root@raspbian.org>
Sat, 3 Oct 2026 04:47:49 +0000 (05:47 +0100)
committerRaspbian automatic forward porter <root@raspbian.org>
Sat, 3 Oct 2026 04:47:49 +0000 (05:47 +0100)
1  2 
debian/changelog

index 699a46796485c756a9a12c0a5a85869935f01054,e991b1ebbd0e811426a9bd60fde6c7a54bee446e..ddeccf4dbdec67cd770efa96f47ea098a6724fad
@@@ -1,9 -1,30 +1,37 @@@
- php8.4 (8.4.24-1~deb13u1+rpi1) trixie-staging; urgency=medium
++php8.4 (8.4.26-1~deb13u1+rpi1) trixie-staging; urgency=medium
 +
 +  [changes brought forward from 8.4.11-1+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Fri, 17 Oct 2025 01:23:38 +0000]
 +  * Fix fpu setting for raspbian.
 +
-  -- Raspbian forward porter <root@raspbian.org>  Sat, 05 Sep 2026 17:20:16 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Sat, 03 Oct 2026 04:47:48 +0000
++
+ php8.4 (8.4.26-1~deb13u1) trixie-security; urgency=high
+ 
+   * New upstream version 8.4.26
+    + [CVE-2026-91768]: IPv6 ACL bypass in FastCGI listen.allowed_clients
+      due to partial address comparison.
+    + [CVE-2025-1218]: Various packet overreads in mysqlnd wire protocol.
+    + [CVE-2026-91769]: TLS hostname verification falls back to CN after
+      SAN mismatch.
+    + [CVE-2026-91767]: Heap buffer overflow in
+      php_openssl_matches_wildcard_name() on crafted server certificate
+      wildcard CN.
+    + [CVE-2026-6103]: Integer overflow in phar_tar_number() allowing TAR
+      archive entry injection.
+    + [CVE-2026-91765]: Unbounded recursion in server-side
+      cleanup_xml_node().
+    + [CVE-2025-14181]: Integer overflow to buffer overflow in SOAP HTTP
+      parsing.
+    + [CVE-2026-93682]: Out-of-bounds read in the HTTP stream wrapper when
+      following a redirect with an empty Location header.
+    + [CVE-2026-92842]: Out-of-bounds read in convert.* stream filters when
+      line-break-chars contains NUL.
+    + [CVE-2026-91766]: Cross-origin credential leak in HTTP stream wrapper
+      redirects.
+    + [CVE-2026-17545]: Reserved device names are not rejected before file
+      and stream I/O.
+ 
+  -- Ondřej Surý <ondrej@debian.org>  Thu, 24 Sep 2026 19:16:18 +0200
  
  php8.4 (8.4.24-1~deb13u1) trixie-security; urgency=high