From: Raspbian automatic forward porter Date: Sat, 3 Oct 2026 04:47:49 +0000 (+0100) Subject: Merge version 8.4.24-1~deb13u1+rpi1 and 8.4.26-1~deb13u1 to produce 8.4.26-1~deb13u1... X-Git-Tag: archive/raspbian/8.4.26-1_deb13u1+rpi1^0 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=36efcc67a676599d5f57e7cd2187cb74e5be37a2;p=php8.4.git Merge version 8.4.24-1~deb13u1+rpi1 and 8.4.26-1~deb13u1 to produce 8.4.26-1~deb13u1+rpi1 --- 36efcc67a676599d5f57e7cd2187cb74e5be37a2 diff --cc debian/changelog index 699a4679,e991b1eb..ddeccf4d --- a/debian/changelog +++ b/debian/changelog @@@ -1,9 -1,30 +1,37 @@@ - php8.4 (8.4.24-1~deb13u1+rpi1) trixie-staging; urgency=medium ++php8.4 (8.4.26-1~deb13u1+rpi1) trixie-staging; urgency=medium + + [changes brought forward from 8.4.11-1+rpi1 by Peter Michael Green at Fri, 17 Oct 2025 01:23:38 +0000] + * Fix fpu setting for raspbian. + - -- Raspbian forward porter Sat, 05 Sep 2026 17:20:16 +0000 ++ -- Raspbian forward porter Sat, 03 Oct 2026 04:47:48 +0000 ++ + php8.4 (8.4.26-1~deb13u1) trixie-security; urgency=high + + * New upstream version 8.4.26 + + [CVE-2026-91768]: IPv6 ACL bypass in FastCGI listen.allowed_clients + due to partial address comparison. + + [CVE-2025-1218]: Various packet overreads in mysqlnd wire protocol. + + [CVE-2026-91769]: TLS hostname verification falls back to CN after + SAN mismatch. + + [CVE-2026-91767]: Heap buffer overflow in + php_openssl_matches_wildcard_name() on crafted server certificate + wildcard CN. + + [CVE-2026-6103]: Integer overflow in phar_tar_number() allowing TAR + archive entry injection. + + [CVE-2026-91765]: Unbounded recursion in server-side + cleanup_xml_node(). + + [CVE-2025-14181]: Integer overflow to buffer overflow in SOAP HTTP + parsing. + + [CVE-2026-93682]: Out-of-bounds read in the HTTP stream wrapper when + following a redirect with an empty Location header. + + [CVE-2026-92842]: Out-of-bounds read in convert.* stream filters when + line-break-chars contains NUL. + + [CVE-2026-91766]: Cross-origin credential leak in HTTP stream wrapper + redirects. + + [CVE-2026-17545]: Reserved device names are not rejected before file + and stream I/O. + + -- Ondřej Surý Thu, 24 Sep 2026 19:16:18 +0200 php8.4 (8.4.24-1~deb13u1) trixie-security; urgency=high