[Git][security-tracker-team/security-tracker][master] 2 commits: Reserve DLA-4732-1 for php8.2
Guilhem Moulin (@guilhem)
guilhem at debian.org
Tue Aug 11 22:50:35 BST 2026
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4af3af7c by Guilhem Moulin at 2026-08-11T23:50:03+02:00
Reserve DLA-4732-1 for php8.2
- - - - -
df52eb40 by Guilhem Moulin at 2026-08-11T23:50:05+02:00
Reserve DLA-4733-1 for php7.4
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -10523,7 +10523,9 @@ CVE-2026-9672
- php8.4 8.4.24-1 (unimportant)
[trixie] - php8.4 8.4.24-1~deb13u1
- php8.2 <removed> (unimportant)
+ [bookworm] - php8.2 8.2.33-1~deb12u1
- php7.4 <removed> (unimportant)
+ [bullseye] - php7.4 7.4.33-1+deb11u12
NOTE: Fixed by: https://github.com/php/php-src/commit/b590f0380fda26ed180874a0255f0be078434315 (php-8.4.24)
CVE-2026-17544 (Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...)
{DSA-6406-1}
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,9 @@
+[11 Aug 2026] DLA-4733-1 php7.4 - security update
+ {CVE-2026-7260 CVE-2026-17543}
+ [bullseye] - php7.4 7.4.33-1+deb11u12
+[11 Aug 2026] DLA-4732-1 php8.2 - security update
+ {CVE-2026-7260 CVE-2026-17543}
+ [bookworm] - php8.2 8.2.33-1~deb12u1
[11 Aug 2026] DLA-4731-1 libgd2 - security update
{CVE-2026-9672}
[bullseye] - libgd2 2.3.0-2+deb11u2
=====================================
data/dla-needed.txt
=====================================
@@ -640,13 +640,6 @@ php-twig/bullseye
NOTE: 20260521: Added by Front-Desk (Beuc)
NOTE: 20260521: Cf. symfony batch of CVEs, upcoming DSA (Beuc/front-desk)
--
-php7.4/bullseye (guilhem)
- NOTE: 20260804: Added by Front-Desk (rouca)
- NOTE: 20260804: Follow DSA-6406-1 (rouca/front-desk)
---
-php8.2/bookworm (guilhem)
- NOTE: 20260804: Added by Front-Desk (rouca)
---
phpseclib/bullseye (Utkarsh)
NOTE: 20260518: Added by Front-Desk (Beuc)
NOTE: 20260518: Follow bookworm 12.14 (2 CVEs) (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/502211c70a775711b44ab9c85efd1de658f940ec...df52eb40821f03aee57b026b1b2aba8fc097df41
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/502211c70a775711b44ab9c85efd1de658f940ec...df52eb40821f03aee57b026b1b2aba8fc097df41
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/2e1a8d91/attachment.htm>
More information about the debian-security-tracker-commits
mailing list