[Git][security-tracker-team/security-tracker][master] Track fixed version for php8.4 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 31 15:45:56 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
082a8650 by Salvatore Bonaccorso at 2026-07-31T16:45:18+02:00
Track fixed version for php8.4 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -679,19 +679,19 @@ CVE-2026-9672
 	- php7.4 <removed> (unimportant)
 	NOTE: Fixed by: https://github.com/php/php-src/commit/b590f0380fda26ed180874a0255f0be078434315 (php-8.4.24)
 CVE-2026-17544 (Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...)
-	- php8.4 <unfixed> (bug #1143153)
+	- php8.4 8.4.24-1 (bug #1143153)
 	- php8.2 <removed>
 	- php7.4 <removed>
 	NOTE: https://github.com/php/php-src/security/advisories/GHSA-x692-q9x7-8c3f
 	NOTE: Fixed by: https://github.com/php/php-src/commit/fa18dab73f9340448c0d5c0a1d75d3fec844b358 (php-8.4.24)
 CVE-2026-17543 (Improper escaping of backslashes in attacker-provided parameters would ...)
-	- php8.4 <unfixed> (bug #1143153)
+	- php8.4 8.4.24-1 (bug #1143153)
 	- php8.2 <removed>
 	- php7.4 <removed>
 	NOTE: https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4
 	NOTE: Fixed by: https://github.com/php/php-src/commit/53ac7025451c6481d44cf1835bb8385299a6a3a3 (php-8.4.24)
 CVE-2026-7260 (Circular symbolic links in phar archives could lead to unbounded recur ...)
-	- php8.4 <unfixed> (bug #1143153)
+	- php8.4 8.4.24-1 (bug #1143153)
 	- php8.2 <removed>
 	- php7.4 <removed>
 	NOTE: https://github.com/php/php-src/security/advisories/GHSA-vc5h-9ppw-p5f3



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/082a86509c465f2b52a47d58ea6df9cd1a815209

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/082a86509c465f2b52a47d58ea6df9cd1a815209
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/e9b5f95f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list