Opened 10 months ago

Closed 9 months ago

Last modified 8 months ago

#22544 closed enhancement (fixed)

php-8.5.1

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: elevated Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (6)

comment:1 by zeckma, 10 months ago

Priority: normal → elevated

A component of PHP has been updated in this update, which fixes CVE-2025-67899 (Low): unbounded recursion and stack consumption. The specific component is uriparser. The email sent to oss-security for uriparser in particular can be found here: ​http://www.openwall.com/lists/oss-security/2025/12/15/1.

comment:2 by zeckma, 10 months ago

Full changelog

Security fixes

  • CVE-2025-14177 (Moderate): information Leak of Memory in getimagesize
  • CVE-2025-14178 (Moderate): heap buffer overflow in array_merge()
  • CVE-2025-14180 (Moderate): PDO quoting result null deref
  • CVE-2025-67899 (Low): unbounded recursion and stack consumption (uriparser issue)

18 Dec 2025

Core:

  • Sync all boost.context files with release 1.86.0.
  • Fixed bug GH-20435 (SensitiveParameter doesn't work for
  • named argument passing to variadic parameter).
  • Fixed bug GH-20546 (preserve_none attribute configure check on macOs issue).
  • Fixed bug GH-20286 (use-after-destroy during userland stream_close()).

Bz2:

  • Fix assertion failures resulting in crashes with stream filter object parameters.

DOM:

  • Fix memory leak when edge case is hit when registering xpath callback.
  • Fixed bug GH-20395 (querySelector and querySelectorAll requires elements in $selectors to be lowercase).
  • Fix missing NUL byte check on C14NFile().

Fibers:

  • Fixed bug GH-20483 (ASAN stack overflow with fiber.stack_size INI small value).

Intl:

  • Fixed bug GH-20426 (Spoofchecker::setRestrictionLevel() error message suggests missing constants).

Lexbor:

  • Fixed bug GH-20501 (\Uri\WhatWg\Url lose host after calling withPath() or withQuery()).
  • Fixed bug GH-20502 (\Uri\WhatWg\Url crashes (SEGV) when parsing malformed URL due to Lexbor memory corruption).

LibXML:

  • Fix some deprecations on newer libxml versions regarding input buffer/parser handling.

MySQLnd:

  • Fixed bug GH-20528 (Regression breaks mysql connexion using an IPv6 address enclosed in square brackets).

Opcache:

  • Fixed bug GH-20329 (opcache.file_cache broken with full interned string buffer).

PDO:

  • Fixed bug GH-20553 (PDO::FETCH_CLASSTYPE ignores $constructorArgs in PHP 8.5.0).
  • Fixed GHSA-8xr5-qppj-gvwj (PDO quoting result null deref). (CVE-2025-14180)

Phar:

  • Fixed bug GH-20442 (Phar does not respect case-insensitiveness of halt_compiler() when reading stub).
  • Fix broken return value of fflush() for phar file entries.
  • Fix assertion failure when fseeking a phar file out of bounds.

PHPDBG:

  • Fixed ZPP type violation in phpdbg_get_executable() and phpdbg_end_oplog().

SPL:

  • Fixed bug GH-20614 (SplFixedArray incorrectly handles references in deserialization).

Standard:

  • Fix memory leak in array_diff() with custom type checks.
  • Fixed bug GH-20583 (Stack overflow in http_build_query via deep structures).
  • Fixed GHSA-www2-q4fc-65wf (Null byte termination in dns_get_record()).
  • Fixed GHSA-h96m-rvf9-jgm2 (Heap buffer overflow in array_merge()). (CVE-20-25-14178)
  • Fixed GHSA-3237-qqm7-mfv7 (Information Leak of Memory in getimagesize). (CVE-2025-14177)

URI:

  • Fixed bug GH-20366 (ext/uri incorrectly throws ValueError when encountering null byte).
  • Fixed CVE-2025-67899 (uriparser through 0.9.9 allows unbounded recursion and stack consumption).

XML:

  • Fixed bug GH-20439 (xml_set_default_handler() does not properly handle special characters in attributes when passing data to callback).

Zip:

  • Fix crash in property existence test.
  • Don't truncate return value of zip_fread() with user sizes.

Zlib:

  • Fix assertion failures resulting in crashes with stream filter object parameters.
Last edited 10 months ago by Bruce Dubbs (previous) (diff)

comment:3 by Bruce Dubbs, 10 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:4 by Bruce Dubbs, 10 months ago

Fixed at commit 5d22e79fb6.

Leaving open for security advisory.

comment:5 by Douglas R. Reno, 9 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-064 issued

comment:6 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.