Opened 4 months ago

Closed 2 months ago

#23420 closed enhancement (fixed)

php-8.5.7

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description (last modified by Bruce Dubbs)

New point version.

CVE-2026-44927   NIST: NVD   Base Score:  5.3 MEDIUM 
                 CNA:  MITRE Base Score:  2.9 LOW 

CVE-2026-44928   NIST: NVD   Base Score:  5.3 MEDIUM
                 CNA:  MITRE Base Score:  2.9 LOW 

Change History (6)

comment:1 by Bruce Dubbs, 4 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 4 months ago

Priority: normal → elevated

04 Jun 2026, PHP 8.5.7

  • CLI:
    • Fixed bug GH-21901 (Stale getopt() optional value).
  • Date:
    • Fixed bug GH-18422 (int overflow in php_date_llabs).
  • DOM:
    • Fixed bug GH-22077 (UAF in custom XPath function).
  • Opcache:
    • Fixed tracing JIT crash when a VM interrupt is handled during an observed user function call.
    • Fixed bug GH-21746 (Segfault with tracing JIT).
    • Fixed bug GH-22004 (Assertion failure at ext/opcache/jit/zend_jit_trace.c).
    • Fixed tailcall VM crash when a VM interrupt is handled from a VM helper.
  • OpenSSL:
    • Fix compatibility issues with OpenSSL 4.0.
  • Standard:
    • Fixed bug GH-21689 (version_compare() incorrectly handles versions ending with a dot).
  • URI:
    • Fixed CVE-2026-44927 (In uriparser before 1.0.2, there is pointer difference truncation to int in various places). (CVE-2026-44927)

  • Fixed CVE-2026-44928 (In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal). (CVE-2026-44928)

comment:3 by Bruce Dubbs, 4 months ago

Description: modified (diff)

comment:4 by Bruce Dubbs, 4 months ago

Owner: changed from Bruce Dubbs to SecurityAdvisory
Status: assigned → new

Fixed at commit c058033664. Leaving open for SA.

comment:5 by Bruce Dubbs, 3 months ago

Milestone: 13.1 → 98-Security

comment:6 by Bruce Dubbs, 2 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-162 has been issued.

Note: See TracTickets for help on using tickets.