Opened 2 months ago

Closed 2 months ago

#23607 closed enhancement (fixed)

php-8.5.8

Reported by: Joe Locash Owned by: Bruce Dubbs
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version. Fixes CVE-2026-14355. See ​https://www.php.net/ChangeLog-8.php for changes.

Change History (4)

comment:1 by Bruce Dubbs, 2 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 2 months ago

02 Jul 2026, PHP 8.5.8

  • Core:
    • Fixed bug GH-22280 (Incorrect compile error for goto to label preceding try/finally block)
    • Fixed bug GH-22112 (Assertion when error handler throws during NaN to bool/string coercion)
  • BCMath:
    • Fixed issues with oversized allocations and signed overflow in bcround() and BcMath\Number::round()
  • Date:
    • Fix incorrect recurrence check of DatePeriod::createFromISO8601String().
  • Exif:
    • Read correct value for single and double tags.

  • GD:
    • Fixed bug GH-22121 (Double free in gdImageSetStyle() after overflow-triggered early return)
  • Intl:
    • Fix incorrect argument positions for invalid start/end arguments in transliterator_transliterate()
    • Fixed IntlTimeZone::getDisplayName() to synchronize object error state for invalid display types
  • Opcache:
    • Fixed bug GH-22265 (Another tailcall vm_interrupt bug).
    • Fixed bug GH-20469 (Unsafe inheritance cache replay with reentrant autoloading)
    • Fixed bug GH-21972 (Corrupted variable type when a typed by-value return contains a reference wrapper)

  • Phar:
    • Fixed a bypass of the magic ".phar" directory protection in Phar::addEmptyDir() for paths starting with "/-phar", while allowing non-magic directory names that merely share the "-phar" prefix.
  • Reflection:
    • Preserve class-name case in ReflectionClass::getProperty() error messages and autoloading

  • SOAP:
    • Fixed bug GH-22218 (SoapServer::handle() crash on $_SERVER not being an array)- (David Carlier / Rex-Reynolds)
    • Fixed bug GH-22285 (Soap server requires the raw input to be passed to $server->handle)
  • Sqlite:
    • Fix error checks for column retrieval.
  • URI:
    • Add LEXBOR_STATIC to CFLAGS_URI on Windows so ext/uri does not see LXB_API as declspec(dllimport) when linked statically into PHP-
    • Clean error logs before each Uri\WhatWg\Url wither call so that errors from previous wither calls are not returned the next time a UrlValidationError is thrown
  • Zip:
    • Fixed error-related memory leaks.
  • Zlib:
    • Fixed memory leak if deflate initialization fails and there is a dict.
    • Fixed memory leak in inflate_add().

comment:3 by Bruce Dubbs, 2 months ago

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

NIST CVSS Base Score: 5.3 MEDIUM

comment:4 by Bruce Dubbs, 2 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at commits

0f21bc3a63 Update to php-8.5.8.   Advisory sa-13.0-142.
e2f5bfb1e4 Update to xfsprogs-7.1.1.
Note: See TracTickets for help on using tickets.