[ubuntu/resolute-security] php8.5 8.5.4-0ubuntu1.2 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Mon Jul 20 12:38:36 UTC 2026


php8.5 (8.5.4-0ubuntu1.2) resolute-security; urgency=medium

  * SECURITY UPDATE: DoS via failure to setup TLS with a remote server
    - debian/patches/CVE-2026-12184.patch: Fix NULL deref when enabling TLS
      fails and the peer name needs to be reset in
      ext/openssl/tests/gh21031.phpt,
      ext/openssl/tests/sni_server_cs_expired.pem,
      ext/standard/http_fopen_wrapper.c.
    - CVE-2026-12184
  * SECURITY UPDATE: Memory corruption in openssl_encrypt with AES-WRAP-PAD
    - debian/patches/CVE-2026-14355.patch: ext/openssl: openssl_encrypt() zend
      mm heap overflow on AES-WRAP-PAD mode. in
      ext/openssl/openssl_backend_common.c, ext/openssl/tests/gh22186.phpt.
    - CVE-2026-14355

Date: 2026-07-16 23:21:11.991860+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/php8.5/8.5.4-0ubuntu1.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list