[ubuntu/resolute-security] php8.5 8.5.4-0ubuntu1.2 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Mon Jul 20 12:38:36 UTC 2026
php8.5 (8.5.4-0ubuntu1.2) resolute-security; urgency=medium
* SECURITY UPDATE: DoS via failure to setup TLS with a remote server
- debian/patches/CVE-2026-12184.patch: Fix NULL deref when enabling TLS
fails and the peer name needs to be reset in
ext/openssl/tests/gh21031.phpt,
ext/openssl/tests/sni_server_cs_expired.pem,
ext/standard/http_fopen_wrapper.c.
- CVE-2026-12184
* SECURITY UPDATE: Memory corruption in openssl_encrypt with AES-WRAP-PAD
- debian/patches/CVE-2026-14355.patch: ext/openssl: openssl_encrypt() zend
mm heap overflow on AES-WRAP-PAD mode. in
ext/openssl/openssl_backend_common.c, ext/openssl/tests/gh22186.phpt.
- CVE-2026-14355
Date: 2026-07-16 23:21:11.991860+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/php8.5/8.5.4-0ubuntu1.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list