-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
[slackware-security] php (SSA:2026-267-01)
New php packages are available for Slackware 15.0 and -current to
fix security issues.
Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
extra/php82/php82-8.2.34-i586-1_slack15.0.txz: Upgraded.
This update fixes security issues:
FPM: IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address
comparison.
OpenSSL: TLS hostname verification falls back to CN after SAN mismatch.
OpenSSL: Heap buffer overflow in php_openssl_matches_wildcard_name() on
crafted server certificate wildcard CN.
Phar: Integer overflow in phar_tar_number() allowing TAR archive entry
injection.
SOAP: Unbounded recursion in server-side cleanup_xml_node().
SOAP: Integer overflow to buffer overflow in SOAP HTTP parsing.
Standard: Out-of-bounds read in convert.* stream filters when
line-break-chars contains NUL.
Standard: Cross-origin credential leak in HTTP stream wrapper redirects.
Standard: Out-of-bounds read in the HTTP stream wrapper when following a
redirect with an empty Location header.
For more information, see:
https://www.php.net/ChangeLog-8.php#8.2.34
https://www.cve.org/CVERecord?id=CVE-2026-91768
https://www.cve.org/CVERecord?id=CVE-2025-1218
https://www.cve.org/CVERecord?id=CVE-2026-91769
https://www.cve.org/CVERecord?id=CVE-2026-91767
https://www.cve.org/CVERecord?id=CVE-2026-6103
https://www.cve.org/CVERecord?id=CVE-2026-91765
https://www.cve.org/CVERecord?id=CVE-2025-14181
https://www.cve.org/CVERecord?id=CVE-2026-92842
https://www.cve.org/CVERecord?id=CVE-2026-91766
https://www.cve.org/CVERecord?id=CVE-2026-93682
https://www.cve.org/CVERecord?id=CVE-2026-17545
(* Security fix *)
+--------------------------+
Where to find the new packages:
+-----------------------------+
Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)
Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.
Updated package for Slackware 15.0:
php82-8.2.34-i586-1_slack15.0.txz
Updated package for Slackware x86_64 15.0:
php82-8.2.34-x86_64-1_slack15.0.txz
Updated package for Slackware -current:
php-8.5.11-i686-1.txz
Updated package for Slackware x86_64 -current:
php-8.5.11-x86_64-1.txz
MD5 signatures:
+-------------+
Slackware 15.0 package:
040ca1fe7641bbb548d5a78bc3f37418 php82-8.2.34-i586-1_slack15.0.txz
Slackware x86_64 15.0 package:
162cff77023f5faf8e507eddef8e019f php82-8.2.34-x86_64-1_slack15.0.txz
Slackware -current package:
0ca1bcfb174bac3974a27b2cfeb7e6a4 n/php-8.5.11-i686-1.txz
Slackware x86_64 -current package:
cfe038905342d741c2d4ba06cc4cfc86 n/php-8.5.11-x86_64-1.txz
Installation instructions:
+------------------------+
Upgrade the package as root:
# upgradepkg php82-8.2.34-i586-1_slack15.0.txz
Then, restart Apache httpd:
# /etc/rc.d/rc.httpd stop
# /etc/rc.d/rc.httpd start
+-----+
Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com
+------------------------------------------------------------------------+
| To leave the slackware-security mailing list: |
+------------------------------------------------------------------------+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. |
+------------------------------------------------------------------------+
-----BEGIN PGP SIGNATURE-----
iHkEARECADkWIQTsVknaQB4iq/pnNu9qRGPAQBAiMwUCarWRFxsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMiwyLDIACgkQakRjwEAQIjMp8gCfazbQXY3bRg6gUHol7gXP
E8BDYH0AnRf1Su85wG/5QADUJSG/6kXuWjjR
=Z0Xt
-----END PGP SIGNATURE-----
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Mehrere Probleme in samba (Slackware) | 0 | 10 | 29-07-2026 |
| 2 | Mehrere Probleme in libarchive (Slackware) | 0 | 10 | 29-07-2026 |
| 3 | Mehrere Probleme in seamonkey (Slackware) | 0 | 10 | 29-07-2026 |
| 4 | Mehrere Probleme in Linux (Red Hat) | 0 | 10 | 11-08-2026 |
| 5 | Mehrere Probleme in Linux (Red Hat) | 0 | 10 | 11-08-2026 |
| 6 | Mehrere Probleme in zstd-jni (SUSE) | 0 | 30 | 24-09-2026 |
| 7 | Mehrere Probleme in nginx (SUSE) | 0 | 10 | 30-07-2026 |
| 8 | Mehrere Probleme in libssh (SUSE) | 0 | 10 | 30-07-2026 |
| 9 | Mehrere Probleme in libssh (SUSE) | 0 | 10 | 30-07-2026 |
| 10 | Mehrere Probleme in exiv2 (SUSE) | 0 | 30 | 24-09-2026 |