Mageia 2024-0132: php Security Advisory Updates
Summary
Core: - Corrupted memory in destructor with weak references - GC does not scale well with a lot of objects created in destructor DOM: - Add some missing ZPP checks. - Fix potential memory leak in XPath evaluation results. FPM: - Fix incorrect check in fpm_shm_free(). Gettext: - Fixed sigabrt raised with dcgettext/dcngettext calls with gettext 0.22.5 with category set to LC_ALL. MySQLnd: - Fixed handshake response [mysqlnd] - Fix incorrect charset length in check_mb_eucjpms(). Opcache: - JITed QM_ASSIGN may be optimized out when op1 is null - Segmentation fault for enabled observers when calling trait method of internal trait when opcache is loaded PDO: - Fix various PDORow bugs. Random: - Pre-PHP 8.2 compatibility for mt_srand with unknown modes - Global Mt19937 is not properly reset in-between requests when MT_RAND_PHP is used Session: - Segfault with session_decode and compilation error Sockets: - socket_getsockname returns random characters in the end of the socket name SPL: - Un...
References
- https://bugs.mageia.org/show_bug.cgi?id=33093
- https://www.php.net/ChangeLog-8.php#8.2.18
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1874
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3096
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2756
Resolution
MGASA-2024-0132 - Updated php packages fix security vulnerabilities
SRPMS
- 9/core/php-8.2.18-1.mga9