{"id":"MGASA-2026-0458","summary":"Updated php package fixes security vulnerabilities","details":"FILTER_SANITIZE_ENCODED does not encode 0xFF\nIPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address\ncomparison\nVarious packet overreads in mysqlnd wire protocol\nTLS hostname verification falls back to CN after SAN mismatch\nHeap buffer overflow in php_openssl_matches_wildcard_name() on crafted\nserver certificate wildcard CN\nInteger overflow in phar_tar_number() allowing TAR archive entry\ninjection\nUnbounded recursion in server-side cleanup_xml_node()\nInteger overflow to buffer overflow in SOAP HTTP parsing)\nOut-of-bounds read in convert.* stream filters when line-break-chars\ncontains NUL\nross-origin credential leak in HTTP stream wrapper redirects\nOut-of-bounds read in the HTTP stream wrapper when following a redirect\nwith an empty Location header\n","modified":"2026-09-28T17:27:47.925856909Z","published":"2026-09-28T17:04:04Z","upstream":["CVE-2025-1218","CVE-2025-14181","CVE-2026-6103","CVE-2026-91765","CVE-2026-91766","CVE-2026-91767","CVE-2026-91768","CVE-2026-91769","CVE-2026-92842","CVE-2026-93682"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0458.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36367"},{"type":"WEB","url":"https://www.php.net/ChangeLog-8.php#8.2.34"}],"affected":[{"package":{"name":"php","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/php?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.2.34-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0458.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}