Home / mailingsPDF  

[slackware-security] php (SSA:2026-267-01)

Posted on 25 September 2026
Slackware Security

[slackware-security] php (SSA:2026-267-01)

New php packages are available for Slackware 15.0 and -current to
fix security issues.


Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
extra/php82/php82-8.2.34-i586-1_slack15.0.txz: Upgraded.
This update fixes security issues:
FPM: IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address
comparison.
OpenSSL: TLS hostname verification falls back to CN after SAN mismatch.
OpenSSL: Heap buffer overflow in php_openssl_matches_wildcard_name() on
crafted server certificate wildcard CN.
Phar: Integer overflow in phar_tar_number() allowing TAR archive entry
injection.
SOAP: Unbounded recursion in server-side cleanup_xml_node().
SOAP: Integer overflow to buffer overflow in SOAP HTTP parsing.
Standard: Out-of-bounds read in convert.* stream filters when
line-break-chars contains NUL.
Standard: Cross-origin credential leak in HTTP stream wrapper redirects.
Standard: Out-of-bounds read in the HTTP stream wrapper when following a
redirect with an empty Location header.
For more information, see:
https://www.php.net/ChangeLog-8.php#8.2.34
https://www.cve.org/CVERecord?id=CVE-2026-91768
https://www.cve.org/CVERecord?id=CVE-2025-1218
https://www.cve.org/CVERecord?id=CVE-2026-91769
https://www.cve.org/CVERecord?id=CVE-2026-91767
https://www.cve.org/CVERecord?id=CVE-2026-6103
https://www.cve.org/CVERecord?id=CVE-2026-91765
https://www.cve.org/CVERecord?id=CVE-2025-14181
https://www.cve.org/CVERecord?id=CVE-2026-92842
https://www.cve.org/CVERecord?id=CVE-2026-91766
https://www.cve.org/CVERecord?id=CVE-2026-93682
https://www.cve.org/CVERecord?id=CVE-2026-17545
(* Security fix *)
+--------------------------+


Where to find the new packages:
+-----------------------------+

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware-15.0/extra/php82/php82-8.2.34-i586-1_slack15.0.txz

Updated package for Slackware x86_64 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/extra/php82/php82-8.2.34-x86_64-1_slack15.0.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/php-8.5.11-i686-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/php-8.5.11-x86_64-1.txz


MD5 signatures:
+-------------+

Slackware 15.0 package:
040ca1fe7641bbb548d5a78bc3f37418 php82-8.2.34-i586-1_slack15.0.txz

Slackware x86_64 15.0 package:
162cff77023f5faf8e507eddef8e019f php82-8.2.34-x86_64-1_slack15.0.txz

Slackware -current package:
0ca1bcfb174bac3974a27b2cfeb7e6a4 n/php-8.5.11-i686-1.txz

Slackware x86_64 -current package:
cfe038905342d741c2d4ba06cc4cfc86 n/php-8.5.11-x86_64-1.txz


Installation instructions:
+------------------------+

Upgrade the package as root:
# upgradepkg php82-8.2.34-i586-1_slack15.0.txz

Then, restart Apache httpd:
# /etc/rc.d/rc.httpd stop
# /etc/rc.d/rc.httpd start


+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

 

TOP