Skip to content

Commit 2cd1675

Browse files
committed
Merge branch 'PHP-8.3' into PHP-8.4
* PHP-8.3: ext/soap: make GHSA-cj93-vc83-wgqv test lean and reliable Add NEWS entries ext/standard: Fix 1-char relative Location redirects after GH-23467 [http] Fix out-of-bounds read on empty Location header Fix GHSA-ch8v-r6jh-4vvr: encode 0xFF in FILTER_SANITIZE_ENCODED Fix GHSA-9f67-6fw4-hpfp Fix GHSA-j3wh-g957-2m85: phar tar entry injection Fix GHSA-cj93-vc83-wgqv Fix GHSA-rgrp-mwpx-f6rm: unbounded recursion in ext/soap XML parsing and decoding Fix GHSA-fpwc-w8rq-cr92: strip credentials from user headers on cross-origin redirects Fix GHSA-r6x9-5r99-36j7: Various packet overreads in mysqlnd wireprotocol Fix GHSA-xr7j-rvgx-xq5p: OOB read in php_openssl_matches_wildcard_name() Fix GHSA-vvx9-73fr-5jjx: do not fall back to CN if the cert has a service ID Fix GHSA-62xp-839h-2637: FastCGI allowed_clients compared only 96 bits of IPv6 addresses Fix heap-buffer-overflow in convert stream filters with NUL in line-break-chars # Conflicts: # ext/openssl/xp_ssl.c
2 parents a1a7bd4 + f9e0418 commit 2cd1675

77 files changed

Lines changed: 4235 additions & 234 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎NEWS‎

Lines changed: 30 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -126,6 +126,8 @@ PHP NEWS
126126

127127
- FPM:
128128
. Fixed bug GH-19320 (FPM UID and GID overflow). (Pratik Bhujel)
129+
. Fixed GHSA-62xp-839h-2637 (IPv6 ACL bypass in FastCGI listen.allowed_clients
130+
due to partial address comparison). (CVE-2026-91768) (Alexandre Daubois)
129131

130132
- Hash:
131133
. Fixed a buffer overflow in hash_pbkdf2() with a large output length.
@@ -154,6 +156,10 @@ PHP NEWS
154156
replacement when a \k<name> backref has no closing delimiter.
155157
(Ilia Alshanetsky)
156158

159+
- MySQLnd:
160+
. Fixed GHSA-r6x9-5r99-36j7 (Various packet overreads in mysqlnd wire
161+
protocol). (CVE-2025-1218) (Jakub Zelenka, Nora Dossche)
162+
157163
- ODBC:
158164
. Fixed odbc_field_len(), odbc_field_scale() and odbc_field_type()
159165
returning uninitialized memory when SQLColAttribute fails.
@@ -169,6 +175,13 @@ PHP NEWS
169175
class that could not be stored in the inheritance cache. (GH-21710)
170176
(Arnaud, iliaal)
171177

178+
- OpenSSL:
179+
. Fixed GHSA-vvx9-73fr-5jjx (TLS hostname verification falls back to CN after
180+
SAN mismatch). (CVE-2026-91769) (Jakub Zelenka)
181+
. Fixed GHSA-xr7j-rvgx-xq5p (Heap buffer overflow in
182+
php_openssl_matches_wildcard_name() on crafted server certificate wildcard
183+
CN). (CVE-2026-91767) (Jakub Zelenka)
184+
172185
- PDO:
173186
. Fixed a leak when a persistent connection failed a liveness check
174187
with no other live PDO handle. (iliaal)
@@ -190,6 +203,8 @@ PHP NEWS
190203
(Weilin Du)
191204
. Fixed bug GH-23477 (Memory leak on duplicate native Phar manifest entries).
192205
(Weilin Du)
206+
. Fixed GHSA-j3wh-g957-2m85 (Integer overflow in phar_tar_number() allowing
207+
TAR archive entry injection). (CVE-2026-6103) (Jakub Zelenka)
193208

194209
- SNMP:
195210
. Fixed bug GH-23453 (SNMP::setSecurity() frees a non-malloced address with a
@@ -202,12 +217,17 @@ PHP NEWS
202217
(Ilia Alshanetsky)
203218
. Fixed stack overflow when parsing a WSDL with self-referential schema
204219
groups or attributeGroups. (Ilia Alshanetsky)
220+
. Fixed GHSA-rgrp-mwpx-f6rm (Unbounded recursion in server-side
221+
cleanup_xml_node()). (CVE-2026-91765) (Alexandre Daubois)
222+
. Fixed GHSA-cj93-vc83-wgqv (Integer overflow to buffer overflow in SOAP HTTP
223+
parsing). (CVE-2025-14181) (Nora Dossche, Jakub Zelenka)
205224

206225
- Standard:
207226
. Fixed a segfault when a stream filter callback unsets StreamBucket::$data
208227
before re-attaching the bucket. (iliaal)
209-
. Fixed an out-of-bounds read when following a redirect response with an
210-
empty Location header. (iliaal)
228+
. Fixed GHSA-7875-c8px-7q5f (Out-of-bounds read in the HTTP stream wrapper
229+
when following a redirect with an empty Location header). (CVE-2026-93682)
230+
(Ilia Alshanetsky, Jordi Kroon)
211231
. Fixed a memory leak in array_merge_recursive() when the recursive merge of
212232
an object converted to an array fails. (David Carlier)
213233
. Fixed read buffer compaction in php_stream_filter_flush(). (crystarm)
@@ -217,6 +237,10 @@ PHP NEWS
217237
argument number for $timeout). (lacatoire)
218238
. Fixed bug GH-23576 (Next index for array returned from array_keys() is
219239
wrong). (Lazizbek Ergashev)
240+
. Fixed GHSA-88hq-2827-7pg6 (Out-of-bounds read in convert.* stream filters
241+
when line-break-chars contains NUL). (CVE-2026-92842) (geeknik)
242+
. Fixed GHSA-fpwc-w8rq-cr92 (Cross-origin credential leak in HTTP stream
243+
wrapper redirects). (CVE-2026-91766) (Alexandre Daubois, Jakub Zelenka)
220244

221245
- SimpleXML:
222246
. Fixed writing to a dimension of the object returned by attributes() not
@@ -225,6 +249,10 @@ PHP NEWS
225249
SimpleXMLElement::addChild() not being accessible by property name when
226250
namespaces are involved. (Ilia Alshanetsky)
227251

252+
- Windows:
253+
. Fixed GHSA-9f67-6fw4-hpfp (Reserved device names are not rejected before
254+
file and stream I/O). (CVE-2026-17545) (Shivam Mathur, Jakub Zelenka)
255+
228256
- Zip:
229257
. Fixed bug GH-23276 (ZipArchive subclass storing its own stream cannot be
230258
garbage collected). (Weilin Du, ndossche)

‎Zend/zend_virtual_cwd.c‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1028,6 +1028,19 @@ CWD_API int virtual_file_ex(cwd_state *state, const char *path, verify_path_func
10281028
fprintf(stderr,"cwd = %s path = %s\n", state->cwd, path);
10291029
#endif
10301030

1031+
#ifdef ZEND_WIN32
1032+
switch (php_win32_ioutil_path_kind_a(path, path_length)) {
1033+
case PHP_WIN32_IOUTIL_PATH_RESERVED:
1034+
SET_ERRNO_FROM_WIN32_CODE(ERROR_INVALID_NAME);
1035+
return 1;
1036+
case PHP_WIN32_IOUTIL_PATH_DEVICE:
1037+
memcpy(resolved_path, path, path_length + 1);
1038+
goto verify;
1039+
default:
1040+
break;
1041+
}
1042+
#endif
1043+
10311044
/* cwd_length can be 0 when getcwd() fails.
10321045
* This can happen under solaris when a dir does not have read permissions
10331046
* but *does* have execute permissions */

0 commit comments

Comments
 (0)