-------------------------------------------------------------------------
Debian LTS Advisory DLA-4733-1                [email protected]
https://www.debian.org/lts/security/                       Guilhem Moulin
August 11, 2026                               https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : php7.4
Version        : 7.4.33-1+deb11u12
CVE ID         : CVE-2026-7260 CVE-2026-17543
Debian Bug     : 1143153

Security issues were found in PHP, a widely-used open source general
purpose scripting language, which could result in denial of service or
SQL injection.

CVE-2026-7260

    Symbolic links in phar archives are followed without any depth limit
    or cycle detection.  A crafted tar-based phar archive containing
    circular symbolic links could therefore cause unbounded recursion,
    exhausting the C stack and crashing the PHP process.

CVE-2026-17543

    Improper escaping of backslashes in attacker-provided parameters
    allow for trivial SQL injection via E'…' backslash breakout.

For Debian 11 bullseye, these problems have been fixed in version
7.4.33-1+deb11u12.

We recommend that you upgrade your php7.4 packages.

For the detailed security status of php7.4 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/php7.4

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: PGP signature

Reply via email to