--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-26cddfc9b8
2026-02-20 01:16:08.171168+00:00
--------------------------------------------------------------------------------

Name        : php
Product     : Fedora 42
Version     : 8.4.18
Release     : 1.fc42
URL         : http://www.php.net/
Summary     : PHP scripting language for creating dynamic web sites
Description :
PHP is an HTML-embedded scripting language. PHP attempts to make it
easy for developers to write dynamically generated web pages. PHP also
offers built-in database integration for several commercial and
non-commercial database management systems, so writing a
database-enabled webpage with PHP is fairly simple. The most common
use of PHP coding is probably as a replacement for CGI scripts.

--------------------------------------------------------------------------------
Update Information:

PHP version 8.4.18 (12 Feb 2026)
Core:
Fixed bug GH-20837 (NULL dereference when calling ob_start() in shutdown
function triggered by bailout in php_output_lock_error()). (timwolla)
Fix OSS-Fuzz #471533782 (Infinite loop in GC destructor fiber). (ilutov)
Fix OSS-Fuzz #472563272 (Borked block_pass JMP[N]Z optimization). (ilutov)
Fixed bug GH-GH-20914 (Internal enums can be cloned and compared). (Arnaud)
Fix OSS-Fuzz #474613951 (Leaked parent property default value). (ilutov)
Fixed bug GH-20766 (Use-after-free in FE_FREE with GC interaction). (Bob)
Fix OSS-Fuzz #471486164 (Broken by-ref assignment to uninitialized hooked
backing value). (ilutov)
Fix OSS-Fuzz #438780145 (Nested finally with repeated return type check may
uaf). (ilutov)
Fixed bug GH-20905 (Lazy proxy bailing __clone assertion). (ilutov)
Fixed bug GH-20479 (Hooked object properties overflow). (ndossche)
DOM:
Fixed GH-21041 (Dom\HTMLDocument corrupts closing tags within scripts).
(lexborisov)
MbString:
Fixed bug GH-20833 (mb_str_pad() divide by zero if padding string is invalid in
the encoding). (ndossche)
Fixed bug GH-20836 (Stack overflow in mb_convert_variables with recursive array
references). (alexandre-daubois)
Opcache:
Fixed bug GH-20818 (Segfault in Tracing JIT with object reference). (khasinski)
OpenSSL:
Fix memory leaks when sk_X509_new_null() fails. (ndossche)
Fix crash when in openssl_x509_parse() when i2s_ASN1_INTEGER() fails. (ndossche)
Fix crash in openssl_x509_parse() when X509_NAME_oneline() fails. (ndossche)
Phar:
Fixed bug GH-20882 (buildFromIterator breaks with missing base directory).
(ndossche)
PGSQL:
Fixed INSERT/UPDATE queries building with PQescapeIdentifier() and possible UB.
(David Carlier)
Readline:
Fixed bug GH-18139 (Memory leak when overriding some settings via
readline_info()). (ndossche)
SPL:
Fixed bug GH-20856 (heap-use-after-free in SplDoublyLinkedList iterator when
modifying during iteration). (ndossche)
Standard:
Fixed bug php#74357 (lchown fails to change ownership of symlink with ZTS)
(Jakub Zelenka)
Fixed bug GH-20843 (var_dump() crash with nested objects) (David Carlier)
--------------------------------------------------------------------------------
ChangeLog:

* Wed Feb 11 2026 Remi Collet <[email protected]> - 8.4.18-1
- Update to 8.4.18 - http://www.php.net/releases/8_4_18.php
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-26cddfc9b8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to