Security News

Cybersecurity news aggregator

🐧
HIGH Updates Debian Security

DSA-6406-1 php8.4 - security update

This Debian Security Advisory (DSA-6406-1) addresses multiple security vulnerabilities (CVE-2026-7260, CVE-2026-17543, CVE-2026-17544) in PHP 8.4 that could lead to denial of service, SQL injection, information disclosure, or arbitrary code execution. For the Debian stable distribution (trixie), these issues are fixed in php8.4 version 8.4.24-1~deb13u1, to which users should upgrade immediately.
Read Full Article →

[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6406-1] php8.4 security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6406-1] php8.4 security update From: Salvatore Bonaccorso <carnil@debian.org> Date: Fri, 31 Jul 2026 21:17:27 +0000 Message-id: <[🔎] E1wpubf-00000000fSC-0qzG@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6406-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 31, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php8.4 CVE ID : CVE-2026-7260 CVE-2026-17543 CVE-2026-17544 Debian Bug : 1143153 Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in denial of service, SQL injection, information disclosure or the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in version 8.4.24-1~deb13u1. We recommend that you upgrade your php8.4 packages. For the detailed security status of php8.4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php8.4 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmptEKJfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0RvDA/9Gtz07hRBlRpeU/rM10m9kbCV+WxL9BfeuQIBg7qfQKlQdXAzLHfxVCCQ 4vm9d7MMqA8CM5R6W+BwTsBilUeBVhcRAAyO+V8LN96IYtvX4r6eUldhKmARuL4a G8qx5GIgYVAhr3FLCdXK6v/aPvu8ohnWNdmEbTDnsYJ2LDDRAbepuScQPVgdFgsA pjyP77sQex4E9/VjDKS3/lPag1TmhI9mrQDUgKiQtW47cmhidBJ6hrjuQjUYvYaA gn9O9odcftKE6jYF8wGIQ+ADFgiAXUjuFBSombFX1+er/YUDs0wxn0FF1v8/qaZX KQdyjLBc86TeZhAVIoZURqB1K0Wm2p2jrAJwTFuX0aKmPGXx8KQh1zE+3o2L6ls6 wqfN6J8HRf/bS9AC/EK0kV4UevjGUqM4u13e9xOKHS6uxbcKTTi7D1DizU85lG9Z PZfG9cYfmH5XyxKAlobvcQFxumjP1WABJZsRLRwHg0kH7DgpJMAhbfpkt1f0h/mr RSZjPQWvCeCnuJY+AON8VQJd/tBAwsE9L9qVQu4beBlfOjTylWkDw7NeDenrHBhv difduiFYjWl+fwlzcD5k9UlD/Y+pxYlw6oKnIiGv59ebyX8K+Zat7jiYOQP+f1Pn LSQXMBhyaehpe0aL/75VFpdTvjvdJKm3Cy7EA5UvhHC8lvPL9FU= =+Wlr -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Salvatore Bonaccorso (on-list) Salvatore Bonaccorso (off-list) Prev by Date: [SECURITY] [DSA 6405-1] linux security update Next by Date: [SECURITY] [DSA 6407-1] incus security update Previous by thread: [SECURITY] [DSA 6405-1] linux security update Next by thread: [SECURITY] [DSA 6407-1] incus security update Index(es): Date Thread

Share this article