ELA-1806-1 php7.3 security update

multiple vulnerabilities

2026-08-12
Packagephp7.3
Version7.3.31-1~deb10u14 (buster)
Related CVEs CVE-2026-7260 CVE-2026-17543


CVE-2026-7260

Symbolic links in phar archives are followed without any depth limit or cycle detection. A crafted tar-based phar archive containing circular symbolic links could therefore cause unbounded recursion, exhausting the C stack and crashing the PHP process, resulting in denial of service.

CVE-2026-17543

Improper escaping of backslashes in user-provided parameters allow for trivial SQL injection via E'…' backslash breakout in the psql extension.

In addition, this update fixes the following issues which, while not directly affecting normal Buster environments, might affect custom builds.

CVE-2026-9672

Processing of malicious GIF files may lead to crash or arbitrary code execution. The package build uses the system libgd so is not directly affected. A separate libgd2 ELA is available for the system library.

CVE-2026-14355

Usage of AES-WRAP-PAD may result in denial of service via memory corruption. Normal Buster environments are not affected because AES key-wrap-with-padding operation is not usable with Buster’s OpenSSL 1.1.1 build.



For Debian 10 buster, these problems have been fixed in version 7.3.31-1~deb10u14.

We recommend that you upgrade your php7.3 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.