| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: php-fpm | Distribution: Unknown |
| Version: 8.0.30 | Vendor: Remi's RPM repository <https://rpms.remirepo.net/> #StandWithUkraine #NoAI |
| Release: 19.module_php.8.0.el10.remi | Build date: Fri Oct 2 10:57:51 2026 |
| Group: Unspecified | Build host: builder2.remirepo.net |
| Size: 4340873 | Source RPM: php-8.0.30-19.module_php.8.0.el10.remi.src.rpm |
| Packager: Remi Collet | |
| Url: http://www.php.net/ | |
| Summary: PHP FastCGI Process Manager | |
PHP-FPM (FastCGI Process Manager) is an alternative PHP FastCGI implementation with some additional features useful for sites of any size, especially busier sites.
PHP and Zend and BSD and MIT and ASL 1.0 and NCSA
* Thu Oct 01 2026 Remi Collet <remi@remirepo.net> - 8.0.30-19
- Fix FILTER_SANITIZE_ENCODED does not encode 0xFF
- Fix IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison
CVE-2026-91768
- Partially Fixed Various packet overreads in mysqlnd wire protocol
CVE-2025-1218
- Fix TLS hostname verification falls back to CN after SAN mismatch
CVE-2026-91769
- Fix Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN
CVE-2026-91767
- Fix Integer overflow in phar_tar_number() allowing TAR archive entry injection
CVE-2026-6103
- Fix Unbounded recursion in server-side cleanup_xml_node()
CVE-2026-91765
- Fix Integer overflow to buffer overflow in SOAP HTTP parsing
CVE-2025-14181
- Fix Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL
CVE-2026-92842
- Fix Cross-origin credential leak in HTTP stream wrapper redirects
CVE-2026-91766
- Fix Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header
CVE-2026-93682
* Thu Jul 30 2026 Remi Collet <remi@remirepo.net> - 8.0.30-18
- Fix leak on double DatePeriod::__construct() call
- Fixed SQL injection via E'...' backslash breakout
CVE-2026-17543
- Fixed GHSA-vc5h-9ppw-p5f3 Crash via recursive symlinks
CVE-2026-7260
* Wed Jul 01 2026 Remi Collet <remi@remirepo.net> - 8.0.30-17
- Fix Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD
CVE-2026-14355
* Mon May 11 2026 Remi Collet <remi@remirepo.net> - 8.0.30-16
- Fix XSS within status endpoint
CVE-2026-6735
- Fix Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()
CVE-2026-7259
- Fix SQL injection via NUL bytes in quoted strings
CVE-2025-14179
- Fix Stale SOAP_GLOBAL(ref_map) pointer with Apache Map
CVE-2026-6722
- Fix Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION
CVE-2026-7261
- Fix Broken Apache map value NULL check
CVE-2026-7262
- Fix Signed integer overflow of char array offset
CVE-2026-7568
- Fix Consistently pass unsigned char to ctype.h functions
CVE-2026-7258
* Thu Dec 18 2025 Remi Collet <remi@remirepo.net> - 8.0.30-15
- Fix Null byte termination in dns_get_record()
GHSA-www2-q4fc-65wf
- Fix Heap buffer overflow in array_merge()
CVE-2025-14178
- Fix Information Leak of Memory in getimagesize
CVE-2025-14177
* Thu Jul 03 2025 Remi Collet <remi@remirepo.net> - 8.0.30-14
- Fix pgsql extension does not check for errors during escaping
CVE-2025-1735
- Fix NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix
CVE-2025-6491
- Fix Null byte termination in hostnames
CVE-2025-1220
* Thu Mar 13 2025 Remi Collet <remi@remirepo.net> - 8.0.30-13
- Fix libxml streams use wrong `content-type` header when requesting a redirected resource
CVE-2025-1219
- Fix Stream HTTP wrapper header check might omit basic auth header
CVE-2025-1736
- Fix Stream HTTP wrapper truncate redirect location to 1024 bytes
CVE-2025-1861
- Fix Streams HTTP wrapper does not fail for headers without colon
CVE-2025-1734
- Fix Header parser of `http` stream wrapper does not handle folded headers
CVE-2025-1217
- use oracle client library version 23.7 on x86_64 and aarch64
* Thu Feb 13 2025 Remi Collet <remi@remirepo.net> - 8.0.30-12
- backport fix for ICU 74+
- backport fix strict prototypes
* Wed Nov 27 2024 Remi Collet <remi@remirepo.net> - 8.0.30-11
- Fix Leak partial content of the heap through heap buffer over-read
CVE-2024-8929
* Fri Nov 22 2024 Remi Collet <remi@remirepo.net> - 8.0.30-10
- Fix Heap-Use-After-Free in sapi_read_post_data Processing in CLI SAPI Interface
GHSA-4w77-75f9-2c8w
- Fix OOB access in ldap_escape
CVE-2024-8932
- Fix Integer overflow in the dblib/firebird quoter causing OOB writes
CVE-2024-11236
- Fix Configuring a proxy in a stream context might allow for CRLF injection in URIs
CVE-2024-11234
- Fix Single byte overread with convert.quoted-printable-decode filter
CVE-2024-11233
/etc/httpd/conf.d/php.conf /etc/logrotate.d/php-fpm /etc/nginx/conf.d/php-fpm.conf /etc/nginx/default.d/php.conf /etc/php-fpm.conf /etc/php-fpm.d /etc/php-fpm.d/www.conf /etc/systemd/system/httpd.service.d/php-fpm.conf /etc/systemd/system/nginx.service.d/php-fpm.conf /etc/systemd/system/php-fpm.service.d /run/php-fpm /usr/lib/.build-id /usr/lib/.build-id/b7 /usr/lib/.build-id/b7/a40789b875d0fb4573093debd2f1c71cda54b6 /usr/lib/systemd/system/php-fpm.service /usr/sbin/php-fpm /usr/share/doc/php-fpm /usr/share/doc/php-fpm/php-fpm.conf.default /usr/share/doc/php-fpm/www.conf.default /usr/share/fpm /usr/share/fpm/status.html /usr/share/licenses/php-fpm /usr/share/licenses/php-fpm/fpm_LICENSE /usr/share/man/man8/php-fpm.8.gz /var/lib/php/opcache /var/lib/php/session /var/lib/php/wsdlcache /var/log/php-fpm
Generated by rpm2html 1.8.1
Fabrice Bellet, Fri Oct 2 14:47:48 2026