Canonical Ubuntu Server 26.04 LTS (Resolute Raccoon) Update Version 8.5.4-0ubuntu1.3
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
USN-8743-1 addresses multiple PHP security issues, including SQL injection in the PostgreSQL extension, an out-of-bounds write in `bccomp()`, and denial of service in `phar` archive handling. Ubuntu 26.04 LTS is affected by the `bccomp()` issue. Reference IDs: CVE-2026-17543, CVE-2026-17544, CVE-2026-7260.
Update Details
Security
- PHP PostgreSQL extension incorrectly handled backslash escaping, enabling SQL injection attacks (CVE-2026-17543).
- PHP incorrectly handled certain inputs to
bccomp(), causing an out-of-bounds write that could lead to denial of service or arbitrary code execution; this affected Ubuntu 26.04 LTS (CVE-2026-17544). - PHP incorrectly handled circular symbolic links in
phararchives, allowing unbounded recursion and denial of service (CVE-2026-7260).
Hints
- A standard system update installs the fixes.
- For Ubuntu 26.04 LTS, update
libapache2-mod-php8.5,php8.5-cgi,php8.5-cli, andphp8.5-fpmto8.5.4-0ubuntu1.3.
Product Information
Vendor: Canonical
Product: Ubuntu Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: 26.04 LTS (Resolute Raccoon)
Version: 8.5.4-0ubuntu1.3
Vendor release date: Sep 10, 2026
Original release notes: View on vendor site
Published on updatealert.io: Sep 10, 2026
Description: Server operating system for Linux infrastructure and workloads.