Views
10

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

USN-8743-1 addresses multiple PHP security issues, including SQL injection in the PostgreSQL extension, an out-of-bounds write in `bccomp()`, and denial of service in `phar` archive handling. Ubuntu 26.04 LTS is affected by the `bccomp()` issue. Reference IDs: CVE-2026-17543, CVE-2026-17544, CVE-2026-7260.

Update Details

Security

  • PHP PostgreSQL extension incorrectly handled backslash escaping, enabling SQL injection attacks (CVE-2026-17543).
  • PHP incorrectly handled certain inputs to bccomp(), causing an out-of-bounds write that could lead to denial of service or arbitrary code execution; this affected Ubuntu 26.04 LTS (CVE-2026-17544).
  • PHP incorrectly handled circular symbolic links in phar archives, allowing unbounded recursion and denial of service (CVE-2026-7260).

Hints

  • A standard system update installs the fixes.
  • For Ubuntu 26.04 LTS, update libapache2-mod-php8.5, php8.5-cgi, php8.5-cli, and php8.5-fpm to 8.5.4-0ubuntu1.3.

Product Information

Vendor: Canonical

Product: Ubuntu Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 26.04 LTS (Resolute Raccoon)

Version: 8.5.4-0ubuntu1.3

Vendor release date: Sep 10, 2026

Original release notes: View on vendor site

Published on updatealert.io: Sep 10, 2026

Description: Server operating system for Linux infrastructure and workloads.