USN-8734-1: PHP vulnerabilities

Publication date

7 September 2026

Overview

PHP could be made to crash or expose sensitive information if it received specially crafted input.

Releases


Packages

  • php7.0 - HTML-embedded scripting language interpreter

Details

It was discovered that PHP incorrectly handled Apache map decoding in SOAP
servers with a typemap configured. A remote attacker could use this issue
to cause a NULL pointer dereference, resulting in a denial of service.
(CVE-2026-7262)

It was discovered that PHP incorrectly handled signed integer overflow in
the metaphone() function. An attacker could use this issue to cause an
out-of-bounds read, resulting in a denial of service. (CVE-2026-7568)

It was discovered that PHP incorrectly handled circular symbolic links in
phar archives. An attacker could use this issue to cause unbounded
recursion, resulting in a denial of service. (CVE-2026-7260)

It was discovered that PHP incorrectly escaped backslashes in the pgsql
extension when standard_conforming_strings is enabled. An attacker could
use this issue to...

It was discovered that PHP incorrectly handled Apache map decoding in SOAP
servers with a typemap configured. A remote attacker could use this issue
to cause a NULL pointer dereference, resulting in a denial of service.
(CVE-2026-7262)

It was discovered that PHP incorrectly handled signed integer overflow in
the metaphone() function. An attacker could use this issue to cause an
out-of-bounds read, resulting in a denial of service. (CVE-2026-7568)

It was discovered that PHP incorrectly handled circular symbolic links in
phar archives. An attacker could use this issue to cause unbounded
recursion, resulting in a denial of service. (CVE-2026-7260)

It was discovered that PHP incorrectly escaped backslashes in the pgsql
extension when standard_conforming_strings is enabled. An attacker could
use this issue to perform SQL injection via a backslash breakout.
(CVE-2026-17543)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
16.04 LTS xenial libapache2-mod-php7.0 –  7.0.33-0ubuntu0.16.04.16+esm20  
libphp7.0-embed –  7.0.33-0ubuntu0.16.04.16+esm20  
php7.0-cgi –  7.0.33-0ubuntu0.16.04.16+esm20  
php7.0-cli –  7.0.33-0ubuntu0.16.04.16+esm20  
php7.0-common –  7.0.33-0ubuntu0.16.04.16+esm20  
php7.0-fpm –  7.0.33-0ubuntu0.16.04.16+esm20  
php7.0-pgsql –  7.0.33-0ubuntu0.16.04.16+esm20  
php7.0-phpdbg –  7.0.33-0ubuntu0.16.04.16+esm20  
php7.0-soap –  7.0.33-0ubuntu0.16.04.16+esm20  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›