[SECURITY] [DLA 4669-1] php8.2 security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -----------------------------------------------------------------------
Debian LTS Advisory DLA-4669-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Utkarsh Gupta
July 04, 2026 https://wiki.debian.org/LTS
- -----------------------------------------------------------------------
Package : php8.2
Version : 8.2.32-1~deb12u1
CVE ID : CVE-2026-14355
It was discovered that a buffer overflow in the implementation of AES
Key Wrap with Padding in the openssl extension of PHP, a widely-used
open source general purpose scripting language, could result in memory
corruption.
For Debian 12 bookworm, this problem has been fixed in version
8.2.32-1~deb12u1.
We recommend that you upgrade your php8.2 packages.
For the detailed security status of php8.2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/php8.2
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmpJFz0ACgkQgj6WdgbD
S5b+9g//be7kpFrXvtKyhnZQCiuPnQYaQYPqqu4I8xyOUgSPyxG3JCU6WOtQ+dWD
pYch/b01qX5Z4U32j7TRJY+4FQIs3K2Hg/D24hwuQi0q9JP0Ngb01g1m8bv7zZKO
KZ1s0xhzNLpwZvqDZ/+WccbDiblD+CUM6oVQQLbRUjviTWKGiCLfJXa8iTijx1sr
OPPSG0dUzCJo8a7VQRyLR7zVUEVp0sBT0JCI/up73GAytX+LG6fukxP7xpvWJquQ
4Ek7dO9tM56VyhK5rSjdatSzvunaqy/T1XArYi3WVsOA8ToNpLH+eba7N76nk6Oy
t1P2buszi7ZeqsOaSAzrdP7R2IXpQk48q/5nZcUNRZPeWYF73j1UebOYPeLhMiVe
JkkWx4irhRoIG2WHDGAd7glzpF5KG81t867cmEWoyRVVVZsFQUsY5eGfIoljD3PX
DM4X9ZJRSpFWzW4dw3XH2xWivcqt4vcDpD4RlgE17rGq+QJMoriamNC8G8kTd7Jq
PL5ou3e8ddFigivQvY4LQ8NVKuFUnOsVWhdbjTM7HQZnPPlS+GSB4RLKD8VFXUdZ
zP6N5oY3OsbIjxhdEQyZYp5C1UJfAUIU+P9VL5jyDY3EQ6kl17qE477+U8AItyxO
O79mYeTVU7/uGAF0eRzD3htAytfPRS1Na1m5ssLrmI5GO2PTfiM=
=tAZy
-----END PGP SIGNATURE-----
Reply to: