Skip to content
Important Security Update on PHP Denial of Service for Ubuntu 16.04 LTS

Important Security Update on PHP Denial of Service for Ubuntu 16.04 LTS

Linuxsecurity LinuxSecurity Advisories September 8, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

PHP could be made to crash or expose sensitive information if it received specially crafted input. Software Description: - php7.0: HTML-embedded scripting language interpreter Details: It was discovered that PHP incorrectly handled Apache map decoding in SOAP servers with a typemap configured. A remote attacker could use this issue to cause a NULL pointer dereference, resulting in a denial of service. (CVE-2026-7262) It was discovered that PHP incorrectly handled signed integer overflow in the metaphone() function. An attacker could use this issue to cause an out-of-bounds read, resulting in a denial of service. (CVE-2026-7568) It was discovered that PHP incorrectly handled circular symbolic links in phar archives. An attacker could use this issue to cause unbounded recursion, resulting in a denial of service. (CVE-2026-7260) It was discovered that PHP incorrectly escaped backslashes in the pgsql extension when standard_conforming_strings is enabled. An attacker could use thi... Read the Full Advisory

PHP could be made to crash or expose sensitive information if it received

specially crafted input.

Software Description:

- php7.0: HTML-embedded scripting language interpreter

It was discovered that PHP incorrectly handled Apache map decoding in SOAP

servers with a typemap configured. A remote attacker could use this issue

to cause a NULL pointer dereference, resulting in a denial of service.

It was discovered that PHP incorrectly handled signed integer overflow in

the metaphone() function. An attacker could use this issue to cause an

out-of-bounds read, resulting in a denial of service. (CVE-2026-7568)

It was discovered that PHP incorrectly handled circular symbolic links in

phar archives. An attacker could use this issue to cause unbounded

recursion, resulting in a denial of service. (CVE-2026-7260)

It was discovered that PHP incorrectly escaped backslashes in the pgsql

extension when standard_conforming_strings is enabled. An attacker could

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libapache2-mod-php7.0 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro libphp7.0-embed 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-cgi 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-cli 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-common 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-fpm 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-pgsql 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-phpdbg 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-soap 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

CVE-2026-17543, CVE-2026-7260, CVE-2026-7262, CVE-2026-7568

Ubuntu Security Notice USN-8734-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases