Back Linuxsecurity Important Security Update on PHP Denial of Service for Ubuntu 16.04 LTS
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
PHP could be made to crash or expose sensitive information if it received specially crafted input. Software Description: - php7.0: HTML-embedded scripting language interpreter Details: It was discovered that PHP incorrectly handled Apache map decoding in SOAP servers with a typemap configured. A remote attacker could use this issue to cause a NULL pointer dereference, resulting in a denial of service. (CVE-2026-7262) It was discovered that PHP incorrectly handled signed integer overflow in the metaphone() function. An attacker could use this issue to cause an out-of-bounds read, resulting in a denial of service. (CVE-2026-7568) It was discovered that PHP incorrectly handled circular symbolic links in phar archives. An attacker could use this issue to cause unbounded recursion, resulting in a denial of service. (CVE-2026-7260) It was discovered that PHP incorrectly escaped backslashes in the pgsql extension when standard_conforming_strings is enabled. An attacker could use thi... Read the Full Advisory
PHP could be made to crash or expose sensitive information if it received
specially crafted input.
Software Description:
- php7.0: HTML-embedded scripting language interpreter
It was discovered that PHP incorrectly handled Apache map decoding in SOAP
servers with a typemap configured. A remote attacker could use this issue
to cause a NULL pointer dereference, resulting in a denial of service.
It was discovered that PHP incorrectly handled signed integer overflow in
the metaphone() function. An attacker could use this issue to cause an
out-of-bounds read, resulting in a denial of service. (CVE-2026-7568)
It was discovered that PHP incorrectly handled circular symbolic links in
phar archives. An attacker could use this issue to cause unbounded
recursion, resulting in a denial of service. (CVE-2026-7260)
It was discovered that PHP incorrectly escaped backslashes in the pgsql
extension when standard_conforming_strings is enabled. An attacker could
The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libapache2-mod-php7.0 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro libphp7.0-embed 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-cgi 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-cli 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-common 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-fpm 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-pgsql 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-phpdbg 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro php7.0-soap 7.0.33-0ubuntu0.16.04.16+esm20 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
CVE-2026-17543, CVE-2026-7260, CVE-2026-7262, CVE-2026-7568
Ubuntu Security Notice USN-8734-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
