Critical SQL Injection and C Stack Exhaustion Vulnerabilities in openSUSE PHP

Critical SQL Injection and C Stack Exhaustion Vulnerabilities in openSUSE PHP

First seen 6 Aug 2026, 07:21 UTC www.suse.comLinuxsecurity 72.9

Article Content

Browse articles
ThreatCluster

Recent updates for openSUSE PHP versions 7 and 8 have revealed critical vulnerabilities, including SQL injection and C stack exhaustion issues. Specifically, CVE-2026-17543 allows for SQL injection through improper escaping of user-provided parameters in `ext-pgsql`, while CVE-2026-7260 can lead to unbounded recursion and C stack exhaustion due to circular symbolic links in phar archives. These vulnerabilities affect multiple SUSE Linux Enterprise Server versions and require immediate patching. The vulnerabilities were disclosed on July 30, 2026, with the first public proof of concept for CVE-2026-17543 released on August 4, 2026. Administrators are urged to apply patches using SUSE's recommended methods. The updates are critical as they could allow attackers to exploit systems, leading to potential data breaches and service disruptions.

Key Points: • Critical vulnerabilities in openSUSE PHP 7 and 8 require immediate attention. • CVE-2026-17543 allows SQL injection via `ext-pgsql`, while CVE-2026-7260 causes C stack exhaustion. • Patches are available, and administrators must apply them to mitigate risks.

Timeline

2026-07-03
CVE-2026-14355 published
Buffer allocation flaw in AES-WRAP-PAD algorithm leads to heap metadata corruption.
Linuxsecurity
2026-07-30
CVE-2026-7260 published
Circular symbolic links in phar archives can cause unbounded recursion and C stack exhaustion.
Linuxsecurity
2026-07-30
CVE-2026-17543 published
Improper escaping of backslashes allows trivial SQL injection in `ext-pgsql`.
Linuxsecurity
2026-08-04
First public PoC for CVE-2026-17543 released
Proof of concept for SQL injection vulnerability in `ext-pgsql` made public, increasing urgency.
Linuxsecurity
2026-08-06
Critical updates released for PHP vulnerabilities
SUSE advises immediate patching for PHP 7 and 8 to mitigate SQL injection and C stack exhaustion risks.
Linuxsecurity