Linuxsecurity Moderate Stack Overflow Vulnerability in php7 Affects SUSE and openSUSE
Article Content
- •CVE-2026-7260 is a moderate stack overflow vulnerability in php7.
- •Affected systems include SUSE Linux Enterprise and openSUSE distributions.
- •Patches were released on September 11, 2026, following the CVE publication on July 30, 2026.
A moderate stack overflow vulnerability, identified as CVE-2026-7260, has been reported in php7, specifically affecting systems with circular symlinks in phar files. This vulnerability allows for potential exploitation, impacting SUSE Linux Enterprise Server and openSUSE users. The vulnerability has a CVSS score of 4.0, indicating a moderate severity level. Users are advised to apply patches immediately to mitigate risks. The vulnerability was published on July 30, 2026, and has been addressed in updates released on September 11, 2026. Additional changes in the patch allow for the removal of apache2-mod_php7 even if the module is not enabled. Administrators are encouraged to follow SUSE's recommended installation methods for applying the updates. The updates are available for various SUSE products including SAP Applications and High Performance Computing versions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-7260 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical PHP Vulnerabilities in Oracle Linux Advisory ELSA-2026-62334 and ELSA-2026-61903 Oracle has issued important bug fix advisories for PHP vulnerabilities affecting Oracle Linux 8 and 9. The vulnerabilities include CVE-2026-17543, a SQL injection flaw, and CVE-2026-7260, which can cause crashes via recursive symlinks. These vulnerabilities impact PHP versions 7.4 and 8.2, respectively, and could…
Multiple PHP Vulnerabilities Lead to Denial of Service Risks Recent vulnerabilities in PHP could allow remote attackers to cause denial of service on affected systems. Specifically, issues were identified in PHP 7.0, including improper handling of Apache map decoding (CVE-2026-7262), signed integer overflow in the metaphone() function (CVE-2026-7568), and circular symbolic…