Multiple PHP Vulnerabilities Lead to Denial of Service Risks

Multiple PHP Vulnerabilities Lead to Denial of Service Risks

First seen 8 Sep 2026, 12:03 UTC UbuntuLinuxsecurity 65.2

Article Content

Browse articles
ThreatCluster

Recent vulnerabilities in PHP could allow remote attackers to cause denial of service on affected systems. Specifically, issues were identified in PHP 7.0, including improper handling of Apache map decoding (CVE-2026-7262), signed integer overflow in the metaphone() function (CVE-2026-7568), and circular symbolic links in phar archives (CVE-2026-7260). Additionally, a flaw in the pgsql extension could lead to SQL injection (CVE-2026-17543). These vulnerabilities affect Ubuntu 16.04 LTS and can be exploited through specially crafted input. Patches are available, and users are urged to update their systems promptly. The vulnerabilities were disclosed in May and July 2026, with some having proof-of-concept code available.

Key Points: • PHP vulnerabilities could lead to denial of service and SQL injection. • Affected systems include PHP 7.0 on Ubuntu 16.04 LTS. • Patches are available, and users should update immediately.

Ask AI about this cluster

Timeline

2026-05-10
CVE-2026-7262 and CVE-2026-7568 published
Two significant vulnerabilities in PHP were disclosed, affecting denial of service capabilities.
Ubuntu
2026-07-30
CVE-2026-17543 and CVE-2026-7260 published
Additional vulnerabilities were disclosed, further increasing the risk of denial of service and SQL injection.
Linuxsecurity
2026-09-07
Security notice USN-8734-1 released
Ubuntu issued a security notice detailing multiple PHP vulnerabilities and available patches.
Ubuntu
2026-09-08
Linuxsecurity advisory published
Linuxsecurity provided guidance on patching and securing systems against the PHP vulnerabilities.
Linuxsecurity