Critical SQL Injection and C Stack Exhaustion Vulnerabilities in PHP7 and PHP8

Critical SQL Injection and C Stack Exhaustion Vulnerabilities in PHP7 and PHP8

First seen 6 Aug 2026, 07:21 UTC Linuxsecurity 92% similarity 74.0

Article Content

Browse articles
ThreatCluster

Recent updates for openSUSE's PHP7 and PHP8 address critical vulnerabilities, including CVE-2026-17543, which allows SQL injection through improper escaping of backslashes in user parameters, and CVE-2026-7260, which can lead to C stack exhaustion due to circular symbolic links in phar archives. Both vulnerabilities were published on July 30, 2026, with a proof of concept for CVE-2026-17543 released on August 4, 2026. Affected systems include various versions of SUSE Linux Enterprise Server and High Performance Computing products. Administrators are urged to apply patches immediately to mitigate potential exploits. The vulnerabilities pose significant risks due to their critical nature and the ease of exploitation.

Key Points: • Critical vulnerabilities in PHP7 and PHP8 require immediate patching. • CVE-2026-17543 allows SQL injection due to improper escaping of user parameters. • CVE-2026-7260 can cause C stack exhaustion through circular symbolic links.

ThreatCluster AI How this analysis works

Timeline

2026-07-30
CVE-2026-17543 published
A vulnerability allowing SQL injection through improper escaping of backslashes in user parameters was disclosed.
Linuxsecurity
2026-07-30
CVE-2026-7260 published
A vulnerability leading to C stack exhaustion due to circular symbolic links in phar archives was disclosed.
Linuxsecurity
2026-08-04
First public PoC for CVE-2026-17543
A proof of concept for the SQL injection vulnerability was made public, increasing the risk of exploitation.
Linuxsecurity
2026-08-06
Patch released for PHP7 and PHP8
SUSE released critical updates for PHP7 and PHP8, urging users to apply patches to mitigate vulnerabilities.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story