Linuxsecurity
Critical SQL Injection and C Stack Exhaustion Vulnerabilities in openSUSE PHP
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Recent updates for openSUSE PHP versions 7 and 8 have revealed critical vulnerabilities, including SQL injection and C stack exhaustion issues. Specifically, CVE-2026-17543 allows for SQL injection through improper escaping of user-provided parameters in `ext-pgsql`, while CVE-2026-7260 can lead to unbounded recursion and C stack exhaustion due to circular symbolic links in phar archives. These vulnerabilities affect multiple SUSE Linux Enterprise Server versions and require immediate patching. The vulnerabilities were disclosed on July 30, 2026, with the first public proof of concept for CVE-2026-17543 released on August 4, 2026. Administrators are urged to apply patches using SUSE's recommended methods. The updates are critical as they could allow attackers to exploit systems, leading to potential data breaches and service disruptions.
Key Points: • Critical vulnerabilities in openSUSE PHP 7 and 8 require immediate attention. • CVE-2026-17543 allows SQL injection via `ext-pgsql`, while CVE-2026-7260 causes C stack exhaustion. • Patches are available, and administrators must apply them to mitigate risks.