Linuxsecurity Critical SQL Injection and C Stack Exhaustion Vulnerabilities in openSUSE PHP
Article Content
- •Critical vulnerabilities in openSUSE PHP 7 and 8 require immediate attention.
- •CVE-2026-17543 allows SQL injection via `ext-pgsql`, while CVE-2026-7260 causes C stack exhaustion.
- •Patches are available, and administrators must apply them to mitigate risks.
Recent updates for openSUSE PHP versions 7 and 8 have revealed critical vulnerabilities, including SQL injection and C stack exhaustion issues. Specifically, CVE-2026-17543 allows for SQL injection through improper escaping of user-provided parameters in `ext-pgsql`, while CVE-2026-7260 can lead to unbounded recursion and C stack exhaustion due to circular symbolic links in phar archives. These vulnerabilities affect multiple SUSE Linux Enterprise Server versions and require immediate patching. The vulnerabilities were disclosed on July 30, 2026, with the first public proof of concept for CVE-2026-17543 released on August 4, 2026. Administrators are urged to apply patches using SUSE's recommended methods. The updates are critical as they could allow attackers to exploit systems, leading to potential data breaches and service disruptions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track OpenSUSE and CVE-2026-14355 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…