PHP 8.4.24 and 8.5.9 Patch Critical CVEs in DEB.SURY.ORG Security Update

Published by

Debian and Ubuntu users accessing DEB.SURY.ORG have received important security updates for PHP, including versions 8.4.24 and 8.5.9, which address critical vulnerabilities such as a BCMath out-of-bounds write and PostgreSQL SQL injection issues. The updates come after a short three-week gap, indicating a rapid response to newly disclosed high-severity CVEs, necessitating immediate upgrades. Alongside these critical patches, significant fixes for opcache stability and JIT bugs have also been included in the updates. Users are advised to upgrade promptly and verify GPG signatures, with caution recommended for those using PHP 8.5 due to extensive changes in behavior



PHP 8.4.24 and 8.5.9 Patch Critical CVEs in DEB.SURY.ORG Security Update

Debian and Ubuntu users pulling from DEB.SURY.ORG received a coordinated batch of PHP updates across all active branches, led by PHP 8.4.24 and the development release 8.5.9. The July 30 patch cycle addresses high-severity vulnerabilities including a BCMath out-of-bounds write and a PostgreSQL SQL injection via pg_query(), alongside significant opcache stability fixes for the JIT. This three-week gap from the previous release indicates an emergency response to newly disclosed critical CVEs, prompting SURY to push security-only updates to both current stable and end-of-life approaching branches. Operators should upgrade immediately via apt-get update and verify GPG signatures, though 8.5 users are advised to test carefully due to the heavy changes to the tracing JIT and default OpCache behavior.

PHP 8.4.24 and 8.5.9 Patch Critical CVEs in DEB.SURY.ORG Security Update @ Linux Compatible