SECURITY: Fedora 35 Update: php-8.0.16-1.fc35
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2022-1596a2dacb
2022-02-22 19:11:40.093323
--------------------------------------------------------------------------------
Name : php
Product : Fedora 35
Version : 8.0.16
Release : 1.fc35
URL : http://www.php.net/
Summary : PHP scripting language for creating dynamic web sites
Description :
PHP is an HTML-embedded scripting language. PHP attempts to make it
easy for developers to write dynamically generated web pages. PHP also
offers built-in database integration for several commercial and
non-commercial database management systems, so writing a
database-enabled webpage with PHP is fairly simple. The most common
use of PHP coding is probably as a replacement for CGI scripts.
--------------------------------------------------------------------------------
Update Information:
**PHP version 8.0.16** (17 Feb 2022) **Core:** * Fixed bug php#81430
(Attribute instantiation leaves dangling pointer). (beberlei) * Fixed bug
[GH-7896]( https://github.com/php/php-src/issues/7896) (Environment vars may be
mangled on Windows). (cmb) **FFI:** * Fixed bug
[GH-7867]( https://github.com/php/php-src/issues/7867) (FFI::cast() from pointer
to array is broken). (cmb, dmitry) **Filter:** * Fixed bug php#81708: UAF due
to php_filter_float() failing for ints. (**CVE-2021-21708**) (cmb) **FPM:** *
Fixed memory leak on invalid port. (David Carlier) **MBString:** * Fixed bug
[GH-7902]( https://github.com/php/php-src/issues/7902) (mb_send_mail may delimit
headers with LF only). (cmb) **MySQLnd:** * Fixed bug
[GH-7972]( https://github.com/php/php-src/issues/7972) (MariaDB version prefix
5.5.5- is not stripped). (Kamil Tekiela) **Sockets:** * Fixed ext/sockets
build on Haiku. (David Carlier) * Fixed bug
[GH-7978]( https://github.com/php/php-src/issues/7978) (sockets extension
compilation errors). (David Carlier) **Standard:** * Fixed bug
[GH-7875]( https://github.com/php/php-src/issues/7875) (mails are sent even if
failure to log throws exception). (cmb)
--------------------------------------------------------------------------------
ChangeLog:
* Wed Feb 16 2022 Remi Collet - 8.0.16-1
- Update to 8.0.16 - http://www.php.net/releases/8_0_16.php
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2055879 - CVE-2021-21708 php: Use after free due to php_filter_float() failing for ints
https://bugzilla.redhat.com/show_bug.cgi?id=2055879
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2022-1596a2dacb' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
A php security update has been released for Fedora 35.