{"affected":[{"ecosystem_specific":{"binaries":[{"apache2-mod_php8":"8.2.30-150600.3.25.1","php8":"8.2.30-150600.3.25.1","php8-bcmath":"8.2.30-150600.3.25.1","php8-bz2":"8.2.30-150600.3.25.1","php8-calendar":"8.2.30-150600.3.25.1","php8-cli":"8.2.30-150600.3.25.1","php8-ctype":"8.2.30-150600.3.25.1","php8-curl":"8.2.30-150600.3.25.1","php8-dba":"8.2.30-150600.3.25.1","php8-devel":"8.2.30-150600.3.25.1","php8-dom":"8.2.30-150600.3.25.1","php8-embed":"8.2.30-150600.3.25.1","php8-enchant":"8.2.30-150600.3.25.1","php8-exif":"8.2.30-150600.3.25.1","php8-fastcgi":"8.2.30-150600.3.25.1","php8-ffi":"8.2.30-150600.3.25.1","php8-fileinfo":"8.2.30-150600.3.25.1","php8-fpm":"8.2.30-150600.3.25.1","php8-fpm-apache":"8.2.30-150600.3.25.1","php8-ftp":"8.2.30-150600.3.25.1","php8-gd":"8.2.30-150600.3.25.1","php8-gettext":"8.2.30-150600.3.25.1","php8-gmp":"8.2.30-150600.3.25.1","php8-iconv":"8.2.30-150600.3.25.1","php8-intl":"8.2.30-150600.3.25.1","php8-ldap":"8.2.30-150600.3.25.1","php8-mbstring":"8.2.30-150600.3.25.1","php8-mysql":"8.2.30-150600.3.25.1","php8-odbc":"8.2.30-150600.3.25.1","php8-opcache":"8.2.30-150600.3.25.1","php8-openssl":"8.2.30-150600.3.25.1","php8-pcntl":"8.2.30-150600.3.25.1","php8-pdo":"8.2.30-150600.3.25.1","php8-pgsql":"8.2.30-150600.3.25.1","php8-phar":"8.2.30-150600.3.25.1","php8-posix":"8.2.30-150600.3.25.1","php8-readline":"8.2.30-150600.3.25.1","php8-shmop":"8.2.30-150600.3.25.1","php8-snmp":"8.2.30-150600.3.25.1","php8-soap":"8.2.30-150600.3.25.1","php8-sockets":"8.2.30-150600.3.25.1","php8-sodium":"8.2.30-150600.3.25.1","php8-sqlite":"8.2.30-150600.3.25.1","php8-sysvmsg":"8.2.30-150600.3.25.1","php8-sysvsem":"8.2.30-150600.3.25.1","php8-sysvshm":"8.2.30-150600.3.25.1","php8-test":"8.2.30-150600.3.25.1","php8-tidy":"8.2.30-150600.3.25.1","php8-tokenizer":"8.2.30-150600.3.25.1","php8-xmlreader":"8.2.30-150600.3.25.1","php8-xmlwriter":"8.2.30-150600.3.25.1","php8-xsl":"8.2.30-150600.3.25.1","php8-zip":"8.2.30-150600.3.25.1","php8-zlib":"8.2.30-150600.3.25.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.6","name":"apache2-mod_php8","purl":"pkg:rpm/opensuse/apache2-mod_php8&distro=openSUSE%20Leap%2015.6"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.2.30-150600.3.25.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"apache2-mod_php8":"8.2.30-150600.3.25.1","php8":"8.2.30-150600.3.25.1","php8-bcmath":"8.2.30-150600.3.25.1","php8-bz2":"8.2.30-150600.3.25.1","php8-calendar":"8.2.30-150600.3.25.1","php8-cli":"8.2.30-150600.3.25.1","php8-ctype":"8.2.30-150600.3.25.1","php8-curl":"8.2.30-150600.3.25.1","php8-dba":"8.2.30-150600.3.25.1","php8-devel":"8.2.30-150600.3.25.1","php8-dom":"8.2.30-150600.3.25.1","php8-embed":"8.2.30-150600.3.25.1","php8-enchant":"8.2.30-150600.3.25.1","php8-exif":"8.2.30-150600.3.25.1","php8-fastcgi":"8.2.30-150600.3.25.1","php8-ffi":"8.2.30-150600.3.25.1","php8-fileinfo":"8.2.30-150600.3.25.1","php8-fpm":"8.2.30-150600.3.25.1","php8-fpm-apache":"8.2.30-150600.3.25.1","php8-ftp":"8.2.30-150600.3.25.1","php8-gd":"8.2.30-150600.3.25.1","php8-gettext":"8.2.30-150600.3.25.1","php8-gmp":"8.2.30-150600.3.25.1","php8-iconv":"8.2.30-150600.3.25.1","php8-intl":"8.2.30-150600.3.25.1","php8-ldap":"8.2.30-150600.3.25.1","php8-mbstring":"8.2.30-150600.3.25.1","php8-mysql":"8.2.30-150600.3.25.1","php8-odbc":"8.2.30-150600.3.25.1","php8-opcache":"8.2.30-150600.3.25.1","php8-openssl":"8.2.30-150600.3.25.1","php8-pcntl":"8.2.30-150600.3.25.1","php8-pdo":"8.2.30-150600.3.25.1","php8-pgsql":"8.2.30-150600.3.25.1","php8-phar":"8.2.30-150600.3.25.1","php8-posix":"8.2.30-150600.3.25.1","php8-readline":"8.2.30-150600.3.25.1","php8-shmop":"8.2.30-150600.3.25.1","php8-snmp":"8.2.30-150600.3.25.1","php8-soap":"8.2.30-150600.3.25.1","php8-sockets":"8.2.30-150600.3.25.1","php8-sodium":"8.2.30-150600.3.25.1","php8-sqlite":"8.2.30-150600.3.25.1","php8-sysvmsg":"8.2.30-150600.3.25.1","php8-sysvsem":"8.2.30-150600.3.25.1","php8-sysvshm":"8.2.30-150600.3.25.1","php8-test":"8.2.30-150600.3.25.1","php8-tidy":"8.2.30-150600.3.25.1","php8-tokenizer":"8.2.30-150600.3.25.1","php8-xmlreader":"8.2.30-150600.3.25.1","php8-xmlwriter":"8.2.30-150600.3.25.1","php8-xsl":"8.2.30-150600.3.25.1","php8-zip":"8.2.30-150600.3.25.1","php8-zlib":"8.2.30-150600.3.25.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.6","name":"php8","purl":"pkg:rpm/opensuse/php8&distro=openSUSE%20Leap%2015.6"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.2.30-150600.3.25.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"apache2-mod_php8":"8.2.30-150600.3.25.1","php8":"8.2.30-150600.3.25.1","php8-bcmath":"8.2.30-150600.3.25.1","php8-bz2":"8.2.30-150600.3.25.1","php8-calendar":"8.2.30-150600.3.25.1","php8-cli":"8.2.30-150600.3.25.1","php8-ctype":"8.2.30-150600.3.25.1","php8-curl":"8.2.30-150600.3.25.1","php8-dba":"8.2.30-150600.3.25.1","php8-devel":"8.2.30-150600.3.25.1","php8-dom":"8.2.30-150600.3.25.1","php8-embed":"8.2.30-150600.3.25.1","php8-enchant":"8.2.30-150600.3.25.1","php8-exif":"8.2.30-150600.3.25.1","php8-fastcgi":"8.2.30-150600.3.25.1","php8-ffi":"8.2.30-150600.3.25.1","php8-fileinfo":"8.2.30-150600.3.25.1","php8-fpm":"8.2.30-150600.3.25.1","php8-fpm-apache":"8.2.30-150600.3.25.1","php8-ftp":"8.2.30-150600.3.25.1","php8-gd":"8.2.30-150600.3.25.1","php8-gettext":"8.2.30-150600.3.25.1","php8-gmp":"8.2.30-150600.3.25.1","php8-iconv":"8.2.30-150600.3.25.1","php8-intl":"8.2.30-150600.3.25.1","php8-ldap":"8.2.30-150600.3.25.1","php8-mbstring":"8.2.30-150600.3.25.1","php8-mysql":"8.2.30-150600.3.25.1","php8-odbc":"8.2.30-150600.3.25.1","php8-opcache":"8.2.30-150600.3.25.1","php8-openssl":"8.2.30-150600.3.25.1","php8-pcntl":"8.2.30-150600.3.25.1","php8-pdo":"8.2.30-150600.3.25.1","php8-pgsql":"8.2.30-150600.3.25.1","php8-phar":"8.2.30-150600.3.25.1","php8-posix":"8.2.30-150600.3.25.1","php8-readline":"8.2.30-150600.3.25.1","php8-shmop":"8.2.30-150600.3.25.1","php8-snmp":"8.2.30-150600.3.25.1","php8-soap":"8.2.30-150600.3.25.1","php8-sockets":"8.2.30-150600.3.25.1","php8-sodium":"8.2.30-150600.3.25.1","php8-sqlite":"8.2.30-150600.3.25.1","php8-sysvmsg":"8.2.30-150600.3.25.1","php8-sysvsem":"8.2.30-150600.3.25.1","php8-sysvshm":"8.2.30-150600.3.25.1","php8-test":"8.2.30-150600.3.25.1","php8-tidy":"8.2.30-150600.3.25.1","php8-tokenizer":"8.2.30-150600.3.25.1","php8-xmlreader":"8.2.30-150600.3.25.1","php8-xmlwriter":"8.2.30-150600.3.25.1","php8-xsl":"8.2.30-150600.3.25.1","php8-zip":"8.2.30-150600.3.25.1","php8-zlib":"8.2.30-150600.3.25.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.6","name":"php8-embed","purl":"pkg:rpm/opensuse/php8-embed&distro=openSUSE%20Leap%2015.6"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.2.30-150600.3.25.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"apache2-mod_php8":"8.2.30-150600.3.25.1","php8":"8.2.30-150600.3.25.1","php8-bcmath":"8.2.30-150600.3.25.1","php8-bz2":"8.2.30-150600.3.25.1","php8-calendar":"8.2.30-150600.3.25.1","php8-cli":"8.2.30-150600.3.25.1","php8-ctype":"8.2.30-150600.3.25.1","php8-curl":"8.2.30-150600.3.25.1","php8-dba":"8.2.30-150600.3.25.1","php8-devel":"8.2.30-150600.3.25.1","php8-dom":"8.2.30-150600.3.25.1","php8-embed":"8.2.30-150600.3.25.1","php8-enchant":"8.2.30-150600.3.25.1","php8-exif":"8.2.30-150600.3.25.1","php8-fastcgi":"8.2.30-150600.3.25.1","php8-ffi":"8.2.30-150600.3.25.1","php8-fileinfo":"8.2.30-150600.3.25.1","php8-fpm":"8.2.30-150600.3.25.1","php8-fpm-apache":"8.2.30-150600.3.25.1","php8-ftp":"8.2.30-150600.3.25.1","php8-gd":"8.2.30-150600.3.25.1","php8-gettext":"8.2.30-150600.3.25.1","php8-gmp":"8.2.30-150600.3.25.1","php8-iconv":"8.2.30-150600.3.25.1","php8-intl":"8.2.30-150600.3.25.1","php8-ldap":"8.2.30-150600.3.25.1","php8-mbstring":"8.2.30-150600.3.25.1","php8-mysql":"8.2.30-150600.3.25.1","php8-odbc":"8.2.30-150600.3.25.1","php8-opcache":"8.2.30-150600.3.25.1","php8-openssl":"8.2.30-150600.3.25.1","php8-pcntl":"8.2.30-150600.3.25.1","php8-pdo":"8.2.30-150600.3.25.1","php8-pgsql":"8.2.30-150600.3.25.1","php8-phar":"8.2.30-150600.3.25.1","php8-posix":"8.2.30-150600.3.25.1","php8-readline":"8.2.30-150600.3.25.1","php8-shmop":"8.2.30-150600.3.25.1","php8-snmp":"8.2.30-150600.3.25.1","php8-soap":"8.2.30-150600.3.25.1","php8-sockets":"8.2.30-150600.3.25.1","php8-sodium":"8.2.30-150600.3.25.1","php8-sqlite":"8.2.30-150600.3.25.1","php8-sysvmsg":"8.2.30-150600.3.25.1","php8-sysvsem":"8.2.30-150600.3.25.1","php8-sysvshm":"8.2.30-150600.3.25.1","php8-test":"8.2.30-150600.3.25.1","php8-tidy":"8.2.30-150600.3.25.1","php8-tokenizer":"8.2.30-150600.3.25.1","php8-xmlreader":"8.2.30-150600.3.25.1","php8-xmlwriter":"8.2.30-150600.3.25.1","php8-xsl":"8.2.30-150600.3.25.1","php8-zip":"8.2.30-150600.3.25.1","php8-zlib":"8.2.30-150600.3.25.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.6","name":"php8-fastcgi","purl":"pkg:rpm/opensuse/php8-fastcgi&distro=openSUSE%20Leap%2015.6"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.2.30-150600.3.25.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"apache2-mod_php8":"8.2.30-150600.3.25.1","php8":"8.2.30-150600.3.25.1","php8-bcmath":"8.2.30-150600.3.25.1","php8-bz2":"8.2.30-150600.3.25.1","php8-calendar":"8.2.30-150600.3.25.1","php8-cli":"8.2.30-150600.3.25.1","php8-ctype":"8.2.30-150600.3.25.1","php8-curl":"8.2.30-150600.3.25.1","php8-dba":"8.2.30-150600.3.25.1","php8-devel":"8.2.30-150600.3.25.1","php8-dom":"8.2.30-150600.3.25.1","php8-embed":"8.2.30-150600.3.25.1","php8-enchant":"8.2.30-150600.3.25.1","php8-exif":"8.2.30-150600.3.25.1","php8-fastcgi":"8.2.30-150600.3.25.1","php8-ffi":"8.2.30-150600.3.25.1","php8-fileinfo":"8.2.30-150600.3.25.1","php8-fpm":"8.2.30-150600.3.25.1","php8-fpm-apache":"8.2.30-150600.3.25.1","php8-ftp":"8.2.30-150600.3.25.1","php8-gd":"8.2.30-150600.3.25.1","php8-gettext":"8.2.30-150600.3.25.1","php8-gmp":"8.2.30-150600.3.25.1","php8-iconv":"8.2.30-150600.3.25.1","php8-intl":"8.2.30-150600.3.25.1","php8-ldap":"8.2.30-150600.3.25.1","php8-mbstring":"8.2.30-150600.3.25.1","php8-mysql":"8.2.30-150600.3.25.1","php8-odbc":"8.2.30-150600.3.25.1","php8-opcache":"8.2.30-150600.3.25.1","php8-openssl":"8.2.30-150600.3.25.1","php8-pcntl":"8.2.30-150600.3.25.1","php8-pdo":"8.2.30-150600.3.25.1","php8-pgsql":"8.2.30-150600.3.25.1","php8-phar":"8.2.30-150600.3.25.1","php8-posix":"8.2.30-150600.3.25.1","php8-readline":"8.2.30-150600.3.25.1","php8-shmop":"8.2.30-150600.3.25.1","php8-snmp":"8.2.30-150600.3.25.1","php8-soap":"8.2.30-150600.3.25.1","php8-sockets":"8.2.30-150600.3.25.1","php8-sodium":"8.2.30-150600.3.25.1","php8-sqlite":"8.2.30-150600.3.25.1","php8-sysvmsg":"8.2.30-150600.3.25.1","php8-sysvsem":"8.2.30-150600.3.25.1","php8-sysvshm":"8.2.30-150600.3.25.1","php8-test":"8.2.30-150600.3.25.1","php8-tidy":"8.2.30-150600.3.25.1","php8-tokenizer":"8.2.30-150600.3.25.1","php8-xmlreader":"8.2.30-150600.3.25.1","php8-xmlwriter":"8.2.30-150600.3.25.1","php8-xsl":"8.2.30-150600.3.25.1","php8-zip":"8.2.30-150600.3.25.1","php8-zlib":"8.2.30-150600.3.25.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.6","name":"php8-fpm","purl":"pkg:rpm/opensuse/php8-fpm&distro=openSUSE%20Leap%2015.6"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.2.30-150600.3.25.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"apache2-mod_php8":"8.2.30-150600.3.25.1","php8":"8.2.30-150600.3.25.1","php8-bcmath":"8.2.30-150600.3.25.1","php8-bz2":"8.2.30-150600.3.25.1","php8-calendar":"8.2.30-150600.3.25.1","php8-cli":"8.2.30-150600.3.25.1","php8-ctype":"8.2.30-150600.3.25.1","php8-curl":"8.2.30-150600.3.25.1","php8-dba":"8.2.30-150600.3.25.1","php8-devel":"8.2.30-150600.3.25.1","php8-dom":"8.2.30-150600.3.25.1","php8-embed":"8.2.30-150600.3.25.1","php8-enchant":"8.2.30-150600.3.25.1","php8-exif":"8.2.30-150600.3.25.1","php8-fastcgi":"8.2.30-150600.3.25.1","php8-ffi":"8.2.30-150600.3.25.1","php8-fileinfo":"8.2.30-150600.3.25.1","php8-fpm":"8.2.30-150600.3.25.1","php8-fpm-apache":"8.2.30-150600.3.25.1","php8-ftp":"8.2.30-150600.3.25.1","php8-gd":"8.2.30-150600.3.25.1","php8-gettext":"8.2.30-150600.3.25.1","php8-gmp":"8.2.30-150600.3.25.1","php8-iconv":"8.2.30-150600.3.25.1","php8-intl":"8.2.30-150600.3.25.1","php8-ldap":"8.2.30-150600.3.25.1","php8-mbstring":"8.2.30-150600.3.25.1","php8-mysql":"8.2.30-150600.3.25.1","php8-odbc":"8.2.30-150600.3.25.1","php8-opcache":"8.2.30-150600.3.25.1","php8-openssl":"8.2.30-150600.3.25.1","php8-pcntl":"8.2.30-150600.3.25.1","php8-pdo":"8.2.30-150600.3.25.1","php8-pgsql":"8.2.30-150600.3.25.1","php8-phar":"8.2.30-150600.3.25.1","php8-posix":"8.2.30-150600.3.25.1","php8-readline":"8.2.30-150600.3.25.1","php8-shmop":"8.2.30-150600.3.25.1","php8-snmp":"8.2.30-150600.3.25.1","php8-soap":"8.2.30-150600.3.25.1","php8-sockets":"8.2.30-150600.3.25.1","php8-sodium":"8.2.30-150600.3.25.1","php8-sqlite":"8.2.30-150600.3.25.1","php8-sysvmsg":"8.2.30-150600.3.25.1","php8-sysvsem":"8.2.30-150600.3.25.1","php8-sysvshm":"8.2.30-150600.3.25.1","php8-test":"8.2.30-150600.3.25.1","php8-tidy":"8.2.30-150600.3.25.1","php8-tokenizer":"8.2.30-150600.3.25.1","php8-xmlreader":"8.2.30-150600.3.25.1","php8-xmlwriter":"8.2.30-150600.3.25.1","php8-xsl":"8.2.30-150600.3.25.1","php8-zip":"8.2.30-150600.3.25.1","php8-zlib":"8.2.30-150600.3.25.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.6","name":"php8-test","purl":"pkg:rpm/opensuse/php8-test&distro=openSUSE%20Leap%2015.6"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.2.30-150600.3.25.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for php8 fixes the following issues:\n\nSecurity fixes:\n  \n- CVE-2025-14177: getimagesize() function may leak uninitialized heap memory into the APPn segments when reading images in multi-chunk mode (bsc#1255710).\n- CVE-2025-14178: heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE (bsc#1255711).\n- CVE-2025-14180: null pointer dereference in pdo_parse_params() function when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled (bsc#1255712).\n\nOther fixes:\n\n- Update to 8.2.30:\n    Curl:\n        Fix curl build and test failures with version 8.16.\n    Opcache:\n        Reset global pointers to prevent use-after-free in zend_jit_status().\n    PDO:\n        Fixed GHSA-8xr5-qppj-gvwj (PDO quoting result null deref). (CVE-2025-14180)\n    Standard:\n        Fixed GHSA-www2-q4fc-65wf (Null byte termination in dns_get_record()).\n        Fixed GHSA-h96m-rvf9-jgm2 (Heap buffer overflow in array_merge()). (CVE-2025-14178)\n        Fixed GHSA-3237-qqm7-mfv7 (Information Leak of Memory in getimagesize). (CVE-2025-14177)\n","id":"SUSE-SU-2026:0071-1","modified":"2026-01-08T13:22:08Z","published":"2026-01-08T13:22:08Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20260071-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255710"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255711"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255712"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-14177"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-14178"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-14180"}],"related":["CVE-2025-14177","CVE-2025-14178","CVE-2025-14180"],"summary":"Security update for php8","upstream":["CVE-2025-14177","CVE-2025-14178","CVE-2025-14180"]}