{"affected":[{"ecosystem_specific":{"binaries":[{"apache2-mod_php8":"8.4.16-160000.1.1","php8":"8.4.16-160000.1.1","php8-bcmath":"8.4.16-160000.1.1","php8-bz2":"8.4.16-160000.1.1","php8-calendar":"8.4.16-160000.1.1","php8-cli":"8.4.16-160000.1.1","php8-ctype":"8.4.16-160000.1.1","php8-curl":"8.4.16-160000.1.1","php8-dba":"8.4.16-160000.1.1","php8-devel":"8.4.16-160000.1.1","php8-dom":"8.4.16-160000.1.1","php8-embed":"8.4.16-160000.1.1","php8-enchant":"8.4.16-160000.1.1","php8-exif":"8.4.16-160000.1.1","php8-fastcgi":"8.4.16-160000.1.1","php8-ffi":"8.4.16-160000.1.1","php8-fileinfo":"8.4.16-160000.1.1","php8-fpm":"8.4.16-160000.1.1","php8-fpm-apache":"8.4.16-160000.1.1","php8-ftp":"8.4.16-160000.1.1","php8-gd":"8.4.16-160000.1.1","php8-gettext":"8.4.16-160000.1.1","php8-gmp":"8.4.16-160000.1.1","php8-iconv":"8.4.16-160000.1.1","php8-intl":"8.4.16-160000.1.1","php8-ldap":"8.4.16-160000.1.1","php8-mbstring":"8.4.16-160000.1.1","php8-mysql":"8.4.16-160000.1.1","php8-odbc":"8.4.16-160000.1.1","php8-opcache":"8.4.16-160000.1.1","php8-openssl":"8.4.16-160000.1.1","php8-pcntl":"8.4.16-160000.1.1","php8-pdo":"8.4.16-160000.1.1","php8-pgsql":"8.4.16-160000.1.1","php8-phar":"8.4.16-160000.1.1","php8-posix":"8.4.16-160000.1.1","php8-readline":"8.4.16-160000.1.1","php8-shmop":"8.4.16-160000.1.1","php8-snmp":"8.4.16-160000.1.1","php8-soap":"8.4.16-160000.1.1","php8-sockets":"8.4.16-160000.1.1","php8-sodium":"8.4.16-160000.1.1","php8-sqlite":"8.4.16-160000.1.1","php8-sysvmsg":"8.4.16-160000.1.1","php8-sysvsem":"8.4.16-160000.1.1","php8-sysvshm":"8.4.16-160000.1.1","php8-test":"8.4.16-160000.1.1","php8-tidy":"8.4.16-160000.1.1","php8-tokenizer":"8.4.16-160000.1.1","php8-xmlreader":"8.4.16-160000.1.1","php8-xmlwriter":"8.4.16-160000.1.1","php8-xsl":"8.4.16-160000.1.1","php8-zip":"8.4.16-160000.1.1","php8-zlib":"8.4.16-160000.1.1"}]},"package":{"ecosystem":"openSUSE:Leap 16.0","name":"apache2-mod_php8","purl":"pkg:rpm/opensuse/apache2-mod_php8&distro=openSUSE%20Leap%2016.0"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.4.16-160000.1.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"apache2-mod_php8":"8.4.16-160000.1.1","php8":"8.4.16-160000.1.1","php8-bcmath":"8.4.16-160000.1.1","php8-bz2":"8.4.16-160000.1.1","php8-calendar":"8.4.16-160000.1.1","php8-cli":"8.4.16-160000.1.1","php8-ctype":"8.4.16-160000.1.1","php8-curl":"8.4.16-160000.1.1","php8-dba":"8.4.16-160000.1.1","php8-devel":"8.4.16-160000.1.1","php8-dom":"8.4.16-160000.1.1","php8-embed":"8.4.16-160000.1.1","php8-enchant":"8.4.16-160000.1.1","php8-exif":"8.4.16-160000.1.1","php8-fastcgi":"8.4.16-160000.1.1","php8-ffi":"8.4.16-160000.1.1","php8-fileinfo":"8.4.16-160000.1.1","php8-fpm":"8.4.16-160000.1.1","php8-fpm-apache":"8.4.16-160000.1.1","php8-ftp":"8.4.16-160000.1.1","php8-gd":"8.4.16-160000.1.1","php8-gettext":"8.4.16-160000.1.1","php8-gmp":"8.4.16-160000.1.1","php8-iconv":"8.4.16-160000.1.1","php8-intl":"8.4.16-160000.1.1","php8-ldap":"8.4.16-160000.1.1","php8-mbstring":"8.4.16-160000.1.1","php8-mysql":"8.4.16-160000.1.1","php8-odbc":"8.4.16-160000.1.1","php8-opcache":"8.4.16-160000.1.1","php8-openssl":"8.4.16-160000.1.1","php8-pcntl":"8.4.16-160000.1.1","php8-pdo":"8.4.16-160000.1.1","php8-pgsql":"8.4.16-160000.1.1","php8-phar":"8.4.16-160000.1.1","php8-posix":"8.4.16-160000.1.1","php8-readline":"8.4.16-160000.1.1","php8-shmop":"8.4.16-160000.1.1","php8-snmp":"8.4.16-160000.1.1","php8-soap":"8.4.16-160000.1.1","php8-sockets":"8.4.16-160000.1.1","php8-sodium":"8.4.16-160000.1.1","php8-sqlite":"8.4.16-160000.1.1","php8-sysvmsg":"8.4.16-160000.1.1","php8-sysvsem":"8.4.16-160000.1.1","php8-sysvshm":"8.4.16-160000.1.1","php8-test":"8.4.16-160000.1.1","php8-tidy":"8.4.16-160000.1.1","php8-tokenizer":"8.4.16-160000.1.1","php8-xmlreader":"8.4.16-160000.1.1","php8-xmlwriter":"8.4.16-160000.1.1","php8-xsl":"8.4.16-160000.1.1","php8-zip":"8.4.16-160000.1.1","php8-zlib":"8.4.16-160000.1.1"}]},"package":{"ecosystem":"openSUSE:Leap 16.0","name":"php8","purl":"pkg:rpm/opensuse/php8&distro=openSUSE%20Leap%2016.0"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.4.16-160000.1.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"apache2-mod_php8":"8.4.16-160000.1.1","php8":"8.4.16-160000.1.1","php8-bcmath":"8.4.16-160000.1.1","php8-bz2":"8.4.16-160000.1.1","php8-calendar":"8.4.16-160000.1.1","php8-cli":"8.4.16-160000.1.1","php8-ctype":"8.4.16-160000.1.1","php8-curl":"8.4.16-160000.1.1","php8-dba":"8.4.16-160000.1.1","php8-devel":"8.4.16-160000.1.1","php8-dom":"8.4.16-160000.1.1","php8-embed":"8.4.16-160000.1.1","php8-enchant":"8.4.16-160000.1.1","php8-exif":"8.4.16-160000.1.1","php8-fastcgi":"8.4.16-160000.1.1","php8-ffi":"8.4.16-160000.1.1","php8-fileinfo":"8.4.16-160000.1.1","php8-fpm":"8.4.16-160000.1.1","php8-fpm-apache":"8.4.16-160000.1.1","php8-ftp":"8.4.16-160000.1.1","php8-gd":"8.4.16-160000.1.1","php8-gettext":"8.4.16-160000.1.1","php8-gmp":"8.4.16-160000.1.1","php8-iconv":"8.4.16-160000.1.1","php8-intl":"8.4.16-160000.1.1","php8-ldap":"8.4.16-160000.1.1","php8-mbstring":"8.4.16-160000.1.1","php8-mysql":"8.4.16-160000.1.1","php8-odbc":"8.4.16-160000.1.1","php8-opcache":"8.4.16-160000.1.1","php8-openssl":"8.4.16-160000.1.1","php8-pcntl":"8.4.16-160000.1.1","php8-pdo":"8.4.16-160000.1.1","php8-pgsql":"8.4.16-160000.1.1","php8-phar":"8.4.16-160000.1.1","php8-posix":"8.4.16-160000.1.1","php8-readline":"8.4.16-160000.1.1","php8-shmop":"8.4.16-160000.1.1","php8-snmp":"8.4.16-160000.1.1","php8-soap":"8.4.16-160000.1.1","php8-sockets":"8.4.16-160000.1.1","php8-sodium":"8.4.16-160000.1.1","php8-sqlite":"8.4.16-160000.1.1","php8-sysvmsg":"8.4.16-160000.1.1","php8-sysvsem":"8.4.16-160000.1.1","php8-sysvshm":"8.4.16-160000.1.1","php8-test":"8.4.16-160000.1.1","php8-tidy":"8.4.16-160000.1.1","php8-tokenizer":"8.4.16-160000.1.1","php8-xmlreader":"8.4.16-160000.1.1","php8-xmlwriter":"8.4.16-160000.1.1","php8-xsl":"8.4.16-160000.1.1","php8-zip":"8.4.16-160000.1.1","php8-zlib":"8.4.16-160000.1.1"}]},"package":{"ecosystem":"openSUSE:Leap 16.0","name":"php8-embed","purl":"pkg:rpm/opensuse/php8-embed&distro=openSUSE%20Leap%2016.0"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.4.16-160000.1.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"apache2-mod_php8":"8.4.16-160000.1.1","php8":"8.4.16-160000.1.1","php8-bcmath":"8.4.16-160000.1.1","php8-bz2":"8.4.16-160000.1.1","php8-calendar":"8.4.16-160000.1.1","php8-cli":"8.4.16-160000.1.1","php8-ctype":"8.4.16-160000.1.1","php8-curl":"8.4.16-160000.1.1","php8-dba":"8.4.16-160000.1.1","php8-devel":"8.4.16-160000.1.1","php8-dom":"8.4.16-160000.1.1","php8-embed":"8.4.16-160000.1.1","php8-enchant":"8.4.16-160000.1.1","php8-exif":"8.4.16-160000.1.1","php8-fastcgi":"8.4.16-160000.1.1","php8-ffi":"8.4.16-160000.1.1","php8-fileinfo":"8.4.16-160000.1.1","php8-fpm":"8.4.16-160000.1.1","php8-fpm-apache":"8.4.16-160000.1.1","php8-ftp":"8.4.16-160000.1.1","php8-gd":"8.4.16-160000.1.1","php8-gettext":"8.4.16-160000.1.1","php8-gmp":"8.4.16-160000.1.1","php8-iconv":"8.4.16-160000.1.1","php8-intl":"8.4.16-160000.1.1","php8-ldap":"8.4.16-160000.1.1","php8-mbstring":"8.4.16-160000.1.1","php8-mysql":"8.4.16-160000.1.1","php8-odbc":"8.4.16-160000.1.1","php8-opcache":"8.4.16-160000.1.1","php8-openssl":"8.4.16-160000.1.1","php8-pcntl":"8.4.16-160000.1.1","php8-pdo":"8.4.16-160000.1.1","php8-pgsql":"8.4.16-160000.1.1","php8-phar":"8.4.16-160000.1.1","php8-posix":"8.4.16-160000.1.1","php8-readline":"8.4.16-160000.1.1","php8-shmop":"8.4.16-160000.1.1","php8-snmp":"8.4.16-160000.1.1","php8-soap":"8.4.16-160000.1.1","php8-sockets":"8.4.16-160000.1.1","php8-sodium":"8.4.16-160000.1.1","php8-sqlite":"8.4.16-160000.1.1","php8-sysvmsg":"8.4.16-160000.1.1","php8-sysvsem":"8.4.16-160000.1.1","php8-sysvshm":"8.4.16-160000.1.1","php8-test":"8.4.16-160000.1.1","php8-tidy":"8.4.16-160000.1.1","php8-tokenizer":"8.4.16-160000.1.1","php8-xmlreader":"8.4.16-160000.1.1","php8-xmlwriter":"8.4.16-160000.1.1","php8-xsl":"8.4.16-160000.1.1","php8-zip":"8.4.16-160000.1.1","php8-zlib":"8.4.16-160000.1.1"}]},"package":{"ecosystem":"openSUSE:Leap 16.0","name":"php8-fastcgi","purl":"pkg:rpm/opensuse/php8-fastcgi&distro=openSUSE%20Leap%2016.0"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.4.16-160000.1.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"apache2-mod_php8":"8.4.16-160000.1.1","php8":"8.4.16-160000.1.1","php8-bcmath":"8.4.16-160000.1.1","php8-bz2":"8.4.16-160000.1.1","php8-calendar":"8.4.16-160000.1.1","php8-cli":"8.4.16-160000.1.1","php8-ctype":"8.4.16-160000.1.1","php8-curl":"8.4.16-160000.1.1","php8-dba":"8.4.16-160000.1.1","php8-devel":"8.4.16-160000.1.1","php8-dom":"8.4.16-160000.1.1","php8-embed":"8.4.16-160000.1.1","php8-enchant":"8.4.16-160000.1.1","php8-exif":"8.4.16-160000.1.1","php8-fastcgi":"8.4.16-160000.1.1","php8-ffi":"8.4.16-160000.1.1","php8-fileinfo":"8.4.16-160000.1.1","php8-fpm":"8.4.16-160000.1.1","php8-fpm-apache":"8.4.16-160000.1.1","php8-ftp":"8.4.16-160000.1.1","php8-gd":"8.4.16-160000.1.1","php8-gettext":"8.4.16-160000.1.1","php8-gmp":"8.4.16-160000.1.1","php8-iconv":"8.4.16-160000.1.1","php8-intl":"8.4.16-160000.1.1","php8-ldap":"8.4.16-160000.1.1","php8-mbstring":"8.4.16-160000.1.1","php8-mysql":"8.4.16-160000.1.1","php8-odbc":"8.4.16-160000.1.1","php8-opcache":"8.4.16-160000.1.1","php8-openssl":"8.4.16-160000.1.1","php8-pcntl":"8.4.16-160000.1.1","php8-pdo":"8.4.16-160000.1.1","php8-pgsql":"8.4.16-160000.1.1","php8-phar":"8.4.16-160000.1.1","php8-posix":"8.4.16-160000.1.1","php8-readline":"8.4.16-160000.1.1","php8-shmop":"8.4.16-160000.1.1","php8-snmp":"8.4.16-160000.1.1","php8-soap":"8.4.16-160000.1.1","php8-sockets":"8.4.16-160000.1.1","php8-sodium":"8.4.16-160000.1.1","php8-sqlite":"8.4.16-160000.1.1","php8-sysvmsg":"8.4.16-160000.1.1","php8-sysvsem":"8.4.16-160000.1.1","php8-sysvshm":"8.4.16-160000.1.1","php8-test":"8.4.16-160000.1.1","php8-tidy":"8.4.16-160000.1.1","php8-tokenizer":"8.4.16-160000.1.1","php8-xmlreader":"8.4.16-160000.1.1","php8-xmlwriter":"8.4.16-160000.1.1","php8-xsl":"8.4.16-160000.1.1","php8-zip":"8.4.16-160000.1.1","php8-zlib":"8.4.16-160000.1.1"}]},"package":{"ecosystem":"openSUSE:Leap 16.0","name":"php8-fpm","purl":"pkg:rpm/opensuse/php8-fpm&distro=openSUSE%20Leap%2016.0"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.4.16-160000.1.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"apache2-mod_php8":"8.4.16-160000.1.1","php8":"8.4.16-160000.1.1","php8-bcmath":"8.4.16-160000.1.1","php8-bz2":"8.4.16-160000.1.1","php8-calendar":"8.4.16-160000.1.1","php8-cli":"8.4.16-160000.1.1","php8-ctype":"8.4.16-160000.1.1","php8-curl":"8.4.16-160000.1.1","php8-dba":"8.4.16-160000.1.1","php8-devel":"8.4.16-160000.1.1","php8-dom":"8.4.16-160000.1.1","php8-embed":"8.4.16-160000.1.1","php8-enchant":"8.4.16-160000.1.1","php8-exif":"8.4.16-160000.1.1","php8-fastcgi":"8.4.16-160000.1.1","php8-ffi":"8.4.16-160000.1.1","php8-fileinfo":"8.4.16-160000.1.1","php8-fpm":"8.4.16-160000.1.1","php8-fpm-apache":"8.4.16-160000.1.1","php8-ftp":"8.4.16-160000.1.1","php8-gd":"8.4.16-160000.1.1","php8-gettext":"8.4.16-160000.1.1","php8-gmp":"8.4.16-160000.1.1","php8-iconv":"8.4.16-160000.1.1","php8-intl":"8.4.16-160000.1.1","php8-ldap":"8.4.16-160000.1.1","php8-mbstring":"8.4.16-160000.1.1","php8-mysql":"8.4.16-160000.1.1","php8-odbc":"8.4.16-160000.1.1","php8-opcache":"8.4.16-160000.1.1","php8-openssl":"8.4.16-160000.1.1","php8-pcntl":"8.4.16-160000.1.1","php8-pdo":"8.4.16-160000.1.1","php8-pgsql":"8.4.16-160000.1.1","php8-phar":"8.4.16-160000.1.1","php8-posix":"8.4.16-160000.1.1","php8-readline":"8.4.16-160000.1.1","php8-shmop":"8.4.16-160000.1.1","php8-snmp":"8.4.16-160000.1.1","php8-soap":"8.4.16-160000.1.1","php8-sockets":"8.4.16-160000.1.1","php8-sodium":"8.4.16-160000.1.1","php8-sqlite":"8.4.16-160000.1.1","php8-sysvmsg":"8.4.16-160000.1.1","php8-sysvsem":"8.4.16-160000.1.1","php8-sysvshm":"8.4.16-160000.1.1","php8-test":"8.4.16-160000.1.1","php8-tidy":"8.4.16-160000.1.1","php8-tokenizer":"8.4.16-160000.1.1","php8-xmlreader":"8.4.16-160000.1.1","php8-xmlwriter":"8.4.16-160000.1.1","php8-xsl":"8.4.16-160000.1.1","php8-zip":"8.4.16-160000.1.1","php8-zlib":"8.4.16-160000.1.1"}]},"package":{"ecosystem":"openSUSE:Leap 16.0","name":"php8-test","purl":"pkg:rpm/opensuse/php8-test&distro=openSUSE%20Leap%2016.0"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.4.16-160000.1.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for php8 fixes the following issues:\n\nVersion update to 8.4.16:\n\nSecurity fixes:\n\n- CVE-2025-14177: getimagesize() function may leak uninitialized heap memory into the APPn segments when reading images in multi-chunk mode (bsc#1255710).\n- CVE-2025-14178: heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE (bsc#1255711).\n- CVE-2025-14180: null pointer dereference in pdo_parse_params() function when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled (bsc#1255712).\n\nOther fixes:\n\n- php8 contains Directories owned by wwwrun but does not require User. (bsc#1255043)\n","id":"openSUSE-SU-2026:20113-1","modified":"2026-01-26T12:37:41Z","published":"2026-01-26T12:37:41Z","references":[{"type":"ADVISORY","url":null},{"type":"REPORT","url":"https://bugzilla.suse.com/1255043"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255710"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255711"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255712"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-14177"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-14178"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-14180"}],"related":["CVE-2025-14177","CVE-2025-14178","CVE-2025-14180"],"summary":"Security update for php8","upstream":["CVE-2025-14177","CVE-2025-14178","CVE-2025-14180"]}