Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 42 phpunit10 Critical Code Exec Fix Advisory FEDORA-2026-1d1c8f5df2

fedora
Calendar Grey February 6, 2026
Dist Fedora Esm H88
PHPUnit 10.5.63 fixes critical vulnerabilities to prevent arbitrary code execution - Fedora update advisory.
Version 10.5.63 - 2026-01-27 Fixed Regression introduced in PHPUnit 9.6.33 Version 10.5.62 - 2026-01-27 Changed

Summary

PHPUnit is a programmer-oriented testing framework for PHP.

It is an instance of the xUnit architecture for unit testing frameworks.

This package provides the version 10 of PHPUnit,

available using the phpunit10 command.

Documentation: https://phpunit.de/documentation.html

Update Information:

Version 10.5.63 - 2026-01-27 Fixed Regression introduced in PHPUnit 9.6.33 Version 10.5.62 - 2026-01-27 Changed To prevent Poisoned Pipeline Execution (PPE) attacks using prepared .coverage files in pull requests, a PHPT test will no longer be run if the temporary file for writing code coverage information already exists before the test runs Version 10.5.61 - 2026-01-24 Changed PHPUnit\Framework\MockObject exceptions are now subtypes of PHPUnit\Exception

Change Log

* Tue Jan 27 2026 Remi Collet - 10.5.63-1 - update to 10.5.63 * Mon Jan 26 2026 Remi Collet - 10.5.61-1 - update to 10.5.61 - raise dependency on sebastian/comparator 5.0.5

References


[ 1 ] Bug #2433679 - CVE-2026-24765 phpunit10: PHPUnit: Arbitrary code execution via unsafe deserialization of code coverage files [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2433679

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1d1c8f5df2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: phpunit10
Product: Fedora 42
Version: 10.5.63
Release: 1.fc42
Summary: The PHP Unit Testing framework version 10

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here