Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Mageia 9 MGASA-2025-0203 critical: php NULL Pointer Dereference Fix

mageia
Calendar Grey July 5, 2025
Dist Mageia Esm H88
Critical vulnerabilities in Mageia PHP, PGSQL, and SOAP fixed to enhance security against exploitation risks.
PGSQL: Fixed GHSA-hrwm-9436-5mv3 (pgsql extension does not check for errors during escaping)

Summary

PGSQL: Fixed GHSA-hrwm-9436-5mv3 (pgsql extension does not check for errors during escaping). (CVE-2025-1735) SOAP: Fixed GHSA-453j-q27h-5p8x (NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix). (CVE-2025-6491) Standard: Fixed GHSA-3cr5-j632-f35r (Null byte termination in hostnames). (CVE-2025-1220)

References

- https://bugs.mageia.org/show_bug.cgi?id=34418

- https://www.php.net/ChangeLog-8.php#8.2.29

- https://www.cve.org/CVERecord?id=CVE-2025-1735

- https://www.cve.org/CVERecord?id=CVE-2025-6491

- https://www.cve.org/CVERecord?id=CVE-2025-1220

Resolution

SRPMS

- 9/core/php-8.2.29-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 05 Jul 2025
URL: https://advisories.mageia.org/MGASA-2025-0203.html
Type: security
CVE: CVE-2025-1735, CVE-2025-6491, CVE-2025-1220

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here