Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Ubuntu 18.04: Critical PHP HTTP Denial of Service Issues USN-7645-1

Ubuntu Large Esm H500
Several security issues were fixed in PHP.
==========================================================================
Ubuntu Security Notice USN-7645-1
July 17, 2025

php7.0, php7.2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in PHP.

Software Description:
- php7.2: HTML-embedded scripting language interpreter
- php7.0: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP incorrectly parsed certain HTTP response
headers. An attacker could possibly use this issue to cause incorrect
MIME type parsing which could result in unexpected behavior.
(CVE-2025-1217)

It was discovered that PHP did not properly validate certain HTTP
headers. An attacker could possibly use this issue to perform an HTTP
request smuggling attack. (CVE-2025-1734)

It was discovered that PHP did not properly validate certain HTTP
headers. An attacker could possibly use this issue to prevent certain
headers from being sent which could result in a denial of service or
other unexpected behavior. (CVE-2025-1736)

It was discovered that PHP incorrectly performed URL truncation. An
attacker could possibly use this issue to specially craft a URL that
would result in unintended redirections or a denial of service.
(CVE-2025-1861)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS
  libapache2-mod-php7.2           7.2.24-0ubuntu0.18.04.17+esm8
                                  Available with Ubuntu Pro
  libphp7.2-embed                 7.2.24-0ubuntu0.18.04.17+esm8
                                  Available with Ubuntu Pro
  php7.2-cgi                      7.2.24-0ubuntu0.18.04.17+esm8
                                  Available with Ubuntu Pro
  php7.2-cli                      7.2.24-0ubuntu0.18.04.17+esm8
                                  Available with Ubuntu Pro
  php7.2-fpm                      7.2.24-0ubuntu0.18.04.17+esm8
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  libapache2-mod-php7.0           7.0.33-0ubuntu0.16.04.16+esm15
                                  Available with Ubuntu Pro
  libphp7.0-embed                 7.0.33-0ubuntu0.16.04.16+esm15
                                  Available with Ubuntu Pro
  php7.0-cgi                      7.0.33-0ubuntu0.16.04.16+esm15
                                  Available with Ubuntu Pro
  php7.0-cli                      7.0.33-0ubuntu0.16.04.16+esm15
                                  Available with Ubuntu Pro
  php7.0-fpm                      7.0.33-0ubuntu0.16.04.16+esm15
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-7645-1
  CVE-2025-1217, CVE-2025-1734, CVE-2025-1736, CVE-2025-1861

Ubuntu 18.04: Critical PHP HTTP Denial of Service Issues USN-7645-1

ubuntu
Calendar Grey July 18, 2025
Dist Ubuntu Esm H88
Major vulnerabilities in PHP patched in Ubuntu versions impacting LTS 16.04 and 18.04. Updating is advised for enhanced security.
Several security issues were fixed in PHP.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in PHP. Software Description: - php7.2: HTML-embedded scripting language interpreter - php7.0: HTML-embedded scripting language interpreter Details: It was discovered that PHP incorrectly parsed certain HTTP response headers. An attacker could possibly use this issue to cause incorrect MIME type parsing which could result in unexpected behavior. (CVE-2025-1217) It was discovered that PHP did not properly validate certain HTTP headers. An attacker could possibly use this issue to perform an HTTP request smuggling attack. (CVE-2025-1734) It was discovered that PHP did not properly validate certain HTTP headers. An attacker could possibly use this issue to prevent certain headers from being sent which could result in a denial of service or other unexpected behavior. (CVE-2025-1736) It was discovered that PHP incorrectly perfo...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libapache2-mod-php7.2 7.2.24-0ubuntu0.18.04.17+esm8 Available with Ubuntu Pro libphp7.2-embed 7.2.24-0ubuntu0.18.04.17+esm8 Available with Ubuntu Pro php7.2-cgi 7.2.24-0ubuntu0.18.04.17+esm8 Available with Ubuntu Pro php7.2-cli 7.2.24-0ubuntu0.18.04.17+esm8 Available with Ubuntu Pro php7.2-fpm 7.2.24-0ubuntu0.18.04.17+esm8 Available with Ubuntu Pro Ubuntu 16.04 LTS libapache2-mod-php7.0 7.0.33-0ubuntu0.16.04.16+esm15 Available with Ubuntu Pro libphp7.0-embed 7.0.33-0ubuntu0.16.04.16+esm15 Available with Ubuntu Pro php7.0-cgi 7.0.33-0ubuntu0.16.04.16+esm15 Available with Ubuntu Pro php7.0-cli 7.0.33-0ubuntu0.16.04.16+esm15 Available with Ubuntu Pro php7.0-fpm 7.0.33-0ubuntu0.16.04.16+esm15 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7645-1

CVE-2025-1217, CVE-2025-1734, CVE-2025-1736, CVE-2025-1861

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7645-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here