forked from php/php-src
-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathNEWS
More file actions
1672 lines (1425 loc) · 69 KB
/
Copy pathNEWS
File metadata and controls
1672 lines (1425 loc) · 69 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
PHP NEWS
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
24 Sep 2026, PHP 8.5.11
- BCMath:
. Fixed out-of-bounds read in bc_is_zero_for_scale() when scale exceeds
n_scale. (Ilia Alshanetsky)
- Core:
. Fixed out-of-bounds reads during automatic UTF-16/32 encoding detection.
(Yudai Takada)
. Fixed bug GH-15375 (Nested "yield from" skips items after a valid() or
next() call on the inner generator). (iliaal)
. Fixed bug GH-23232 (lone namespace separator asks the autoloader for an
empty class name). (spawnia)
. Fixed bug GH-23301 (Nested "yield from" yields a value twice when the
middle generator delegates again). (Lazizbek Ergashev)
- DOM:
. Fixed NamedNodeMap::getNamedItemNS() with an empty URI not matching
the null namespace in spec-following mode. (Ilia Alshanetsky)
. Fixed stale getElementsByClassName() and other node list caches after
className/classList writes and attribute removals. (Ilia Alshanetsky)
. Fixed a use-after-free when cloning a DOMNameSpaceNode after
DOMDocument::xinclude(). (iliaal)
. Fixed a crash in DOMXPath when a php:function callback receives a nodeset
and a later callback returns a node from another document. (iliaal)
. Fixed bug GH-23331 (UAF when node_list_unlink() skips attribute children
that still have a live wrapper). (iliaal)
. Fixed a use-after-free when Dom\Element::setAttributeNS() replaces the
value of an attribute whose child still has a live wrapper. (iliaal)
- GD:
. Fixed imageaffinematrixget() and imageaffinematrixconcat() reporting the
wrong argument in error messages. (Weilin Du)
- FPM:
. Fixed bug GH-19320 (FPM UID and GID overflow). (Pratik Bhujel)
. Fixed GHSA-62xp-839h-2637 (IPv6 ACL bypass in FastCGI listen.allowed_clients
due to partial address comparison). (CVE-2026-91768) (Alexandre Daubois)
- Intl:
. Fixed grapheme_strpos() and grapheme_strrpos() with an empty needle
returning UTF-16 offsets instead of grapheme offsets. (Ilia Alshanetsky)
. Fixed a memory leak when dumping IntlCalendar instances. (Ilia Alshanetsky)
. Fixed a memory leak when iterating IntlBreakIterator::getPartsIterator()
results. (iliaal)
. Fixed a double-free when IntlGregorianCalendar construction fails after
the ICU constructor adopts the TimeZone. (iliaal)
. Fixed bug GH-23094 (NumberFormatter parsing offsets use UTF-16 positions
for UTF-8 strings). (ColumbusLabs)
. Fixed Locale::parseLocale() reading past a trailing '-' or '_'.
(iliaal, Xuyang Zhang)
. Fixed grapheme_str_split() treating UBRK_DONE as a byte index. (iliaal)
. Fixed a leak in Locale::getKeywords() when a keyword value cannot be
read. (iliaal)
. Fixed a use-after-free when IntlRuleBasedBreakIterator is constructed
from compiled rules. (iliaal)
- MBString:
. Fixed mb_ereg_replace() emitting a NUL or out-of-bounds bytes in the
replacement when a \k<name> backref has no closing delimiter.
(Ilia Alshanetsky)
- MySQLnd:
. Fixed GHSA-r6x9-5r99-36j7 (Various packet overreads in mysqlnd wire
protocol). (CVE-2025-1218) (Jakub Zelenka, Nora Dossche)
- ODBC:
. Fixed odbc_field_len(), odbc_field_scale() and odbc_field_type()
returning uninitialized memory when SQLColAttribute fails.
(Ilia Alshanetsky)
- Opcache:
. Fixed opcache.protect_memory race under ZTS. (realFlowControl)
. Fixed a tracing JIT crash when compiling a side trace for a method of a
class that could not be stored in the inheritance cache. (GH-21710)
(Arnaud, iliaal)
. Fixed a crash when the huge page SHM remap discarded mappings outside the
reserved address range. (Piotr Hałas)
- OpenSSL:
. Fixed GHSA-vvx9-73fr-5jjx (TLS hostname verification falls back to CN after
SAN mismatch). (CVE-2026-91769) (Jakub Zelenka)
. Fixed GHSA-xr7j-rvgx-xq5p (Heap buffer overflow in
php_openssl_matches_wildcard_name() on crafted server certificate wildcard
CN). (CVE-2026-91767) (Jakub Zelenka)
- PDO:
. Fixed a leak when a persistent connection failed a liveness check
with no other live PDO handle. (iliaal)
- PDO_PGSQL:
. Fixed PDO::CURSOR_SCROLL statements failing under lazy fetching
(PDO::ATTR_PREFETCH => 0). (KentarouTakeda)
- PDO Sqlite:
. Fixed bug GH-20214 (PDO::FETCH_DEFAULT unexpected behavior with
PDOStatement::setFetchMode). (SakiTakamachi)
- Phar:
. Fixed bug GH-23418 (Use-after-free when looking up mounted directories).
(Weilin Du)
. Fixed bug GH-23477 (Memory leak on duplicate native Phar manifest entries).
(Weilin Du)
. Fixed GHSA-j3wh-g957-2m85 (Integer overflow in phar_tar_number() allowing
TAR archive entry injection). (CVE-2026-6103) (Jakub Zelenka)
- Readline:
. Fixed the interactive shell not waiting for the pager process to exit.
(Weilin Du)
- SOAP:
. Fixed WSDL cache corruption when a soap:header defines headerfaults.
(Ilia Alshanetsky)
. Fixed stack overflow when parsing a WSDL with self-referential schema
groups or attributeGroups. (Ilia Alshanetsky)
. Fixed GHSA-rgrp-mwpx-f6rm (Unbounded recursion in server-side
cleanup_xml_node()). (CVE-2026-91765) (Alexandre Daubois)
. Fixed GHSA-cj93-vc83-wgqv (Integer overflow to buffer overflow in SOAP HTTP
parsing). (CVE-2025-14181) (Nora Dossche, Jakub Zelenka)
- Standard:
. Fixed a segfault when a stream filter callback unsets StreamBucket::$data
before re-attaching the bucket. (iliaal)
. Fixed GHSA-7875-c8px-7q5f (Out-of-bounds read in the HTTP stream wrapper
when following a redirect with an empty Location header). (CVE-2026-93682)
(Ilia Alshanetsky, Jordi Kroon)
. Fixed read buffer compaction in php_stream_filter_flush(). (crystarm)
. Fixed bug GH-22410 (Incorrect float behavior with large numbers).
(arshidkv12)
. Fixed GH-23338 (fsockopen()/pfsockopen() ValueError reported wrong
argument number for $timeout). (lacatoire)
. Fixed bug GH-23576 (Next index for array returned from array_keys() is
wrong). (Lazizbek Ergashev)
. Fixed GHSA-88hq-2827-7pg6 (Out-of-bounds read in convert.* stream filters
when line-break-chars contains NUL). (CVE-2026-92842) (geeknik)
. Fixed GHSA-fpwc-w8rq-cr92 (Cross-origin credential leak in HTTP stream
wrapper redirects). (CVE-2026-91766) (Alexandre Daubois)
- SimpleXML:
. Fixed writing to a dimension of the object returned by attributes() not
creating the attribute. (Ilia Alshanetsky)
. Fixed child elements of the element returned by
SimpleXMLElement::addChild() not being accessible by property name when
namespaces are involved. (Ilia Alshanetsky)
- Windows:
. Fixed GHSA-9f67-6fw4-hpfp (Reserved device names are not rejected before
file and stream I/O). (CVE-2026-17545) (Shivam Mathur, Jakub Zelenka)
- Zip:
. Fixed bug GH-17787 (ZipArchive stream stops reading early when the archive
is freed while the stream is still open). (Eyüp Can Akman)
. Fixed bug GH-23276 (ZipArchive subclass storing its own stream cannot be
garbage collected). (Weilin Du, ndossche)
- SAPI:
. Fixed fuzzer targets failing to build in isolation. (Mrmaxmeier)
. Fixed returns uninitialized value on LiteSpeed lsapi SAPI (Go Kudo)
27 Aug 2026, PHP 8.5.10
- Core:
. Fixed bug GH-22782 (Const expr FCC crashes under preloading). (Arnaud)
. Fixed bug GH-23088 (Stack overflow when comparing deeply nested arrays).
(Lazizbek Ergashev)
- Date:
. Fixed leak on double DatePeriod::__construct() call. (ilutov)
- DOM:
. Fixed bug GH-23116 (Stack overflow when normalizing a deeply nested
DOMDocument). (Lazizbek Ergashev)
. Fixed bug GH-23117 (Stack overflow when normalizing a deeply nested
Dom\XMLDocument). (Lazizbek Ergashev)
. Fixed bug GH-22825 (DOMElement::setAttribute() fails silently when the DTD
declares a default value for the attribute). (iliaal)
. Fixed bug GH-23120 (Stack overflow when comparing deeply nested DOM nodes
with DOMNode::isEqualNode()). (Weilin Du)
- Exif:
. Fixed exif_read_data() allocating a HEIF meta box larger than the file
it came from. (iliaal)
- Intl:
. Fixed IntlListFormatter::__construct() leaving stale global error state
after successful calls. (Weilin Du)
- Opcache:
. Fixed GH-22693 (DT_TEXTREL in JIT-generated TLS access on x86_64).
(David Carlier)
. Fixed bug GH-22763 (JIT fails to clear ZREG_TYPE_ONLY after setting reg).
(Arnaud)
. Fixed bug GH-22857 (Function JIT emits wrong code for FETCH_OBJ_FUNC_ARG on
a property hook getter, losing register-held variables). (Zhao Hao)
. Fixed bug GH-22916 (Preserve parent regs in zend_jit_deoptimizer_start()).
(Arnaud)
- OpenSSL:
. Fix missing error check on invalid alpn protocols. (ndossche)
- MBString:
. Fixed bug GH-22779 (mb_strrpos() returns the wrong position for a negative
offset in a non-UTF-8 encoding). (Eyüp Can Akman)
. Fixed bug GH-21036 (mb_ereg_search_getregs() crashes after mb_eregi()
invalidates the regex cache). (Matthias Goergens)
- PCRE:
. Fixed bug GH-21134 (Crash with \C + UTF-8). Using \C in UTF-8 patterns is
now forbidden. (Arnaud)
- PDO_ODBC:
. Fixed bug GH-23016 (NULL values in long columns come back as garbage
binary strings). (Calvin Buckley, iliaal)
- PDO_PGSQL:
. Fixed several lazy fetch (PDO::ATTR_PREFETCH => 0) defects: an infinite
loop when cleaning up a fetch left in a COPY, a use-after-free when a
statement with emulated or disabled prepares is destroyed, a connection
left busy for the next fetch, and rows delivered from a result another
statement took over. (KentarouTakeda)
- Reflection:
. Fixed bug GH-22905 (Reflection exception messages truncate on null bytes).
(DanielEScherzer)
. Fixed ReflectionProperty::isLazy() and skipLazyInitialization() using the
parent slot when a child class hooks an inherited property. (iliaal)
. Fixed segfault in ReflectionMethod::createFromMethodName() on an
uninstantiable subclass. (iliaal)
- Session:
. Fix corruption in mod_mm. (ndossche)
. Fixed bug GH-23043 (broken session id code can cause zend_mm_heap
corrupted). (ndossche)
- SimpleXML:
. Fixed integer element offsets that cannot resolve aliasing an existing
element. (iliaal)
. Fixed segfault when comparing uninitialized SimpleXMLElement
instances. (iliaal)
- Sockets:
. Fixed socket_set_option() validation error messages for UDP_SEGMENT and
SO_LINGER options. (Weilin Du)
. Fixed various memory related issues in ext/sockets. (David Carlier)
- SQLite:
. Fix leak when trying to close db if blob stream is still open. (ndossche)
- Standard:
. Fixed bug GH-23111 (Stack overflow in array_walk_recursive() with deeply
nested arrays). (Lazizbek Ergashev)
. Fixed bug GH-23113 (Stack overflow in array_replace_recursive() with deeply
nested arrays). (Lazizbek Ergashev)
. Fixed bug GH-23115 (Stack overflow in compact() with deeply nested
arrays). (Lazizbek Ergashev)
- Streams:
. Fixed bug GH-15836 (Use-after-free when a user stream filter accesses
$this->stream during the close flush). (iliaal)
- XSL:
. Fixed use-after-free when a DOMDocument subclass __clone() retains the
stylesheet copy made by XSLTProcessor::importStylesheet(). (iliaal)
30 Jul 2026, PHP 8.5.9
- Core:
. Fixed bug GH-22290 (AST pretty printing does not correctly handle strings
containing NUL). (iliaal)
. Fixed bug GH-22206 (missing return in global register detection).
(P3p111n0)
. Lock unmodified readonly properties for modification after clone-with.
(NickSdot)
- BCMath:
. Fixed GHSA-x692-q9x7-8c3f (Out-of-bounds write in bccomp()).
(CVE-2026-17544) (Recep Asan)
- Calendar:
. Fixed bug GH-22602 (gregoriantojd() and juliantojd() integer overflow with
INT_MAX year). (arshidkv12)
- Date:
. Update timelib to 2022.17. (Derick)
. Fixed bug GH-19803 (Parsing a string with a single white space does create
an error). (Derick)
. Fixed Unix timestamps in February of the year 0 are misparsed with
@-notation. (LukasGelbmann)
. Fixed bug GH-11310 (__debugInfo does nothing on userland classes extending
Date classes). (Derick)
- DBA:
. Fixed OOB read on malformed length field in dba flatfile handler. (alhudz)
- DOM:
. Fixed bug GH-22570 (Stack overflow when serializing a deeply nested
Dom\XMLDocument). (iliaal)
. Fixed getElementsByClassName() item() returning the wrong element on
random access. (David Carlier)
- Exif:
. Fixed bug GH-11020 (exif_read_data() emits a spurious "Illegal IFD size"
warning when an IFD is not followed by a next-IFD offset). (Eyüp Can Akman)
- GD:
. Upgrade libgd. (CVE-2026-9672) (Pierre Joye)
- Hash:
. Fixed bug GH-18173 (ext/hash relies on implementation-defined malloc
alignment). (iliaal)
- ODBC:
. Fixed bug GH-22668 (Heap buffer over-read when a column value exceeds the
driver-reported display size). (iliaal)
- Opcache:
. Fixed bug GH-22158 (Tracing JIT dispatches the observer begin handler
through the wrong run_time_cache slot on megamorphic calls). (ptondereau,
iliaal)
. Fixed bug GH-22443 (Tracing JIT SIGSEGV on megamorphic dynamic calls from
an undereferenced run_time_cache map_ptr offset). (iliaal)
. Fixed bug GH-21770 (Infinite recursion in property hook getter in opcache
preloaded trait). (iliaal)
- OpenSSL:
. Fixed timeout for supplemental read at end of a blocking stream in SSL
stream wrapper. (ilutov)
- Intl:
. Fixed Locale::lookup() and locale_lookup() to return NULL instead of the
fallback locale when a language tag cannot be canonicalized. (Weilin Du)
. Fixed memory leaks when calling Collator::__construct() or
Spoofchecker::__construct() twice. (Weilin Du)
. Fixed memory leak when calling IntlListFormatter::__construct() twice.
(Weilin Du)
. Fixed IntlChar methods leaving stale global error state after successful
calls. (Xuyang Zhang)
- PDO_ODBC:
. Fixed bug GH-20726 (Crash with ODBC connection pooling when the DSN
carries no credentials). (iliaal)
. Fixed bug GH-22667 (Heap buffer over-read when a column value exceeds the
driver-reported display size). (iliaal)
. Fixed bug GH-22666 (Heap buffer overflow when an output parameter value is
longer than the declared maxlen). (iliaal)
. Fixed bug GH-22665 (Out-of-bounds write when the ODBC driver reports a
diagnostic message length beyond the error buffer). (iliaal)
- PGSQL:
. Fixed GHSA-7qpv-r5mr-78m4 (SQL injection via E'...' backslash breakout).
(CVE-2026-17543) (ilutov)
- Phar:
. Fixed inconsistent handling of the magic ".phar" directory. Paths such as
"/.phar" remain protected, while non-magic paths that merely start with
".phar" are handled consistently across file and directory creation,
copying, ArrayAccess, stream lookup, directory iteration and extraction.
(Weilin Du)
. Fixed GHSA-vc5h-9ppw-p5f3 (Crash via recursive symlinks). (CVE-2026-7260)
(Jakub Zelenka)
- PHPDBG:
. Fixed bug GH-17387 (Trivial crash in phpdbg lexer). (iliaal)
. Fixed fleaked lowercased lookup keys in phpdbg_resolve_opline_break.
(jorgsowa)
. Fixed off-by-one in phpdbg_safe_class_lookup() causing class lookups to
always fail during phpdbg's signal-safe interruption path. (jorgsowa)
- Reflection:
. Fixed bug GH-22324 (Ignore leading namespace separator in
ReflectionParameter::__construct()). (jorgsowa)
. Fixed bug GH-22441 (ReflectionClass::hasProperty() and getProperty() ignore
dynamic properties shadowing a private parent property). (iliaal)
. Fixed bug GH-22658 (ReflectionConstant::__toString() with a string value
with null bytes truncates output). (DanielEScherzer)
. Fixed bug GH-22683 (Reflection(Class)Constant::__toString() should not warn
on NAN conversions). (Khaled Alam)
. Fixed bug GH-22681 (Reflection*::__toString() truncates on null bytes).
(DanielEScherzer)
- Session:
. Fixed bug GH-21314 (Different session garbage collector behavior between
PHP 8.3 and PHP 8.5). (jorgsowa)
- SPL:
. Fix class_parents for classes with leading slash in non-autoload mode.
(jorgsowa)
. Ignore leading back-slash in class_parents(), class_implements(), and
class_uses(). (jorgsowa)
. Fixed bug GH-16217 (SplFileObject::fputcsv() on an uninitialized object
segfaults). (iliaal)
- Standard:
. Fixed bug GH-22395 (base_convert() outputs at most 64 characters).
(Weilin Du)
. Fixed bug GH-22678 (Use-after-free in array_multisort() when the comparator
mutates the array being sorted). (azchin, iliaal)
- URI:
. Fixed behavior of Uri\WhatWg\Url wither methods with regards to empty
opaque hosts. (kocsismate)
. Fixed bug GH-22628 (Percent-encoding of caret in WHATWG URL paths is not
performed). (kocsismate)
. Fixed bug GH-22629 (WHATWG Validation error incorrect with empty host and
non-empty userinfo). (kocsismate)
- Zip:
. Fixed bug GH-22649 (ZipArchive::setCommentName() and setCommentIndex()
could crash after overwriting an entry and resetting its inherited
unchanged comment). (Weilin Du)
. Fixed bug GH-21705 (ZipArchive::getFromIndex() ignores
ZipArchive::FL_UNCHANGED for deleted entries). (Weilin Du)
02 Jul 2026, PHP 8.5.8
- Core:
. Fixed bug GH-22280 (Incorrect compile error for goto to label preceding
try/finally block). (Pratik Bhujel)
. Fixed bug GH-22112 (Assertion when error handler throws during NaN to
bool/string coercion). (iliaal)
- BCMath:
. Fixed issues with oversized allocations and signed overflow in bcround()
and BcMath\Number::round(). (edorian)
- Date:
. Fix incorrect recurrence check of DatePeriod::createFromISO8601String().
(ndossche)
- Exif:
. Read correct value for single and double tags. (ndossche)
- GD:
. Fixed bug GH-22121 (Double free in gdImageSetStyle() after
overflow-triggered early return). (iliaal)
- Intl:
. Fix incorrect argument positions for invalid start/end arguments in
transliterator_transliterate().
(Weilin Du)
. Fixed IntlTimeZone::getDisplayName() to synchronize object error state
for invalid display types. (Weilin Du)
- Lexbor:
. Merge patch c3a6847. (ilutov, timwolla)
- Opcache:
. Fixed bug GH-22265 (Another tailcall vm_interrupt bug). (Levi Morrison)
. Fixed bug GH-20469 (Unsafe inheritance cache replay with reentrant
autoloading). (Levi Morrison)
. Fixed bug GH-21972 (Corrupted variable type when a typed by-value return
contains a reference wrapper). (Weilin Du)
- OpenSSL:
. Fixed bug GH-22187 (Memory corruption (zend_mm_heap corrupted) in
openssl_encrypt with AES-WRAP-PAD). (CVE-2026-14355) (David Carlier)
- Phar:
. Fixed a bypass of the magic ".phar" directory protection in
Phar::addEmptyDir() for paths starting with "/.phar", while allowing
non-magic directory names that merely share the ".phar" prefix. (Weilin Du)
. Fixed an integer underflow when parsing ZIP extra fields. (Weilin Du)
- Reflection:
. Preserve class-name case in ReflectionClass::getProperty() error messages
and autoloading. (jorgsowa)
- SOAP:
. Fixed bug GH-22218 (SoapServer::handle() crash on $_SERVER not being
an array). (David Carlier / Rex-Reynolds)
. Fixed bug GH-22285 (Soap server requires the raw input to be passed
to $server->handle). (David Carlier / ndossche)
- Sqlite:
. Fix error checks for column retrieval. (ndossche)
- URI:
. Add LEXBOR_STATIC to CFLAGS_URI on Windows so ext/uri does not see
LXB_API as __declspec(dllimport) when linked statically into PHP.
(Luther Monson)
. Clean error logs before each Uri\WhatWg\Url wither call so that errors from
previous wither calls are not returned the next time a UrlValidationError
is thrown. (kocsismate)
- Zip:
. Fixed error-related memory leaks. (ndossche)
- Zlib:
. Fixed memory leak if deflate initialization fails and there is a dict.
(ndossche)
. Fixed memory leak in inflate_add(). (ndossche)
02 Jun 2026, PHP 8.5.7
- CLI:
. Fixed bug GH-21901 (Stale getopt() optional value). (onthebed)
- Core:
. Fixed bug GH-22071 (JIT assertion on abstract static method call).
(David Carlier)
- Date:
. Fixed bug GH-18422 (int overflow in php_date_llabs). (iliaal)
- DOM:
. Fixed bug GH-22077 (UAF in custom XPath function).
(afflerbach/David Carlier)
- Opcache:
. Fixed tracing JIT crash when a VM interrupt is handled during an observed
user function call. (Levi Morrison)
. Fixed bug GH-21746 (Segfault with tracing JIT). (Arnaud)
. Fixed bug GH-22004 (Assertion failure at ext/opcache/jit/zend_jit_trace.c).
(Arnaud)
. Fixed tailcall VM crash when a VM interrupt is handled from a VM helper.
(Levi Morrison, Arnaud)
- OpenSSL:
. Fix compatibility issues with OpenSSL 4.0. (jordikroon, Remi)
- Standard:
. Fixed bug GH-21689 (version_compare() incorrectly handles versions ending
with a dot). (timwolla)
- URI:
. Fixed CVE-2026-44927 (In uriparser before 1.0.2, there is pointer
difference truncation to int in various places). (CVE-2026-44927)
(Sebastian Pipping)
. Fixed CVE-2026-44928 (In uriparser before 1.0.2, the function family
EqualsUri can misclassify two unequal URIs as equal). (CVE-2026-44928)
(Sebastian Pipping)
07 May 2026, PHP 8.5.6
- Core:
. Fixed bug GH-19983 (GC assertion failure with fibers, generators and
destructors). (iliaal)
. Fixed ZEND_API mismatch on zend_ce_closure forward decl for Windows+Clang.
(henderkes)
. Fixed bug GH-21504 (Incorrect RC-handling for ZEND_EXT_STMT op1). (ilutov)
. Fixed bug GH-21478 (Forward property operations to real instance for
initialized lazy proxies). (iliaal)
. Fixed bug GH-21605 (Missing addref for Countable::count()). (ilutov)
. Fixed bug GH-21699 (Assertion failure in shutdown_executor when resolving
self::/parent::/static:: callables if the error handler throws). (macoaure)
. Fixed bug GH-21603 (Missing addref for __unset). (ilutov)
. Fixed bug GH-21760 (Trait with class constant name conflict against
enum case causes SEGV). (Pratik Bhujel)
- CLI:
. Fixed bug GH-21754 (`--rf` command line option with a method triggers
ext/reflection deprecation warnings). (DanielEScherzer)
- Curl:
. Add support for brotli and zstd on Windows. (Shivam Mathur)
- DOM:
. Fixed GHSA-4jhr-8w89-j733 and GH-21566 (Dom\XMLDocument::C14N() emits
duplicate xmlns declarations after setAttributeNS()). (CVE-2026-7263)
(David Carlier)
- FPM:
. Fixed GHSA-7qg2-v9fj-4mwv (XSS within status endpoint). (CVE-2026-6735)
(Jakub Zelenka)
- Iconv:
. Fixed bug GH-17399 (iconv memory leak on bailout). (iliaal)
- Lexbor:
. Upgrade to lexbor v2.7.0. (CVE-2026-29078, CVE-2026-29079)
(ndossche, ilutov)
- MBString:
. Fixed GHSA-wm6j-2649-pv75 (Null pointer dereference in
php_mb_check_encoding() via mb_ereg_search_init()). (CVE-2026-7259)
(vi3tL0u1s)
. Fixed GHSA-74r9-qxhc-fx53 (Out-of-bounds access in mbfl_name2encoding_ex()).
(CVE-2026-6104) (ilutov)
- Opcache:
. Fixed bug GH-21158 (JIT: Assertion jit->ra[var].flags & (1<<0) failed in
zend_jit_use_reg). (Arnaud)
. Fixed bug GH-21593 (Borked function JIT JMPNZ smart branch). (ilutov)
. Fixed bug GH-21460 (COND optimization regression). (Dmitry, Arnaud)
. Fixed faulty returns out of zend_try block in zend_jit_trace(). (ilutov)
- OpenSSL:
. Fix memory leak regression in openssl_pbkdf2(). (ndossche)
. Fix a bunch of memory leaks and crashes on edge cases. (ndossche)
- PDO_Firebird:
. Fixed GHSA-w476-322c-wpvm (SQL injection via NUL bytes in quoted strings).
(CVE-2025-14179) (SakiTakamachi)
- PDO_PGSQL:
. Fixed bug GH-21683 (pdo_pgsql throws with ATTR_PREFETCH=0
on empty result set). (thomasschiet)
- Phar:
. Restore is_link handler in phar_intercept_functions_shutdown. (iliaal)
. Fixed bug GH-21797 (phar: NULL dereference in Phar::webPhar() when
SCRIPT_NAME is absent from SAPI environment). (iliaal)
. Fix memory leak in Phar::offsetGet(). (iliaal)
. Fix memory leak in phar_add_file(). (iliaal)
. Fixed bug GH-21799 (phar: propagate phar_stream_flush return value from
phar_stream_close). (iliaal)
. Fix memory leak in phar_verify_signature() when md_ctx is invalid.
(JarneClauw)
- Random:
. Fixed bug GH-21731 (Random\Engine\Xoshiro256StarStar::__unserialize()
accepts all-zero state). (iliaal)
- Session:
. Fixed memory leak when session GC callback return a refcounted value.
(jorgsowa)
- SOAP:
. Fixed GHSA-85c2-q967-79q5 (Stale SOAP_GLOBAL(ref_map) pointer with Apache
Map). (CVE-2026-6722) (ilutov)
. Fixed GHSA-m33r-qmcv-p97q (Use-after-free after header parsing failure with
SOAP_PERSISTENCE_SESSION). (CVE-2026-7261) (ilutov)
. Fixed GHSA-hmxp-6pc4-f3vv (Broken Apache map value NULL check).
(CVE-2026-7262) (ilutov)
- SPL:
. Fixed bug GH-21499 (RecursiveArrayIterator getChildren UAF after parent
free). (Girgias)
. Fix concurrent iteration and deletion issues in SplObjectStorage.
(ndossche)
- Sqlite3:
. Fixed wrong free list comparator pointer type. (David Carlier)
- Standard:
. Fixed GHSA-96wq-48vp-hh57 (Signed integer overflow of char array offset).
(CVE-2026-7568) (TimWolla)
. Fixed GHSA-m8rr-4c36-8gq4 (Consistently pass unsigned char to ctype.h
functions). (CVE-2026-7258) (ilutov)
- Streams:
. Fixed bug GH-21468 (Segfault in file_get_contents w/ a https URL
and a proxy set). (CVE-2026-12184) (ndossche)
- URI:
. Fixed CVE-2026-42371 (uriparser before 1.0.1 has numeric truncation in
text range comparison). (CVE-2026-42371) (Joshua W. Windle)
26 Mar 2026, PHP 8.5.5
- Core:
. Fixed bug GH-20672 (Incorrect property_info sizing for locally shadowed
trait properties). (ilutov)
. Fixed bugs GH-20875, GH-20873, GH-20854 (Propagate IN_GET guard in
get_property_ptr_ptr for lazy proxies). (iliaal)
- Bz2:
. Fix truncation of total output size causing erroneous errors. (ndossche)
- DOM:
. Fixed bug GH-21486 (Dom\HTMLDocument parser mangles xml:space and
xml:lang attributes). (ndossche)
- FFI:
. Fixed resource leak in FFI::cdef() onsymbol resolution failure.
(David Carlier)
- GD:
. Fixed bug GH-21431 (phpinfo() to display libJPEG 10.0 support).
(David Carlier)
- Opcache:
. Fixed bug GH-21052 (Preloaded constant erroneously propagated to file-cached
script). (ilutov)
. Fixed bug GH-20838 (JIT compiler produces wrong arithmetic results).
(Dmitry, iliaal)
. Fixed bug GH-21267 (JIT tracing: infinite loop on FETCH_OBJ_R with
IS_UNDEF property in polymorphic context). (Dmitry, iliaal)
. Fixed bug GH-21395 (uaf in jit). (ndossche)
- OpenSSL:
. Fixed bug GH-21083 (Skip private_key_bits validation for EC/curve-based
keys). (iliaal)
. Fix missing error propagation for BIO_printf() calls. (ndossche)
- PCNTL:
. Fixed signal handler installation on AIX by bumping the storage size of the
num_signals global. (Calvin Buckley)
- PCRE:
. Fixed re-entrancy issue on php_pcre_match_impl, php_pcre_replace_impl,
php_pcre_split_impl, and php_pcre_grep_impl. (David Carlier)
- Phar:
. Fixed bug GH-21333 (use after free when unlinking entries during iteration
of a compressed phar). (David Carlier)
- SNMP:
. Fixed bug GH-21336 (SNMP::setSecurity() undefined behavior with
NULL arguments). (David Carlier)
- SOAP:
. Fixed Set-Cookie parsing bug wrong offset while scanning attributes.
(David Carlier)
- SPL:
. Fixed bug GH-21454 (missing write lock validation in SplHeap).
(ndossche)
- Standard:
. Fixed bug GH-20906 (Assertion failure when messing up output buffers).
(ndossche)
. Fixed bug GH-20627 (Cannot identify some avif images with getimagesize).
(y-guyon)
. Fixed bug GH-22171 (Invalid auth header generation in
http(s) stream wrapper). (David Carlier)
- Sysvshm:
. Fix memory leak in shm_get_var() when variable is corrupted. (ndossche)
- XSL:
. Fix GH-21357 (XSLTProcessor works with DOMDocument, but fails with
Dom\XMLDocument). (ndossche)
. Fixed bug GH-21496 (UAF in dom_objects_free_storage).
(David Carlier/ndossche)
12 Mar 2026, PHP 8.5.4
- Core:
. Fixed bug GH-21029 (zend_mm_heap corrupted on Aarch64, LTO builds). (Arnaud)
. Fixed bug GH-21059 (Segfault when preloading constant AST closure). (ilutov)
. Fixed bug GH-21072 (Crash on (unset) cast in constant expression).
(arshidkv12)
. Fix deprecation now showing when accessing null key of an array with JIT.
(alexandre-daubois)
. Fixed bug GH-20657 (Assertion failure in zend_lazy_object_get_info triggered
by setRawValueWithoutLazyInitialization() and newLazyGhost()). (Arnaud)
. Fixed bug GH-20504 (Assertion failure in zend_get_property_guard when
accessing properties on Reflection LazyProxy via isset()). (Arnaud)
. Fixed OSS-Fuzz #478009707 (Borked assign-op/inc/dec on untyped hooked
property backing value). (ilutov)
. Fixed bug GH-21215 (Build fails with -std=). (Arnaud)
. Fixed bug GH-13674 (Build system installs libtool wrappers when using
slibtool). (Michael Orlitzky)
- Curl:
. Don't truncate length. (ndossche)
- Date:
. Fixed bug GH-20936 (DatePeriod::__set_state() cannot handle null start).
(ndossche)
. Fix timezone offset with seconds losing precision. (ndossche)
- DOM:
. Fixed bug GH-21077 (Accessing Dom\Node::baseURI can throw TypeError).
(ndossche)
. Fixed bug GH-21097 (Accessing Dom\Node properties can can throw TypeError).
(ndossche)
- LDAP:
. Fixed bug GH-21262 (ldap_modify() too strict controls argument validation
makes it impossible to unset attribute). (David Carlier)
- MBString:
. Fixed bug GH-21223; mb_guess_encoding no longer crashes when passed huge
list of candidate encodings (with 200,000+ entries). (Jordi Kroon)
- Opcache:
. Fixed bug GH-20718 ("Insufficient shared memory" when using JIT on Solaris).
(Petr Sumbera)
. Fixed bug GH-21227 (Borked SCCP of array containing partial object).
(ilutov)
- OpenSSL:
. Fix a bunch of leaks and error propagation. (ndossche)
- Windows:
. Fixed compilation with clang (missing intrin.h include). (Kévin Dunglas)
29 Jan 2026, PHP 8.5.3
- Core:
. Fixed bug GH-20806 (preserve_none feature compatiblity with LTO).
(henderkes)
. Fixed bug GH-20767 (build failure with musttail/preserve_none feature
on macOs). (David Carlier)
. Fixed bug GH-20837 (NULL dereference when calling ob_start() in shutdown
function triggered by bailout in php_output_lock_error()). (timwolla)
. Fix OSS-Fuzz #471533782 (Infinite loop in GC destructor fiber). (ilutov)
. Fix OSS-Fuzz #472563272 (Borked block_pass JMP[N]Z optimization). (ilutov)
. Fixed bug GH-20914 (Internal enums can be cloned and compared). (Arnaud)
. Fix OSS-Fuzz #474613951 (Leaked parent property default value). (ilutov)
. Fixed bug GH-20895 (ReflectionProperty does not return the PHPDoc of a
property if it contains an attribute with a Closure). (timwolla)
. Fixed bug GH-20766 (Use-after-free in FE_FREE with GC interaction). (Bob)
. Fix OSS-Fuzz #471486164 (Broken by-ref assignment to uninitialized hooked
backing value). (ilutov)
. Fix OSS-Fuzz #438780145 (Nested finally with repeated return type check may
uaf). (ilutov)
. Fixed bug GH-20905 (Lazy proxy bailing __clone assertion). (ilutov)
. Fixed bug GH-20479 (Hooked object properties overflow). (ndossche)
- Date:
. Update timelib to 2022.16. (Derick)
- DOM:
. Fixed GH-21041 (Dom\HTMLDocument corrupts closing tags within scripts).
(lexborisov)
- MbString:
. Fixed bug GH-20833 (mb_str_pad() divide by zero if padding string is
invalid in the encoding). (ndossche)
. Fixed bug GH-20836 (Stack overflow in mb_convert_variables with
recursive array references). (alexandre-daubois)
- Opcache:
. Fixed bug GH-20818 (Segfault in Tracing JIT with object reference).
(khasinski)
- OpenSSL:
. Fix memory leaks when sk_X509_new_null() fails. (ndossche)
. Fix crash when in openssl_x509_parse() when i2s_ASN1_INTEGER() fails.
(ndossche)
. Fix crash in openssl_x509_parse() when X509_NAME_oneline() fails.
(ndossche)
- Phar:
. Fixed bug GH-20882 (buildFromIterator breaks with missing base directory).
(ndossche)
- PGSQL:
. Fixed INSERT/UPDATE queries building with PQescapeIdentifier() and possible
UB. (David Carlier)
- Readline:
. Fixed bug GH-18139 (Memory leak when overriding some settings
via readline_info()). (ndossche)
- SPL:
. Fixed bug GH-20856 (heap-use-after-free in SplDoublyLinkedList iterator
when modifying during iteration). (ndossche)
- Standard:
. Fixed bug #74357 (lchown fails to change ownership of symlink with ZTS)
(Jakub Zelenka)
. Fixed bug GH-20843 (var_dump() crash with nested objects)
(David Carlier)
15 Jan 2026, PHP 8.5.2
- Core:
. Fix OSS-Fuzz #465488618 (Wrong assumptions when dumping function signature
with dynamic class const lookup default argument). (ilutov)
. Fixed bug GH-20695 (Assertion failure in normalize_value() when parsing
malformed INI input via parse_ini_string()). (ndossche)
. Fixed bug GH-20714 (Uncatchable exception thrown in generator). (ilutov)
. Fixed bug GH-20352 (UAF in php_output_handler_free via re-entrant
ob_start() during error deactivation). (ndossche)
. Fixed bug GH-20745 ("Casting out of range floats to int" applies to
strings). (Bob)
- DOM:
. Fixed bug GH-20722 (Null pointer dereference in DOM namespace node cloning
via clone on malformed objects). (ndossche)
. Fixed bug GH-20444 (Dom\XMLDocument::C14N() seems broken compared
to DOMDocument::C14N()). (ndossche)
- EXIF:
. Fixed bug GH-20631 (Integer underflow in exif HEIF parsing
when pos.size < 2). (Oblivionsage)
- Intl:
. Fixed IntlListFormatter::getErrorCode() and getErrorMessage() not
reflecting format() failures. (Weilin Du)
. Fix leak in umsg_format_helper(). (ndossche)
- LDAP:
. Fix memory leak in ldap_set_options(). (ndossche)
- Lexbor:
. Fixed bug GH-20668 (\Uri\WhatWg\Url::withHost() crashes (SEGV) for URLs
using the file: scheme). (lexborisov)
- Mbstring:
. Fixed bug GH-20674 (mb_decode_mimeheader does not handle separator).
(Yuya Hamada)
- OpenSSL:
. Fixed bug GH-20802 (undefined behavior with invalid SNI_server_certs
options). (David Carlier)
- PCNTL:
. Fixed bug with pcntl_getcpuaffinity() on solaris regarding invalid
process ids handling. (David Carlier)
- Phar:
. Fixed bug GH-20732 (Phar::LoadPhar undefined behavior when reading fails).
(ndossche)
. Fix SplFileInfo::openFile() in write mode. (ndossche)
. Fix build on legacy OpenSSL 1.1.0 systems. (Giovanni Giacobbi)
. Fixed bug #74154 (Phar extractTo creates empty files). (ndossche)
- Session:
. Fix support for MM module. (Michael Orlitzky)
- Sqlite3:
. Fixed bug GH-20699 (SQLite3Result fetchArray return array|false,
null returned). (ndossche, plusminmax)
- Standard:
. Fix error check for proc_open() command. (ndossche)
. Fix memory leak in mail() when header key is numeric. (Girgias)
. Fixed bug GH-20582 (Heap Buffer Overflow in iptcembed). (ndossche)
- URI:
. Fixed bug GH-20771 (Assertion failure when getUnicodeHost() returns
empty string). (ndossche)
- Zlib:
. Fix OOB gzseek() causing assertion failure. (ndossche)
18 Dec 2025, PHP 8.5.1
- Core:
. Sync all boost.context files with release 1.86.0. (mvorisek)
. Fixed bug GH-20435 (SensitiveParameter doesn't work for named argument
passing to variadic parameter). (ndossche)
. Fixed bug GH-20546 (preserve_none attribute configure check on macOs
issue). (David Carlier/cho-m)
. Fixed bug GH-20286 (use-after-destroy during userland stream_close()).
(ndossche, David Carlier)
- Bz2:
. Fix assertion failures resulting in crashes with stream filter
object parameters. (ndossche)
- DOM:
. Fix memory leak when edge case is hit when registering xpath callback.
(ndossche)
. Fixed bug GH-20395 (querySelector and querySelectorAll requires elements
in $selectors to be lowercase). (ndossche)
. Fix missing NUL byte check on C14NFile(). (ndossche)
- Fibers:
. Fixed bug GH-20483 (ASAN stack overflow with fiber.stack_size INI
small value). (David Carlier)
- Intl:
. Fixed bug GH-20426 (Spoofchecker::setRestrictionLevel() error message
suggests missing constants). (DanielEScherzer)
- Lexbor:
. Fixed bug GH-20501 (\Uri\WhatWg\Url lose host after calling
withPath() or withQuery()). (lexborisov)
. Fixed bug GH-20502 (\Uri\WhatWg\Url crashes (SEGV) when parsing
malformed URL due to Lexbor memory corruption). (lexborisov)
- LibXML:
. Fix some deprecations on newer libxml versions regarding input
buffer/parser handling. (ndossche)
- mysqli:
. Make mysqli_begin_transaction() report errors properly. (Kamil Tekiela)
- MySQLnd:
. Fixed bug GH-20528 (Regression breaks mysql connexion using an IPv6 address
enclosed in square brackets). (Remi)
- Opcache:
. Fixed bug GH-20329 (opcache.file_cache broken with full interned string
buffer). (Arnaud)
- PDO:
. Fixed bug GH-20553 (PDO::FETCH_CLASSTYPE ignores $constructorArgs in
PHP 8.5.0). (Girgias)
. Fixed GHSA-8xr5-qppj-gvwj (PDO quoting result null deref). (CVE-2025-14180)
(Jakub Zelenka)
- Phar:
. Fixed bug GH-20442 (Phar does not respect case-insensitiveness of
__halt_compiler() when reading stub). (ndossche, TimWolla)
. Fix broken return value of fflush() for phar file entries. (ndossche)
. Fix assertion failure when fseeking a phar file out of bounds. (ndossche)
- PHPDBG:
. Fixed ZPP type violation in phpdbg_get_executable() and phpdbg_end_oplog().
(Girgias)
- SPL:
. Fixed bug GH-20614 (SplFixedArray incorrectly handles references
in deserialization). (ndossche)
- Standard:
. Fix memory leak in array_diff() with custom type checks. (ndossche)
. Fixed bug GH-20583 (Stack overflow in http_build_query
via deep structures). (ndossche)
. Fixed GHSA-www2-q4fc-65wf (Null byte termination in dns_get_record()).
(ndossche)