Remi's RPM repository - Packages

Blog | Support | Repository | Wizard

php-oci8 - A module for PHP applications that use OCI8 databases

Website:
http://www.php.net/
Licence:
PHP
Vendor:
Remi's RPM repository <https://rpms.remirepo.net/> #StandWithUkraine #NoAI
Description:
The php-oci8 packages provides the OCI8 extension version 3.1.0
and the PDO driver to access Oracle Database.

The extension is linked with Oracle client libraries 23.26.3
(Oracle Instant Client).  For details, see Oracle's note
"Oracle Client / Server Interoperability Support" (ID 207303.1).

You must install libclntsh.so.23.1 to use this package,
provided by Oracle Instant Client RPM available from Oracle on:
https://www.oracle.com/database/technologies/instant-client/downloads.html

Documentation is at http://php.net/oci8 and http://php.net/pdo_oci

Packages

php-oci8-8.1.34-5.module_php.8.1.el10.remi.aarch64 [78 KiB] Changelog by Remi Collet (2026-10-01):
- Fix FILTER_SANITIZE_ENCODED does not encode 0xFF
- Fix IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison
  CVE-2026-91768
- Fixed Various packet overreads in mysqlnd wire protocol
  CVE-2025-1218
- Fix TLS hostname verification falls back to CN after SAN mismatch
  CVE-2026-91769
- Fix Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN
  CVE-2026-91767
- Fix Integer overflow in phar_tar_number() allowing TAR archive entry injection
  CVE-2026-6103
- Fix Unbounded recursion in server-side cleanup_xml_node()
  CVE-2026-91765
- Fix Integer overflow to buffer overflow in SOAP HTTP parsing
  CVE-2025-14181
- Fix Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL
  CVE-2026-92842
- Fix Cross-origin credential leak in HTTP stream wrapper redirects
  CVE-2026-91766
- Fix Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header
  CVE-2026-93682
php-oci8-8.1.34-4.module_php.8.1.el10.remi.aarch64 [77 KiB] Changelog by Remi Collet (2026-07-30):
- Fix leak on double DatePeriod::__construct() call
- Fixed SQL injection via E'...' backslash breakout
  CVE-2026-17543
- Fixed GHSA-vc5h-9ppw-p5f3 Crash via recursive symlinks
  CVE-2026-7260