Remi's RPM repository - Packages

Blog | Support | Repository | Wizard

php81-php - PHP scripting language for creating dynamic web sites

Website:
http://www.php.net/
Licence:
PHP and Zend and BSD and MIT and ASL 1.0 and NCSA and Boost
Vendor:
Remi's RPM repository <https://rpms.remirepo.net/> #StandWithUkraine #NoAI
Description:
PHP is an HTML-embedded scripting language. PHP attempts to make it
easy for developers to write dynamically generated web pages. PHP also
offers built-in database integration for several commercial and
non-commercial database management systems, so writing a
database-enabled webpage with PHP is fairly simple. The most common
use of PHP coding is probably as a replacement for CGI scripts.

This package contains the module (often referred to as mod_php)
which adds support for the PHP language to system Apache HTTP Server.

Packages

php81-php-8.1.34-5.el10.remi.aarch64 [1.6 MiB] Changelog by Remi Collet (2026-10-01):
- Fix FILTER_SANITIZE_ENCODED does not encode 0xFF
- Fix IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison
  CVE-2026-91768
- Fixed Various packet overreads in mysqlnd wire protocol
  CVE-2025-1218
- Fix TLS hostname verification falls back to CN after SAN mismatch
  CVE-2026-91769
- Fix Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN
  CVE-2026-91767
- Fix Integer overflow in phar_tar_number() allowing TAR archive entry injection
  CVE-2026-6103
- Fix Unbounded recursion in server-side cleanup_xml_node()
  CVE-2026-91765
- Fix Integer overflow to buffer overflow in SOAP HTTP parsing
  CVE-2025-14181
- Fix Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL
  CVE-2026-92842
- Fix Cross-origin credential leak in HTTP stream wrapper redirects
  CVE-2026-91766
- Fix Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header
  CVE-2026-93682
php81-php-8.1.34-4.el10.remi.aarch64 [1.6 MiB] Changelog by Remi Collet (2026-07-30):
- Fix leak on double DatePeriod::__construct() call
- Fixed SQL injection via E'...' backslash breakout
  CVE-2026-17543
- Fixed GHSA-vc5h-9ppw-p5f3 Crash via recursive symlinks
  CVE-2026-7260