Release Info

Advisory: CLSA-2026:1769025762

OS: Debian 13

Public date: 2026-01-21 20:02:44.948189

Project: php

Version: 5.5.38-149

Errata link: https://errata.tuxcare.com/els_alt_php/debian13/CLSA-2026-1769025762.html

Changelog

* Security fixes - CVE-2021-21703: fix error in php fpm shared memory organization leading to privilage escalation - CVE-2021-21707: fix handling of paths with percent encoded NULL byte - CVE-2022-31625: Fix freeing of uninitialized memory leading to RCE - CVE-2022-31626: Fix buffer overflow in mysqlnd driver leading to RCE

Update

Update command: apt-get update apt-get --only-upgrade install alt-php*

Packages list

alt-php55_5.5.38-149_amd64.deb alt-php55-bcmath_5.5.38-149_amd64.deb alt-php55-cli_5.5.38-149_amd64.deb alt-php55-common_5.5.38-149_amd64.deb alt-php55-dba_5.5.38-149_amd64.deb alt-php55-dbx_5.5.38-149_amd64.deb alt-php55-dev_5.5.38-149_amd64.deb alt-php55-enchant_5.5.38-149_amd64.deb alt-php55-firebird_5.5.38-149_amd64.deb alt-php55-fpm_5.5.38-149_amd64.deb alt-php55-gd_5.5.38-149_amd64.deb alt-php55-imap_5.5.38-149_amd64.deb alt-php55-intl_5.5.38-149_amd64.deb alt-php55-ldap_5.5.38-149_amd64.deb alt-php55-mbstring_5.5.38-149_amd64.deb alt-php55-mcrypt_5.5.38-149_amd64.deb alt-php55-mssql_5.5.38-149_amd64.deb alt-php55-mysqlnd_5.5.38-149_amd64.deb alt-php55-odbc_5.5.38-149_amd64.deb alt-php55-pdo_5.5.38-149_amd64.deb alt-php55-pgsql_5.5.38-149_amd64.deb alt-php55-process_5.5.38-149_amd64.deb alt-php55-pspell_5.5.38-149_amd64.deb alt-php55-recode_5.5.38-149_amd64.deb alt-php55-snmp_5.5.38-149_amd64.deb alt-php55-soap_5.5.38-149_amd64.deb alt-php55-sybase_5.5.38-149_amd64.deb alt-php55-tidy_5.5.38-149_amd64.deb alt-php55-xml_5.5.38-149_amd64.deb alt-php55-xmlrpc_5.5.38-149_amd64.deb

CVEs

CVE-2022-31626
CVE-2021-21703
CVE-2022-31625
CVE-2021-21707