June 2024ZendPHP ChangesAddedAlpine 3.20 supportUbuntu 24.04 supportRemovedAlpine 3.16 supportUbuntu 18.04 supportPHP version 7.2.34.19, 7.3.33.11, 7.4.33.6, 8.0.30.2 changesFunctionality improvements for upgrading IBM iCommunity CVE FixesPHP version 8.3.8, 8.2.20, 8.1.29 CVE fixesCGIFixed bug GHSA-3qgc-jrrr-25jv: Bypass of CVE-2012-1823, Argument Injection in PHP-CGI (CVE-2024-4577)FilterFixed bug GHSA-w8qr-v226-r27w: Filter bypass in filter_var FILTER_VALIDATE_URL (CVE-2024-5458)OpenSSLThe openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https://github.com/openssl/openssl/pull/13817 (rsa_pkcs1_implicit_rejection). These changes are part of OpenSSL 3.2 and have also been backported to stable versions of various Linux distributions, as well as to the PHP builds provided for Windows since the previous release. All distributors and builders should ensure that this version is used to prevent PHP from being vulnerable. (CVE-2024-2408)StandardFixed bug GHSA-9fcc-425m-g385: Bypass of CVE-2024-1874 (CVE-2024-5585)Community FixesPHP version 8.3.8, 8.2.20 fixesCGIFixed buffer limit on Windows, replacing read call usage by _readCLIFixed bug GH-14189: PHP Interactive shell input state incorrectly handles quoted heredoc literals.CoreFixed bug GH-13970: Incorrect validation of #[Attribute] flags type for non-compile-time expressionsDOMFix crashes when entity declaration is removed while still having entity references.Fix references not handled correctly in C14NFix crash when calling childNodes next() when iterator is exhausted.Fix crash in ParentNode::append() when dealing with a fragment containing text nodesFPMFix bug GH-14175: Show decimal number instead of scientific notation in systemd statusHashext/hash: Swap the checking order of __has_builtin and __GNUC__IntlFixed build regression on systems without C++17 compilersMySQLndFix bug GH-14255: mysqli_fetch_assoc reports error from nested queryOpcacheFixed bug GH-14109: Fix accidental persisting of internal class constant in shmXMLFixed bug GH-14124: Segmentation fault with XML extension under certain memory limitXMLReaderFixed bug GH-14183: XMLReader::open() can't be overriddenPHP version 8.2.20 fixesCoreFixed bug GH-14140: Floating point bug in range operation on Apple Silicon hardwareFFIFixed bug GH-14215: Cannot use FFI::load on CRLF header file with apache2handlerIniFixed bug GH-14100: Corrected spelling mistake in php.ini filesBackported PHP CVE FixesPHP version 7.2.34.19, 7.3.33.11, 7.4.33.6, 8.0.30.2 CVE fixesCGIFixed bug GHSA-3qgc-jrrr-25jv: Bypass of CVE-2012-1823, Argument Injection in PHP-CGI (CVE-2024-4577)FilterFixed bug GHSA-w8qr-v226-r27w: Filter bypass in filter_var FILTER_VALIDATE_URL (CVE-2024-5458)PHP version 7.4.33.6, 8.0.30.2 CVE fixesStandardFixed bug GHSA-9fcc-425m-g385: Bypass of CVE-2024-1874 (CVE-2024-5585)