Skip to content

[pull] master from php:master#570

Merged
pull[bot] merged 11 commits intoturkdevops:masterfrom
php:master
Dec 4, 2025
Merged

[pull] master from php:master#570
pull[bot] merged 11 commits intoturkdevops:masterfrom
php:master

Conversation

@pull
Copy link
Copy Markdown

@pull pull bot commented Dec 4, 2025

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

devnexen and others added 11 commits December 3, 2025 20:22
the timeout needed to be unsigned.

close GH-20634
* PHP-8.3:
  Fix GH-20603 issue on windows 32 bits.
* PHP-8.4:
  Fix GH-20603 issue on windows 32 bits.
* PHP-8.5:
  Fix GH-20603 issue on windows 32 bits.
* PHP-8.2:
  xml: Fix deprecation properly by backporting the modern-but-actually-old implementation
* PHP-8.3:
  xml: Fix deprecation properly by backporting the modern-but-actually-old implementation
* PHP-8.4:
  xml: Fix deprecation properly by backporting the modern-but-actually-old implementation
* PHP-8.5:
  xml: Fix deprecation properly by backporting the modern-but-actually-old implementation
When pos.size is less than 2, the subtraction pos.size - 2 causes
an unsigned integer underflow, resulting in a ~4GB allocation attempt.

Add minimum size check (pos.size >= 2) to prevent the underflow.

Closes GH-20630.
* PHP-8.5:
  Fix GH-20631: Integer underflow in exif HEIF parsing
@pull pull bot locked and limited conversation to collaborators Dec 4, 2025
@pull pull bot added the ⤵️ pull label Dec 4, 2025
@pull pull bot merged commit 114260b into turkdevops:master Dec 4, 2025
1 of 2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants