Synopsis
| Issued | 2026-08-07 |
| Severity | Critical |
| Updated Packages | kusanagi-php85 |
| Affected Products | Business Edition, KUSANAGI 9, Security Edition |
Description
An update for kusanagi-php85 is now available.
Security fix(es):
- Fixed GHSA-x692-q9x7-8c3f (Out-of-bounds write in bccomp()). (CVE-2026-17544)
- Upgrade libgd. (CVE-2026-9672)
- Fixed GHSA-7qpv-r5mr-78m4 (SQL injection via E'...' backslash breakout). (CVE-2026-17543)
- Fixed GHSA-vc5h-9ppw-p5f3 (Crash via recursive symlinks). (CVE-2026-7260)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE information may not yet be available on those websites.