Home » Releases » 8.4 » 8.4.25 »

PHP 8.4.20

The latest release of PHP 8.4 is 8.4.25 which includes important security patches.

Source Code

Change Log

  • bz2

    • Fix truncation of total output size causing erroneous errors.
      ndossche
  • core

  • dom

    • Fixed bug GH-21486 (Dom\HTMLDocument parser mangles xml:space and xml:lang attributes).
      ndossche
  • ffi

    • Fixed resource leak in FFI::cdef() onsymbol resolution failure.
      David Carlier
  • gd

    • Fixed bug GH-21431 (phpinfo() to display libJPEG 10.0 support).
      David Carlier
  • opcache

    • Fixed bug GH-20838 (JIT compiler produces wrong arithmetic results).
      Dmitry
      iliaal
    • Fixed bug GH-21267 (JIT tracing: infinite loop on FETCH_OBJ_R with IS_UNDEF property in polymorphic context).
      Dmitry
      iliaal
    • Fixed bug GH-21395 (uaf in jit).
      ndossche
  • openssl

    • Fixed bug GH-21083 (Skip private_key_bits validation for EC/curve-based keys).
      iliaal
    • Fix missing error propagation for BIO_printf() calls.
      ndossche
  • pcre

    • Fixed re-entrancy issue on php_pcre_match_impl, php_pcre_replace_impl, php_pcre_split_impl, and php_pcre_grep_impl.
      David Carlier
  • pgsql

    • Fixed preprocessor silently guarding PGSQL_SUPPRESS_TIMESTAMPS support due to a typo.
      KentarouTakeda
  • snmp

    • Fixed bug GH-21336 (SNMP::setSecurity() undefined behavior with NULL arguments).
      David Carlier
  • soap

    • Fixed Set-Cookie parsing bug wrong offset while scanning attributes.
      David Carlier
  • spl

    • Fixed bug GH-21454 (missing write lock validation in SplHeap).
      ndossche
  • standard

    • Fixed bug GH-20906 (Assertion failure when messing up output buffers).
      ndossche
    • Fixed bug GH-20627 (Cannot identify some avif images with getimagesize).
      y-guyon
  • sysvshm

    • Fix memory leak in shm_get_var() when variable is corrupted.
      ndossche
  • xsl

    • Fix GH-21357 (XSLTProcessor works with DOMDocument, but fails with Dom\XMLDocument).
      ndossche
    • Fixed bug GH-21496 (UAF in dom_objects_free_storage).
      David Carlier/ndossche

PHP 8.4


  Represents a security release