Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Package Request] - Update PHP8.3 => 8.3.15 #887

Open
adnweedon opened this issue Jan 16, 2025 · 1 comment
Open

[Package Request] - Update PHP8.3 => 8.3.15 #887

adnweedon opened this issue Jan 16, 2025 · 1 comment
Labels
bug Something isn't working fixed-upstream Bug fix is present in an upstream tree/release packages Package request

Comments

@adnweedon
Copy link

What package is missing from Amazon Linux 2023? Please describe and include package name.
Please can PHP 8.3 be upgraded from 8.3.10 to 8.3.15, so we can benefit from 6 months worth of bug fixes and security patches.

Is this an update to existing package or new package request?
Update

Is this package available in Amazon Linux 2? If it is available via external sources such as EPEL, please specify.
I have no idea - I can't find a package list like I can for AL2023, sorry!

Any additional information you'd like to include. (use-cases, etc)
This brings in fixes for some CVEs, including two that have CVSS of 9.8:

@stewartsmith
Copy link
Member

For completeness, Amazon Linux 2023 is Not Affected by CVE-2024-11236, and we have evaluated CVE-2024-8932.html in the context of Amazon Linux (details at https://explore.alas.aws.amazon.com/CVE-2024-8932.html ). Notably, https://explore.alas.aws.amazon.com/CVE-2024-8932.html affects running 32-bit, of which AL2023 does not ship 32bit packages.

I'm keeping this issue open for a general PHP update though.

@stewartsmith stewartsmith added bug Something isn't working packages Package request fixed-upstream Bug fix is present in an upstream tree/release labels Jan 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working fixed-upstream Bug fix is present in an upstream tree/release packages Package request
Projects
None yet
Development

No branches or pull requests

2 participants