Version 7.3

PHP 7.3.33
Released 18 Nov, 2021
xml
  • Fix #79971: special character is breaking the path in xml function. (CVE-2021-21707)
PHP 7.3.32
Released 28 Oct, 2021
fpm
  • Fixed bug #81026 (PHP-FPM oob R/W in root process leading to privilege escalation). (CVE-2021-21703)
PHP 7.3.31
Released 23 Sep, 2021
zip
  • Fixed bug #81420 (ZipArchive::extractTo extracts outside of destination). (CVE-2021-21706)
PHP 7.3.30
Released 26 Aug, 2021
phar
  • Fixed bug #81211: Symlinks are followed when creating PHAR archive
PHP 7.3.29
Released 01 Jul, 2021
core
  • Fixed bug #81122: SSRF bypass in FILTER_VALIDATE_URL. (CVE-2021-21705)
pdo_firebird
  • Fixed bug #76448: Stack buffer overflow in firebird_info_cb. (CVE-2021-21704)
  • Fixed bug #76449: SIGSEGV in firebird_handle_doer. (CVE-2021-21704)
  • Fixed bug #76450: SIGSEGV in firebird_stmt_execute. (CVE-2021-21704)
  • Fixed bug #76452: Crash while parsing blob data in firebird_fetch_blob. (CVE-2021-21704)
PHP 7.3.28
Released 29 Apr, 2021
core
  • Fixed ./makedist wrt. to GH move.
imap
  • Fixed bug #80710 (imap_mail_compose() header injection).
PHP 7.3.27
Released 04 Feb, 2021
soap
  • Fixed bug #80672 (Null Dereference in SoapClient). (CVE-2021-21702)
PHP 7.3.26
Released 07 Jan, 2021
standard
  • Fixed bug #77423 (FILTER_VALIDATE_URL accepts URLs with invalid userinfo). (CVE-2020-7071)
  • Fixed bug #80457 (stream_get_contents() fails with maxlength=-1 or default).
PHP 7.3.25
Released 26 Nov, 2020
core
  • Fixed bug #80280 (ADD_EXTENSION_DEP() fails for ext/standard and ext/date).
  • Fixed bug #80258 (Windows Deduplication Enabled, randon permission errors).
com
  • Fixed bug #62474 (com_event_sink crashes on certain arguments).
dom
  • Fixed bug #80268 (loadHTML() truncates at NUL bytes).
imap
  • Fixed bug #64076 (imap_sort() does not return FALSE on failure).
  • Fixed bug #76618 (segfault on imap_reopen).
  • Fixed bug #80239 (imap_rfc822_write_address() leaks memory).
  • Fixed minor regression caused by fixing bug #80220.
  • Fixed bug #80242 (imap_mail_compose() segfaults for multipart with rfc822).
intl
  • Fixed bug #80310 (ext-intl with icu4c 68.1: use of undeclared identifier 'TRUE').
odbc
  • Fixed bug #44618 (Fetching may rely on uninitialized data).
snmp
  • Fixed bug #70461 (disable md5 code when it is not supported in net-snmp).
standard
  • Fixed bug #80266 (parse_url silently drops port number 0).
PHP 7.3.24
Released 29 Oct, 2020
core
  • Fixed bug #79423 (copy command is limited to size of file it can copy).
calendar
  • Fixed bug #80185 (jdtounix() fails after 2037).
imap
  • Fixed bug #80213 (imap_mail_compose() segfaults on certain $bodies).
  • Fixed bug #80215 (imap_mail_compose() may modify by-val parameters).
  • Fixed bug #80220 (imap_mail_compose() may leak memory).
  • Fixed bug #80223 (imap_mail_compose() leaks envelope on malformed bodies).
  • Fixed bug #80216 (imap_mail_compose() does not validate types/encodings).
  • Fixed bug #80226 (imap_sort() leaks sortpgm memory).
mysqlnd
  • Fixed bug #80115 (mysqlnd.debug doesn't recognize absolute paths with slashes).
  • Fixed bug #80107 (mysqli_query() fails for ~16 MB long query when compression is enabled).
odbc
  • Fixed bug #78470 (odbc_specialcolumns() no longer accepts $nullable).
  • Fixed bug #80147 (BINARY strings may not be properly zero-terminated).
  • Fixed bug #80150 (Failure to fetch error message).
  • Fixed bug #80152 (odbc_execute() moves internal pointer of $params).
  • Fixed bug #46050 (odbc_next_result corrupts prepared resource).
opcache
  • Fixed bug #80083 (Optimizer pass 6 removes variables used for ibm_db2 data binding).
pdo_odbc
  • Fixed bug #67465 (NULL Pointer dereference in odbc_handle_preparer).
standard
  • Fixed bug #80114 (parse_url does not accept URLs with port 0).
  • Fixed bug #76943 (Inconsistent stream_wrapper_restore() errors).
  • Fixed bug #76735 (Incorrect message in fopen on invalid mode).
tidy
  • Fixed bug #77040 (tidyNode::isHtml() is completely broken).
PHP 7.3.23
Released 01 Oct, 2020
core
  • Fixed bug #80048 (Bug #69100 has not been fixed for Windows).
  • Fixed bug #80049 (Memleak when coercing integers to string via variadic argument).
  • Fixed bug #79699 (PHP parses encoded cookie names so malicious `__Host-` cookies can be sent). (CVE-2020-7070)
calendar
  • Fixed bug #80007 (Potential type confusion in unixtojd() parameter parsing).
com
  • Fixed bug #64130 (COM obj parameters passed by reference are not updated).
opcache
  • Fixed bug #80002 (calc free space for new interned string is wrong).
  • Fixed bug #79825 (opcache.file_cache causes SIGSEGV when custom opcode handlers changed).
openssl
  • Fixed bug #79601 (Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV). (CVE-2020-7069)
pdo
  • Fixed bug #80027 (Terrible performance using $query->fetch on queries with many bind parameters).
soap
  • Fixed bug #47021 (SoapClient stumbles over WSDL delivered with "Transfer-Encoding: chunked").
standard
  • Fixed bug #79986 (str_ireplace bug with diacritics characters).
  • Fixed bug #80077 (getmxrr test bug).
  • Fixed bug #72941 (Modifying bucket->data by-ref has no effect any longer).
  • Fixed bug #80067 (Omitting the port in bindto setting errors).
PHP 7.3.22
Released 03 Sep, 2020
core
  • Fixed bug #79884 (PHP_CONFIG_FILE_PATH is meaningless).
  • Fixed bug #77932 (File extensions are case-sensitive).
  • Fixed bug #79806 (realpath() erroneously resolves link to link).
  • Fixed bug #79895 (PHP_CHECK_GCC_ARG does not allow flags with equal sign).
  • Fixed bug #79919 (Stack use-after-scope in define()).
  • Fixed bug #79934 (CRLF-only line in heredoc causes parsing error).
com
  • Fixed bug #48585 (com_load_typelib holds reference, fails on second call).
exif
  • Fixed bug #75785 (Many errors from exif_read_data).
gettext
  • Fixed bug #70574 (Tests fail due to relying on Linux fallback behavior for gettext()).
ldap
  • Fixed memory leaks.
opcache
  • Fixed bug #73060 (php failed with error after temp folder cleaned up).
pdo
  • Fixed bug #64705 (errorInfo property of PDOException is null when PDO::__construct() fails).
standard
  • Fixed bug #79930 (array_merge_recursive() crashes when called with array with single reference).
  • Fixed bug #79944 (getmxrr always returns true on Alpine linux).
  • Fixed bug #79951 (Memory leak in str_replace of empty string).
xml
  • Fixed bug #79922 (Crash after multiple calls to xml_parser_free()).
PHP 7.3.21
Released 06 Aug, 2020
apache
  • Fixed bug #79030 (Upgrade apache2handler's php_apache_sapi_get_request_time to return usec).
core
  • Fixed bug #79877 (getimagesize function silently truncates after a null byte)
  • Fixed bug #79778 (Assertion failure if dumping closure with unresolved static variable).
  • Fixed bug #79792 (HT iterators not removed if empty array is destroyed).
com
  • Fixed bug #63208 (BSTR to PHP string conversion not binary safe).
  • Fixed bug #63527 (DCOM does not work with Username, Password parameter).
curl
  • Fixed bug #79741 (curl_setopt CURLOPT_POSTFIELDS asserts on object with declared properties).
fileinfo
  • Fixed bug #79756 (finfo_file crash (FILEINFO_MIME)).
ftp
  • Fixed bug #55857 (ftp_size on large files).
mbstring
  • Fixed bug #79787 (mb_strimwidth does not trim string).
phar
  • Fixed bug #79797 (Use of freed hash key in the phar_parse_zipfile function). (CVE-2020-7068)
standard
  • Fixed bug #70362 (Can't copy() large 'data://' with open_basedir).
  • Fixed bug #79817 (str_replace() does not handle INDIRECT elements).
  • Fixed bug #78008 (dns_check_record() always return true on Alpine).
PHP 7.3.20
Released 09 Jul, 2020
core
  • Fixed bug #79650 (php-win.exe 100% cpu lockup).
  • Fixed bug #79668 (get_defined_functions(true) may miss functions).
  • Fixed possibly unsupported timercmp() usage.
exif
  • Fixed bug #79687 (Sony picture - PHP Warning - Make, Model, MakerNotes).
filter
  • Fixed bug #73527 (Invalid memory access in php_filter_strip).
gd
  • Fixed bug #79676 (imagescale adds black border with IMG_BICUBIC).
openssl
  • Fixed bug #62890 (default_socket_timeout=-1 causes connection to timeout).
pdo sqlite
  • Fixed bug #79664 (PDOStatement::getColumnMeta fails on empty result set).
spl
  • Fixed bug #79710 (Reproducible segfault in error_handler during GC involved an SplFileObject).
standard
  • Fixed bug #74267 (segfault with streams and invalid data).
  • Fixed bug #79579 (ZTS build of PHP 7.3.17 doesn't handle ERANGE for posix_getgrgid and others).
PHP 7.3.19
Released 11 Jun, 2020
core
  • Fixed bug #79566 (Private SHM is not private on Windows).
  • Fixed bug #79489 (.user.ini does not inherit).
gd
  • Fixed bug #79615 (Wrong GIF header written in GD GIFEncode).
mysqlnd
  • Fixed bug #79596 (MySQL FLOAT truncates to int some locales).
opcache
  • Fixed bug #79535 (PHP crashes with specific opcache.optimization_level).
  • Fixed bug #79588 (Boolean opcache settings ignore on/off values).
standard
  • Fixed bug #79561 (dns_get_record() fails with DNS_ALL).
PHP 7.3.18
Released 14 May, 2020
core
  • Fixed bug #78875 (Long filenames cause OOM and temp files are not cleaned). (CVE-2019-11048)
  • Fixed bug #78876 (Long variables in multipart/form-data cause OOM and temp files are not cleaned). (CVE-2019-11048)
  • Fixed bug #79434 (PHP 7.3 and PHP-7.4 crash with NULL-pointer dereference on !CS constant).
  • Fixed bug #79477 (casting object into array creates references).
  • Fixed bug #79470 (PHP incompatible with 3rd party file system on demand).
  • Fixed bug #78784 (Unable to interact with files inside a VFS for Git repository).
dom
  • Fixed bug #78221 (DOMNode::normalize() doesn't remove empty text nodes).
fcgi
  • Fixed bug #79491 (Search for .user.ini extends up to root dir).
mbstring
  • Fixed bug #79441 (Segfault in mb_chr() if internal encoding is unsupported).
openssl
  • Fixed bug #79497 (stream_socket_client() throws an unknown error sometimes with <1s timeout).
phar
  • Fix bug #79503 (Memory leak on duplicate metadata).
simplexml
  • Fixed bug #79528 (Different object of the same xml between 7.4.5 and 7.4.4).
standard
  • Fixed bug #79468 (SIGSEGV when closing stream handle with a stream filter appended).
PHP 7.3.17
Released 16 Apr, 2020
core
  • Fixed bug #79364 (When copy empty array, next key is unspecified).
  • Fixed bug #78210 (Invalid pointer address).
curl
  • Fixed bug #79199 (curl_copy_handle() memory leak).
date
  • Fixed bug #79396 (DateTime hour incorrect during DST jump forward).
iconv
  • Fixed bug #79200 (Some iconv functions cut Windows-1258).
opcache
  • Fixed bug #79412 (Opcache chokes and uses 100% CPU on specific script).
session
  • Fixed bug #79413 (session_create_id() fails for active sessions).
shmop
  • Fixed bug #79427 (Integer Overflow in shmop_open()).
simplexml
  • Fixed bug #61597 (SXE properties may lack attributes and content).
spl
  • Fixed bug #75673 (SplStack::unserialize() behavior).
  • Fixed bug #79393 (Null coalescing operator failing with SplFixedArray).
standard
  • Fixed bug #79330 (shell_exec() silently truncates after a null byte).
  • Fixed bug #79465 (OOB Read in urldecode()). (CVE-2020-7067)
  • Fixed bug #79410 (system() swallows last chunk if it is exactly 4095 bytes without newline).
zip
  • Fixed Bug #79296 (ZipArchive::open fails on empty file).
  • Fixed bug #79424 (php_zip_glob uses gl_pathc after call to globfree).
PHP 7.3.16
Released 19 Mar, 2020
core
  • Fixed bug #63206 (restore_error_handler does not restore previous errors mask).
com
  • Fixed bug #66322 (COMPersistHelper::SaveToFile can save to wrong location).
  • Fixed bug #79242 (COM error constants don't match com_exception codes on x86).
  • Fixed bug #79248 (Traversing empty VT_ARRAY throws com_exception).
  • Fixed bug #79299 (com_print_typeinfo prints duplicate variables).
  • Fixed bug #79332 (php_istreams are never freed).
  • Fixed bug #79333 (com_print_typeinfo() leaks memory).
dom
  • Fixed bug #77569: (Write Access Violation in DomImplementation).
  • Fixed bug #79271 (DOMDocumentType::$childNodes is NULL).
enchant
  • Fixed bug #79311 (enchant_dict_suggest() fails on big endian architecture).
exif
  • Fixed bug #79282 (Use-of-uninitialized-value in exif). (CVE-2020-7064)
mbstring
  • Fixed bug #79371 (mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full). (CVE-2020-7065)
mysqli
  • Fixed bug #64032 (mysqli reports different client_version).
pcre
  • Fixed bug #79188 (Memory corruption in preg_replace/preg_replace_callback and unicode).
pdo_odbc
  • Fixed bug #79038 (PDOStatement::nextRowset() leaks column values).
reflection
  • Fixed bug #79062 (Property with heredoc default value returns false for getDocComment).
sqlite3
  • Fixed bug #79294 (::columnType() may fail after SQLite3Stmt::reset()).
standard
  • Fixed bug #79329 (get_headers() silently truncates after a null byte). (CVE-2020-7066)
  • Fixed bug #79254 (getenv() w/o arguments not showing changes).
  • Fixed bug #79265 (Improper injection of Host header when using fopen for http requests).
PHP 7.3.15
Released 20 Feb, 2020
core
  • Fixed bug #71876 (Memory corruption htmlspecialchars(): charset `*' not supported).
  • Fixed bug #79146 (cscript can fail to run on some systems).
  • Fixed bug #78323 (Code 0 is returned on invalid options).
  • Fixed bug #76047 (Use-after-free when accessing already destructed backtrace arguments).
curl
  • Fixed bug #79078 (Hypothetical use-after-free in curl_multi_add_handle()).
intl
  • Fixed bug #79212 (NumberFormatter::format() may detect wrong type).
libxml
  • Fixed bug #79191 (Error in SoapClient ctor disables DOMDocument::save()).
mbstring
  • Fixed bug #79154 (mb_convert_encoding() can modify $from_encoding).
mysqlnd
  • Fixed bug #79084 (mysqlnd may fetch wrong column indexes with MYSQLI_BOTH).
openssl
  • Fixed bug #79145 (openssl memory leak).
phar
  • Fixed bug #79082 (Files added to tar with Phar::buildFromIterator have all-access permissions). (CVE-2020-7063)
  • Fixed bug #79171 (heap-buffer-overflow in phar_extract_file). (CVE-2020-7061)
  • Fixed bug #76584 (PharFileInfo::decompress not working).
reflection
  • Fixed bug #79115 (ReflectionClass::isCloneable call reflected class __destruct).
session
  • Fixed bug #79221 (Null Pointer Dereference in PHP Session Upload Progress). (CVE-2020-7062)
spl
  • Fixed bug #79151 (heap use after free caused by spl_dllist_it_helper_move_forward).
standard
  • Fixed bug #78902 (Memory leak when using stream_filter_append).
testing
  • Fixed bug #78090 (bug45161.phpt takes forever to finish).
xsl
  • Fixed bug #70078 (XSL callbacks with nodes as parameter leak memory).
PHP 7.3.14
Released 23 Jan, 2020
curl
  • Fixed bug #78999 (Cycle leak when using function result as temporary).
  • Fixed bug #79033 (Curl timeout error with specific url and post).
date
  • Fixed bug #79015 (undefined-behavior in php_date.c).
dba
  • Fixed bug #78808 ([LMDB] MDB_MAP_FULL: Environment mapsize limit reached).
fileinfo
  • Fixed bug #74170 (locale information change after mime_content_type).
gd
  • Fixed bug #78923 (Artifacts when convoluting image with transparency).
  • Fixed bug #79067 (gdTransformAffineCopy() may use unitialized values).
  • Fixed bug #79068 (gdTransformAffineCopy() changes interpolation method).
libxml
  • Fixed bug #79029 (Use After Free's in XMLReader / XMLWriter).
mbstring
  • Fixed bug #79037 (global buffer-overflow in `mbfl_filt_conv_big5_wchar`). (CVE-2020-7060)
opcache
  • Fixed bug #79040 (Warning Opcode handlers are unusable due to ASLR).
pcntl
  • Fixed bug #78402 (Converting null to string in error message is bad DX).
pdo_pgsql
  • Fixed bug #78983 (pdo_pgsql config.w32 cannot find libpq-fe.h).
  • Fixed bug #78980 (pgsqlGetNotify() overlooks dead connection).
  • Fixed bug #78982 (pdo_pgsql returns dead persistent connection).
session
  • Fixed bug #79091 (heap use-after-free in session_create_id()).
shmop
  • Fixed bug #78538 (shmop memory leak).
standard
  • Fixed bug #79099 (OOB read in php_strip_tags_ex). (CVE-2020-7059).
  • Fixed bug #54298 (Using empty additional_headers adding extraneous CRLF).
PHP 7.3.13
Released 18 Dec, 2019
bcmath
  • Fixed bug #78878 (Buffer underflow in bc_shift_addsub). (CVE-2019-11046).
core
  • Fixed bug #78862 (link() silently truncates after a null byte on Windows). (CVE-2019-11044).
  • Fixed bug #78863 (DirectoryIterator class silently truncates after a null byte). (CVE-2019-11045).
  • Fixed bug #78943 (mail() may release string with refcount==1 twice). (CVE-2019-11049).
  • Fixed bug #78787 (Segfault with trait overriding inherited private shadow property).
  • Fixed bug #78868 (Calling __autoload() with incorrect EG(fake_scope) value).
  • Fixed bug #78296 (is_file fails to detect file).
exif
  • Fixed bug #78793 (Use-after-free in exif parsing under memory sanitizer). (CVE-2019-11050).
  • Fixed bug #78910 (Heap-buffer-overflow READ in exif). (CVE-2019-11047).
gd
  • Fixed bug #78849 (GD build broken with -D SIGNED_COMPARE_SLOW).
mbstring
  • Upgraded bundled Oniguruma to 6.9.4.
opcache
  • Fixed potential ASLR related invalid opline handler issues.
  • Fixed $x = (bool)$x; with opcache (should emit undeclared variable notice).
pcre
  • Fixed bug #78853 (preg_match() may return integer > 1).
standard
  • Fixed bug #78759 (array_search in $GLOBALS).
  • Fixed bug #77638 (var_export'ing certain class instances segfaults).
  • Fixed bug #78840 (imploding $GLOBALS crashes).
  • Fixed bug #78833 (Integer overflow in pack causes out-of-bound access).
  • Fixed bug #78814 (strip_tags allows / in tag name => whitelist bypass).
PHP 7.3.12
Released 21 Nov, 2019
core
  • Fixed bug #78658 (Memory corruption using Closure::bindTo).
  • Fixed bug #78656 (Parse errors classified as highest log-level).
  • Fixed bug #78752 (Segfault if GC triggered while generator stack frame is being destroyed).
  • Fixed bug #78689 (Closure::fromCallable() doesn't handle [Closure, '__invoke']).
com
  • Fixed bug #78694 (Appending to a variant array causes segfault).
date
  • Fixed bug #70153 (\DateInterval incorrectly unserialized).
  • Fixed bug #78751 (Serialising DatePeriod converts DateTimeImmutable).
iconv
  • Fixed bug #78642 (Wrong libiconv version displayed). .
opcache
  • Fixed bug #78654 (Incorrectly computed opcache checksum on files with non-ascii characters).
  • Fixed bug #78747 (OpCache corrupts custom extension result).
openssl
  • Fixed bug #78775 (TLS issues from HTTP request affecting other encrypted connections).
reflection
  • Fixed bug #78697 (ReflectionClass::ImplementsInterface - inaccurate error message with traits).
sockets
  • Fixed bug #78665 (Multicasting may leak memory).
PHP 7.3.11
Released 24 Oct, 2019
core
  • Fixed bug #78535 (auto_detect_line_endings value not parsed as bool).
  • Fixed bug #78620 (Out of memory error).
exif
  • Fixed bug #78442 ('Illegal component' on exif_read_data since PHP7)
fpm
  • Fixed bug #78599 (env_path_info underflow in fpm_main.c can lead to RCE). (CVE-2019-11043)
  • Fixed bug #78413 (request_terminate_timeout does not take effect after fastcgi_finish_request).
mbstring
  • Fixed bug #78633 (Heap buffer overflow (read) in mb_eregi).
  • Fixed bug #78579 (mb_decode_numericentity: args number inconsistency).
  • Fixed bug #78609 (mb_check_encoding() no longer supports stringable objects).
mysqli
  • Fixed bug #76809 (SSL settings aren't respected when persistent connections are used).
mysqlnd
  • Fixed bug #78525 (Memory leak in pdo when reusing native prepared statements).
pcre
  • Fixed bug #78272 (calling preg_match() before pcntl_fork() will freeze child process).
pdo_mysql
  • Fixed bug #78623 (Regression caused by "SP call yields additional empty result set").
session
  • Fixed bug #78624 (session_gc return value for user defined session handlers).
standard
  • Fixed bug #76342 (file_get_contents waits twice specified timeout).
  • Fixed bug #78612 (strtr leaks memory when integer keys are used and the subject string shorter).
  • Fixed bug #76859 (stream_get_line skips data if used with data-generating filter).
zip
  • Fixed bug #78641 (addGlob can modify given remove_path value).
PHP 7.3.10
Released 26 Sep, 2019
core
  • Fixed bug #78220 (Can't access OneDrive folder).
  • Fixed bug #77922 (Double release of doc comment on inherited shadow property).
  • Fixed bug #78441 (Parse error due to heredoc identifier followed by digit).
  • Fixed bug #77812 (Interactive mode does not support PHP 7.3-style heredoc).
fastcgi
  • Fixed bug #78469 (FastCGI on_accept hook is not called when using named pipes on Windows).
fpm
  • Fixed bug #78334 (fpm log prefix message includes wrong stdout/stderr notation).
intl
  • Ensure IDNA2003 rules are used with idn_to_ascii() and idn_to_utf8() when requested.
mbstring
  • Fixed bug #78559 (Heap buffer overflow in mb_eregi).
mysqlnd
  • Fixed connect_attr issues and added the _server_host connection attribute.
odbc
  • Fixed bug #78473 (odbc_close() closes arbitrary resources).
pdo_mysql
  • Fixed bug #41997 (SP call yields additional empty result set).
sodium
  • Fixed bug #78510 (Partially uninitialized buffer returned by sodium_crypto_generichash_init()).
PHP 7.3.9
Released 29 Aug, 2019
core
  • Fixed bug #78363 (Buffer overflow in zendparse).
  • Fixed bug #78379 (Cast to object confuses GC, causes crash).
  • Fixed bug #78412 (Generator incorrectly reports non-releasable $this as GC child).
curl
  • Fixed bug #77946 (Bad cURL resources returned by curl_multi_info_read()).
exif
  • Fixed bug #78333 (Exif crash (bus error) due to wrong alignment and invalid cast).
fpm
  • Fixed bug #77185 (Use-after-free in FPM master event handling).
iconv
  • Fixed bug #78342 (Bus error in configure test for iconv //IGNORE).
litespeed
  • Updated to LiteSpeed SAPI V7.5 (Fixed clean shutdown).
mbstring
  • Fixed bug #78380 (Oniguruma 6.9.3 fixes CVEs). (CVE-2019-13224)
mysqlnd
  • Fixed bug #78179 (MariaDB server version incorrectly detected).
  • Fixed bug #78213 (Empty row pocket).
opcache
  • Fixed bug #77191 (Assertion failure in dce_live_ranges() when silencing is used).
standard
  • Fixed bug #69100 (Bus error from stream_copy_to_stream (file -> SSL stream) with invalid length).
  • Fixed bug #78282 (atime and mtime mismatch).
  • Fixed bug #78326 (improper memory deallocation on stream_get_contents() with fixed length buffer).
  • Fixed bug #78346 (strip_tags no longer handling nested php tags).
PHP 7.3.8
Released 01 Aug, 2019
core
  • Added syslog.filter=raw option.
  • Fixed bug #78212 (Segfault in built-in webserver).
date
  • Fixed bug #69044 (discrepency between time and microtime).
  • Updated timelib to 2018.02.
exif
  • Fixed bug #78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042)
  • Fixed bug #78222 (heap-buffer-overflow on exif_scan_thumbnail). (CVE-2019-11041)
ftp
  • Fixed bug #78039 (FTP with SSL memory leak).
libxml
  • Fixed bug #78279 (libxml_disable_entity_loader settings is shared between requests (cgi-fcgi)).
litespeed
  • Updated to LiteSpeed SAPI V7.4.3 (increased response header count limit from 100 to 1000, added crash handler to cleanly shutdown PHP request, added CloudLinux mod_lsapi mode).
  • Fixed bug #76058 (After "POST data can't be buffered", using php://input makes huge tmp files).
openssl
  • Fixed bug #78231 (Segmentation fault upon stream_socket_accept of exported socket-to-stream).
opcache
  • Fixed bug #78189 (file cache strips last character of uname hash).
  • Fixed bug #78202 (Opcache stats for cache hits are capped at 32bit NUM).
  • Fixed bug #78271 (Invalid result of if-else).
  • Fixed bug #78291 (opcache_get_configuration doesn't list all directives).
  • Fixed bug #78341 (Failure to detect smart branch in DFA pass).
pcre
  • Fixed bug #78197 (PCRE2 version check in configure fails for "##.##-xxx" version strings).
  • Fixed bug #78338 (Array cross-border reading in PCRE).
pdo_sqlite
  • Fixed bug #78192 (SegFault when reuse statement after schema has changed).
phar
  • Fixed bug #77919 (Potential UAF in Phar RSHUTDOWN).
phpdbg
  • Fixed bug #78297 (Include unexistent file memory leak).
sqlite
  • Upgraded to SQLite 3.28.0.
standard
  • Fixed bug #78241 (touch() does not handle dates after 2038 in PHP 64-bit).
  • Fixed bug #78269 (password_hash uses weak options for argon2).
PHP 7.3.7
Released 04 Jul, 2019
core
  • Fixed bug #76980 (Interface gets skipped if autoloader throws an exception).
dom
  • Fixed bug #78025 (segfault when accessing properties of DOMDocumentType).
mysqli
  • Fixed bug #77956 (When mysqli.allow_local_infile = Off, use a meaningful error message).
  • Fixed bug #38546 (bindParam incorrect processing of bool types).
mysqlnd
  • Fixed bug #77955 (Random segmentation fault in mysqlnd from php-fpm).
opcache
  • Fixed bug #78015 (Incorrect evaluation of expressions involving partials arrays in SCCP).
  • Fixed bug #78106 (Path resolution fails if opcache disabled during request).
openssl
  • Fixed bug #78079 (openssl_encrypt_ccm.phpt fails with OpenSSL 1.1.1c).
phpdbg
  • Fixed bug #78050 (SegFault phpdbg + opcache on include file twice).
sockets
  • Fixed bug #78038 (Socket_select fails when resource array contains references).
sodium
  • Fixed bug #78114 (segfault when calling sodium_* functions from eval).
standard
  • Fixed bug #77135 (Extract with EXTR_SKIP should skip $this).
  • Fixed bug #77937 (preg_match failed).
zip
  • Fixed bug #76345 (zip.h not found).
PHP 7.3.6
Released 30 May, 2019
curl
  • Implemented FR #72189 (Add missing CURL_VERSION_* constants).
date
  • Fixed bug #77909 (DatePeriod::__construct() with invalid recurrence count value).
exif
  • Fixed bug #77988 (heap-buffer-overflow on php_jpg_get16). (CVE-2019-11040)
fpm
  • Fixed bug #77934 (php-fpm kill -USR2 not working).
  • Fixed bug #77921 (static.php.net doesn't work anymore).
gd
  • Fixed bug #77943 (imageantialias($image, false); does not work).
  • Fixed bug #77973 (Uninitialized read in gdImageCreateFromXbm). (CVE-2019-11038)
iconv
  • Fixed bug #78069 (Out-of-bounds read in iconv.c:_php_iconv_mime_decode() due to integer overflow). (CVE-2019-11039).
json
  • Fixed bug #77843 (Use after free with json serializer).
opcache
  • Fixed possible crashes, because of inconsistent PCRE cache and opcache SHM reset.
pdo_mysql
  • Fixed bug #77944 (Wrong meta pdo_type for bigint on LLP64).
reflection
  • Fixed bug #75186 (Inconsistent reflection of Closure:::__invoke()).
session
  • Fixed bug #77911 (Wrong warning for session.sid_bits_per_character).
soap
  • Fixed bug #77945 (Segmentation fault when constructing SoapClient with WSDL_CACHE_BOTH).
spl
  • Fixed bug #77024 (SplFileObject::__toString() may return array).
sqlite
  • Fixed bug #77967 (Bypassing open_basedir restrictions via file uris).
standard
  • Fixed bug #77931 (Warning for array_map mentions wrong type).
  • Fixed bug #78003 (strip_tags output change since PHP 7.3).
PHP 7.3.5
Released 02 May, 2019
core
  • Fixed bug #77903 (ArrayIterator stops iterating after offsetSet call).
cli
  • Fixed bug #77794 (Incorrect Date header format in built-in server).
  • EXIF
  • Fixed bug #77950 (Heap-buffer-overflow in _estrndup via exif_process_IFD_TAG). (CVE-2019-11036)
interbase
  • Fixed bug #72175 (Impossibility of creating multiple connections to Interbase with php 7.x).
intl
  • Fixed bug #77895 (IntlDateFormatter::create fails in strict mode if $locale = null).
ldap
  • Fixed bug #77869 (Core dump when using server controls)
  • Mail
  • Fixed bug #77821 (Potential heap corruption in TSendMail()).
mbstring
  • Implemented FR #72777 (Implement regex stack limits for mbregex functions).
mysqli
  • Fixed bug #77773 (Unbuffered queries leak memory - MySQLi / mysqlnd).
pcre
  • Fixed bug #77827 (preg_match does not ignore \r in regex flags).
pdo
  • Fixed bug #77849 (Disable cloning of PDO handle/connection objects).
phpdbg
  • Fixed bug #76801 (too many open files).
  • Fixed bug #77800 (phpdbg segfaults on listing some conditional breakpoints).
  • Fixed bug #77805 (phpdbg build fails when readline is shared).
reflection
  • Fixed bug #77772 (ReflectionClass::getMethods(null) doesn't work).
  • Fixed bug #77882 (Different behavior: always calls destructor).
standard
  • Fixed bug #77793 (Segmentation fault in extract() when overwriting reference with itself).
  • Fixed bug #77844 (Crash due to null pointer in parse_ini_string with INI_SCANNER_TYPED).
  • Fixed bug #77853 (Inconsistent substr_compare behaviour with empty haystack).
PHP 7.3.4
Released 04 Apr, 2019
core
  • Fixed bug #77738 (Nullptr deref in zend_compile_expr).
  • Fixed bug #77660 (Segmentation fault on break 2147483648).
  • Fixed bug #77652 (Anonymous classes can lose their interface information).
  • Fixed bug #77345 (Stack Overflow caused by circular reference in garbage collection).
  • Fixed bug #76956 (Wrong value for 'syslog.filter' documented in php.ini).
apache2handler
  • Fixed bug #77648 (BOM in sapi/apache2handler/php_functions.c).
bcmath
  • Fixed bug #77742 (bcpow() implementation related to gcc compiler optimization).
cli server
  • Fixed bug #77722 (Incorrect IP set to $_SERVER['REMOTE_ADDR'] on the localhost).
com
  • Fixed bug #77578 (Crash when php unload).
exif
  • Fixed bug #77753 (Heap-buffer-overflow in php_ifd_get32s). (CVE-2019-11034)
  • Fixed bug #77831 (Heap-buffer-overflow in exif_iif_add_value). (CVE-2019-11035)
fpm
  • Fixed bug #77677 (FPM fails to build on AIX due to missing WCOREDUMP).
gd
  • Fixed bug #77700 (Writing truecolor images as GIF ignores interlace flag).
mysqli
  • Fixed bug #77597 (mysqli_fetch_field hangs scripts).
opcache
  • Fixed bug #77743 (Incorrect pi node insertion for jmpznz with identical successors).
pcre
  • Fixed bug #76127 (preg_split does not raise an error on invalid UTF-8).
phar
  • Fixed bug #77697 (Crash on Big_Endian platform).
phpdbg
  • Fixed bug #77767 (phpdbg break cmd aliases listed in help do not match actual aliases).
sodium
  • Fixed bug #77646 (sign_detached() strings not terminated).
sqlite3
  • Added sqlite3.defensive INI directive.
standard
  • Fixed bug #77664 (Segmentation fault when using undefined constant in custom wrapper).
  • Fixed bug #77669 (Crash in extract() when overwriting extracted array).
  • Fixed bug #76717 (var_export() does not create a parsable value for PHP_INT_MIN).
  • Fixed bug #77765 (FTP stream wrapper should set the directory as executable).
PHP 7.3.3
Released 07 Mar, 2019
core
  • Fixed bug #77589 (Core dump using parse_ini_string with numeric sections).
  • Fixed bug #77329 (Buffer Overflow via overly long Error Messages).
  • Fixed bug #77494 (Disabling class causes segfault on member access).
  • Fixed bug #77498 (Custom extension Segmentation fault when declare static property).
  • Fixed bug #77530 (PHP crashes when parsing `(2)::class`).
  • Fixed bug #77546 (iptcembed broken function).
  • Fixed bug #77630 (rename() across the device may allow unwanted access during processing).
com
  • Fixed bug #77621 (Already defined constants are not properly reported).
  • Fixed bug #77626 (Persistence confusion in php_com_import_typelib()).
exif
  • Fixed bug #77509 (Uninitialized read in exif_process_IFD_in_TIFF).
  • Fixed bug #77540 (Invalid Read on exif_process_SOFn).
  • Fixed bug #77563 (Uninitialized read in exif_process_IFD_in_MAKERNOTE).
  • Fixed bug #77659 (Uninitialized read in exif_process_IFD_in_MAKERNOTE).
mbstring
  • Fixed bug #77514 (mb_ereg_replace() with trailing backslash adds null byte).
  • MySQL
  • Disabled LOCAL INFILE by default, can be enabled using php.ini directive mysqli.allow_local_infile for mysqli, or PDO::MYSQL_ATTR_LOCAL_INFILE attribute for pdo_mysql.
openssl
  • Fixed bug #77390 (feof might hang on TLS streams in case of fragmented TLS records).
pdo_oci
  • Support Oracle Database tracing attributes ACTION, MODULE, CLIENT_INFO, and CLIENT_IDENTIFIER.
phar
  • Fixed bug #77396 (Null Pointer Dereference in phar_create_or_parse_filename).
  • Fixed bug #77586 (phar_tar_writeheaders_int() buffer overflow).
phpdbg
  • Fixed bug #76596 (phpdbg support for display_errors=stderr).
spl
  • Fixed bug #51068 (DirectoryIterator glob:// don't support current path relative queries).
  • Fixed bug #77431 (openFile() silently truncates after a null byte).
standard
  • Fixed bug #77552 (Unintialized php_stream_statbuf in stat functions).
  • Fixed bug #77612 (setcookie() sets incorrect SameSite header if all of its options filled).
PHP 7.3.2
Released 07 Feb, 2019
core
  • Fixed bug #77369 (memcpy with negative length via crafted DNS response).
  • Fixed bug #77387 (Recursion detection broken when printing GLOBALS).
  • Fixed bug #77376 ("undefined function" message no longer includes namespace).
  • Fixed bug #77357 (base64_encode / base64_decode doest not work on nested VM).
  • Fixed bug #77339 (__callStatic may get incorrect arguments).
  • Fixed bug #77317 (__DIR__, __FILE__, realpath() reveal physical path for subst virtual drive).
  • Fixed bug #77263 (Segfault when using 2 RecursiveFilterIterator).
  • Fixed bug #77447 (PHP 7.3 built with ASAN crashes in zend_cpu_supports_avx2).
  • Fixed bug #77484 (Zend engine crashes when calling realpath in invalid working dir).
curl
  • Fixed bug #76675 (Segfault with H2 server push).
fileinfo
  • Fixed bug #77346 (webm files incorrectly detected as application/octet-stream).
fpm
  • Fixed bug #77430 (php-fpm crashes with Main process exited, code=dumped, status=11/SEGV).
gd
  • Fixed bug #73281 (imagescale(…, IMG_BILINEAR_FIXED) can cause black border).
  • Fixed bug #73614 (gdImageFilledArc() doesn't properly draw pies).
  • Fixed bug #77272 (imagescale() may return image resource on failure).
  • Fixed bug #77391 (1bpp BMPs may fail to be loaded).
  • Fixed bug #77479 (imagewbmp() segfaults with very large images).
ldap
  • Fixed bug #77440 (ldap_bind using ldaps or ldap_start_tls()=exception in libcrypto-1_1-x64.dll).
mbstring
  • Fixed bug #77428 (mb_ereg_replace() doesn't replace a substitution variable).
  • Fixed bug #77454 (mb_scrub() silently truncates after a null byte).
mysqlnd
  • Fixed bug #77308 (Unbuffered queries memory leak).
  • Fixed bug #75684 (In mysqlnd_ext_plugin.h the plugin methods family has no external visibility).
opcache
  • Fixed bug #77266 (Assertion failed in dce_live_ranges).
  • Fixed bug #77257 (value of variable assigned in a switch() construct gets lost).
  • Fixed bug #77434 (php-fpm workers are segfaulting in zend_gc_addre).
  • Fixed bug #77361 (configure fails on 64-bit AIX when opcache enabled).
  • Fixed bug #77287 (Opcache literal compaction is incompatible with EXT opcodes).
pcre
  • Fixed bug #77338 (get_browser with empty string).
pdo
  • Fixed bug #77273 (array_walk_recursive corrupts value types leading to PDO failure).
pdo mysql
  • Fixed bug #77289 (PDO MySQL segfaults with persistent connection).
soap
  • Fixed bug #77410 (Segmentation Fault when executing method with an empty parameter).
sockets
  • Fixed bug #76839 (socket_recvfrom may return an invalid 'from' address on MacOS).
spl
  • Fixed bug #77298 (segfault occurs when add property to unserialized empty ArrayObject).
standard
  • Fixed bug #77395 (segfault about array_multisort).
  • Fixed bug #77439 (parse_str segfaults when inserting item into existing array).
PHP 7.3.1
Released 10 Jan, 2019
core
  • Fixed bug #76654 (Build failure on Mac OS X on 32-bit Intel).
  • Fixed bug #71041 (zend_signal_startup() needs ZEND_API).
  • Fixed bug #76046 (PHP generates "FE_FREE" opcode on the wrong line).
  • Fixed bug #77291 (magic methods inherited from a trait may be ignored).
curl
  • Fixed bug #77264 (curl_getinfo returning microseconds, not seconds).
com
  • Fixed bug #77177 (Serializing or unserializing COM objects crashes).
exif
  • Fixed bug #77184 (Unsigned rational numbers are written out as signed rationals).
gd
  • Fixed bug #77195 (Incorrect error handling of imagecreatefromjpeg()).
  • Fixed bug #77198 (auto cropping has insufficient precision).
  • Fixed bug #77200 (imagecropauto(…, GD_CROP_SIDES) crops left but not right).
  • Fixed bug #77269 (efree() on uninitialized Heap data in imagescale leads to use-after-free).
  • Fixed bug #77270 (imagecolormatch Out Of Bounds Write on Heap).
mbstring
  • Fixed bug #77367 (Negative size parameter in mb_split).
  • Fixed bug #77370 (Buffer overflow on mb regex functions - fetch_token).
  • Fixed bug #77371 (heap buffer overflow in mb regex functions
  • compile_string_node).
  • Fixed bug #77381 (heap buffer overflow in multibyte match_at).
  • Fixed bug #77382 (heap buffer overflow due to incorrect length in expand_case_fold_string).
  • Fixed bug #77385 (buffer overflow in fetch_token).
  • Fixed bug #77394 (Buffer overflow in multibyte case folding - unicode).
  • Fixed bug #77418 (Heap overflow in utf32be_mbc_to_code).
oci8
  • Fixed bug #76804 (oci_pconnect with OCI_CRED_EXT not working).
  • Added oci_set_call_timeout() for call timeouts.
  • Added oci_set_db_operation() for the DBOP end-to-end-tracing attribute.
opcache
  • Fixed bug #77215 (CFG assertion failure on multiple finalizing switch frees in one block).
  • Fixed bug #77275 (OPcache optimization problem for ArrayAccess->offsetGet).
pcre
  • Fixed bug #77193 (Infinite loop in preg_replace_callback).
pdo
  • Handle invalid index passed to PDOStatement::fetchColumn() as error.
phar
  • Fixed bug #77247 (heap buffer overflow in phar_detect_phar_fname_ext).
soap
  • Fixed bug #77088 (Segfault when using SoapClient with null options).
sockets
  • Fixed bug #77136 (Unsupported IPV6_RECVPKTINFO constants on macOS).
sodium
  • Fixed bug #77297 (SodiumException segfaults on PHP 7.3).
spl
  • Fixed bug #77359 (spl_autoload causes segfault).
  • Fixed bug #77360 (class_uses causes segfault).
sqlite3
  • Fixed bug #77051 (Issue with re-binding on SQLite3).
xmlrpc
  • Fixed bug #77242 (heap out of bounds read in xmlrpc_decode()).
  • Fixed bug #77380 (Global out of bounds read in xmlrpc base64 code).
PHP 7.3.0
Released 06 Dec, 2018
core
  • Improved PHP GC.
  • Redesigned the old ext_skel program written in PHP, run: 'php ext_skel.php' for all options. This means there are no dependencies, thus making it work on Windows out of the box.
  • Removed support for BeOS.
  • Add PHP_VERSION to phpinfo() <title/>.
  • Add net_get_interfaces().
  • Added gc_status().
  • Implemented flexible heredoc and nowdoc syntax, per RFC https://wiki.php.net/rfc/flexible_heredoc_nowdoc_syntaxes.
  • Added support for references in list() and array destructuring, per RFC https://wiki.php.net/rfc/list_reference_assignment.
  • Improved effectiveness of ZEND_SECURE_ZERO for NetBSD and systems without native similar feature.
  • Added syslog.facility and syslog.ident INI entries for customizing syslog logging.
  • Fixed bug #75683 (Memory leak in zend_register_functions() in ZTS mode).
  • Fixed bug #75031 (support append mode in temp/memory streams).
  • Fixed bug #74860 (Uncaught exceptions not being formatted properly when error_log set to "syslog").
  • Fixed bug #75220 (Segfault when calling is_callable on parent).
  • Fixed bug #69954 (broken links and unused config items in distributed ini files).
  • Fixed bug #74922 (Composed class has fatal error with duplicate, equal const properties).
  • Fixed bug #63911 (identical trait methods raise errors during composition).
  • Fixed bug #75677 (Clang ignores fastcall calling convention on variadic function).
  • Fixed bug #54043 (Remove inconsitency of internal exceptions and user defined exceptions).
  • Fixed bug #53033 (Mathematical operations convert objects to integers).
  • Fixed bug #73108 (Internal class cast handler uses integer instead of float).
  • Fixed bug #75765 (Fatal error instead of Error exception when base class is not found).
  • Fixed bug #76198 (Wording: "iterable" is not a scalar type).
  • Fixed bug #76137 (config.guess/config.sub do not recognize RISC-V).
  • Fixed bug #76427 (Segfault in zend_objects_store_put).
  • Fixed bug #76422 (ftruncate fails on files > 2GB).
  • Fixed bug #76509 (Inherited static properties can be desynchronized from their parent by ref).
  • Fixed bug #76439 (Changed behaviour in unclosed HereDoc).
  • Fixed bug #63217 (Constant numeric strings become integers when used as ArrayAccess offset).
  • Fixed bug #33502 (Some nullary functions don't check the number of arguments).
  • Fixed bug #76392 (Error relocating sapi/cli/php: unsupported relocation type 37).
  • The declaration and use of case-insensitive constants has been deprecated.
  • Added syslog.filter INI entry for syslog filtering.
  • Fixed bug #76667 (Segfault with divide-assign op and __get + __set).
  • Fixed bug #76030 (RE2C_FLAGS rarely honoured)
  • Fixed broken zend_read_static_property
  • Fixed bug #76773 (Traits used on the parent are ignored for child classes).
  • Fixed bug #76767 (‘asm’ operand has impossible constraints in zend_operators.h).
  • Fixed bug #76752 (Crash in ZEND_COALESCE_SPEC_TMP_HANDLER - assertion in _get_zval_ptr_tmp failed).
  • Fixed bug #76820 (Z_COPYABLE invalid definition).
  • Fixed bug #76510 (file_exists() stopped working for phar://).
  • Fixed bug #76869 (Incorrect bypassing protected method accessibilty check).
  • Fixed bug #72635 (Undefined class used by class constant in constexpr generates fatal error).
  • Fixed bug #76947 (file_put_contents() blocks the directory of the file (__DIR__)).
  • Fixed bug #76979 (define() error message does not mention resources as valid values).
  • Fixed bug #76825 (Undefined symbols ___cpuid_count).
  • Fixed bug #77110 (undefined symbol zend_string_equal_val in C++ build).
bcmath
  • Implemented FR #67855 (No way to get current scale in use).
  • Fixed bug #66364 (BCMath bcmul ignores scale parameter).
  • Fixed bug #75164 (split_bc_num() is pointless).
  • Fixed bug #75169 (BCMath errors/warnings bypass PHP's error handling).
cli
  • Fixed bug #44217 (Output after stdout/stderr closed cause immediate exit with status 0).
  • Fixed bug #77111 (php-win.exe corrupts unicode symbols from cli parameters).
curl
  • Expose curl constants from curl 7.50 to 7.61.
  • Fixed bug #74125 (Fixed finding CURL on systems with multiarch support).
date
  • Implemented FR #74668: Add DateTime::createFromImmutable() method.
  • Fixed bug #75222 (DateInterval microseconds property always 0).
  • Fixed bug #68406 (calling var_dump on a DateTimeZone object modifies it).
  • Fixed bug #76131 (mismatch arginfo for date_create).
  • Updated timelib to 2018.01RC1 to address several bugs:
  • Fixed bug #75577 (DateTime::createFromFormat does not accept 'v' format specifier).
  • Fixed bug #75642 (Wrap around behaviour for microseconds is not working).
dba
  • Fixed bug #75264 (compiler warnings emitted).
dom
  • Fixed bug #76285 (DOMDocument::formatOutput attribute sometimes ignored).
fileinfo
  • Fixed bug #77095 (slowness regression in 7.2/7.3 (compared to 7.1)).
filter
  • Added the 'add_slashes' sanitization mode (FILTER_SANITIZE_ADD_SLASHES).
fpm
  • Added fpm_get_status function.
  • Fixed bug #62596 (getallheaders() missing with PHP-FPM).
  • Fixed bug #69031 (Long messages into stdout/stderr are truncated incorrectly) - added new log related FPM configuration options: log_limit, log_buffering and decorate_workers_output.
ftp
  • Fixed bug #77151 (ftp_close(): SSL_read on shutdown).
gd
  • Added support for WebP in imagecreatefromstring().
gmp
  • Export internal structures and accessor helpers for GMP object.
  • Added gmp_binomial(n, k).
  • Added gmp_lcm(a, b).
  • Added gmp_perfect_power(a).
  • Added gmp_kronecker(a, b).
iconv
  • Fixed bug #53891 (iconv_mime_encode() fails to Q-encode UTF-8 string).
  • Fixed bug #77147 (Fixing 60494 ignored ICONV_MIME_DECODE_CONTINUE_ON_ERROR).
imap
  • Fixed bug #77020 (null pointer dereference in imap_mail).
  • Fixed bug #77153 (imap_open allows to run arbitrary shell commands via mailbox parameter).
interbase
  • Fixed bug #75453 (Incorrect reflection for ibase_[p]connect).
  • Fixed bug #76443 (php+php_interbase.dll crash on module_shutdown).
intl
  • Fixed bug #75317 (UConverter::setDestinationEncoding changes source instead of destination).
  • Fixed bug #76829 (Incorrect validation of domain on idn_to_utf8() function).
json
  • Added JSON_THROW_ON_ERROR flag.
ldap
  • Added ldap_exop_refresh helper for EXOP REFRESH operation with dds overlay.
  • Added full support for sending and parsing ldap controls.
  • Fixed bug #49876 (Fix LDAP path lookup on 64-bit distros).
libxml2
  • Fixed bug #75871 (use pkg-config where available).
litespeed
  • Fixed bug #75248 (Binary directory doesn't get created when building only litespeed SAPI).
  • Fixed bug #75251 (Missing program prefix and suffix).
mbstring
  • Updated to Oniguruma 6.9.0.
  • Fixed bug #65544 (mb title case conversion-first word in quotation isn't capitalized).
  • Fixed bug #71298 (MB_CASE_TITLE misbehaves with curled apostrophe/quote).
  • Fixed bug #73528 (Crash in zif_mb_send_mail).
  • Fixed bug #74929 (mbstring functions version 7.1.1 are slow compared to 5.3 on Windows).
  • Fixed bug #76319 (mb_strtolower with invalid UTF-8 causes segmentation fault).
  • Fixed bug #76574 (use of undeclared identifiers INT_MAX and LONG_MAX).
  • Fixed bug #76594 (Bus Error due to unaligned access in zend_ini.c OnUpdateLong).
  • Fixed bug #76706 (mbstring.http_output_conv_mimetypes is ignored).
  • Fixed bug #76958 (Broken UTF7-IMAP conversion).
  • Fixed bug #77025 (mb_strpos throws Unknown encoding or conversion error).
  • Fixed bug #77165 (mb_check_encoding crashes when argument given an empty array).
mysqlnd
  • Fixed bug #76386 (Prepared Statement formatter truncates fractional seconds from date/time column).
odbc
  • Removed support for ODBCRouter.
  • Removed support for Birdstep.
  • Fixed bug #77079 (odbc_fetch_object has incorrect type signature).
opcache
  • Fixed bug #76466 (Loop variable confusion).
  • Fixed bug #76463 (var has array key type but not value type).
  • Fixed bug #76446 (zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc)).
  • Fixed bug #76711 (OPcache enabled triggers false-positive "Illegal string offset").
  • Fixed bug #77058 (Type inference in opcache causes side effects).
  • Fixed bug #77092 (array_diff_key() - segmentation fault).
openssl
  • Added openssl_pkey_derive function.
  • Add min_proto_version and max_proto_version ssl stream options as well as related constants for possible TLS protocol values.
pcre
  • Implemented https://wiki.php.net/rfc/pcre2-migration.
  • Upgrade PCRE2 to 10.32.
  • Fixed bug #75355 (preg_quote() does not quote # control character).
  • Fixed bug #76512 (\w no longer includes unicode characters).
  • Fixed bug #76514 (Regression in preg_match makes it fail with PREG_JIT_STACKLIMIT_ERROR).
  • Fixed bug #76909 (preg_match difference between 7.3 and < 7.3).
pdo_dblib
  • Implemented FR #69592 (allow 0-column rowsets to be skipped automatically).
  • Expose TDS version as \PDO::DBLIB_ATTR_TDS_VERSION attribute on \PDO instance.
  • Treat DATETIME2 columns like DATETIME.
  • Fixed bug #74243 (allow locales.conf to drive datetime format).
pdo_firebird
  • Fixed bug #74462 (PDO_Firebird returns only NULLs for results with boolean for FIREBIRD >= 3.0).
pdo_oci
  • Fixed bug #74631 (PDO_PCO with PHP-FPM: OCI environment initialized before PHP-FPM sets it up).
  • PDO SQLite
  • Add support for additional open flags
pgsql
  • Added new error constants for pg_result_error(): PGSQL_DIAG_SCHEMA_NAME, PGSQL_DIAG_TABLE_NAME, PGSQL_DIAG_COLUMN_NAME, PGSQL_DIAG_DATATYPE_NAME, PGSQL_DIAG_CONSTRAINT_NAME and PGSQL_DIAG_SEVERITY_NONLOCALIZED.
  • Fixed bug #77047 (pg_convert has a broken regex for the 'TIME WITHOUT TIMEZONE' data type).
phar
  • Fixed bug #74991 (include_path has a 4096 char limit in some cases).
  • Fixed bug #65414 (deal with leading slash when adding files correctly).
readline
  • Added completion_append_character and completion_suppress_append options to readline_info() if linked against libreadline.
session
  • Fixed bug #74941 (session fails to start after having headers sent).
simplexml
  • Fixed bug #54973 (SimpleXML casts integers wrong).
  • Fixed bug #76712 (Assignment of empty string creates extraneous text node).
sockets
  • Fixed bug #67619 (Validate length on socket_write).
soap
  • Fixed bug #75464 (Wrong reflection on SoapClient::__setSoapHeaders).
  • Fixed bug #70469 (SoapClient generates E_ERROR even if exceptions=1 is used).
  • Fixed bug #50675 (SoapClient can't handle object references correctly).
  • Fixed bug #76348 (WSDL_CACHE_MEMORY causes Segmentation fault).
  • Fixed bug #77141 (Signedness issue in SOAP when precision=-1).
spl
  • Fixed bug #74977 (Appending AppendIterator leads to segfault).
  • Fixed bug #75173 (incorrect behavior of AppendIterator::append in foreach loop).
  • Fixed bug #74372 (autoloading file with syntax error uses next autoloader, may hide parse error).
  • Fixed bug #75878 (RecursiveTreeIterator::setPostfix has wrong signature).
  • Fixed bug #74519 (strange behavior of AppendIterator).
  • Fixed bug #76131 (mismatch arginfo for splarray constructor).
sqlite3
  • Updated bundled libsqlite to 3.24.0.
standard
  • Added is_countable() function.
  • Added support for the SameSite cookie directive, including an alternative signature for setcookie(), setrawcookie() and session_set_cookie_params().
  • Remove superfluous warnings from inet_ntop()/inet_pton().
  • Fixed bug #75916 (DNS_CAA record results contain garbage).
  • Fixed unserialize(), to disable creation of unsupported data structures through manually crafted strings.
  • Fixed bug #75409 (accept EFAULT in addition to ENOSYS as indicator that getrandom() is missing).
  • Fixed bug #74719 (fopen() should accept NULL as context).
  • Fixed bug #69948 (path/domain are not sanitized in setcookie).
  • Fixed bug #75996 (incorrect url in header for mt_rand).
  • Added hrtime() function, to get high resolution time.
  • Fixed bug #48016 (stdClass::__setState is not defined although var_export() uses it).
  • Fixed bug #76136 (stream_socket_get_name should enclose IPv6 in brackets).
  • Fixed bug #76688 (Disallow excessive parameters after options array).
  • Fixed bug #76713 (Segmentation fault caused by property corruption).
  • Fixed bug #76755 (setcookie does not accept "double" type for expire time).
  • Fixed bug #76674 (improve array_* failure messages exposing what was passed instead of an array).
  • Fixed bug #76803 (ftruncate changes file pointer).
  • Fixed bug #76818 (Memory corruption and segfault).
  • Fixed bug #77081 (ftruncate() changes seek pointer in c mode).
testing
  • Implemented FR #62055 (Make run-tests.php support --CGI-- sections).
tidy
  • Support using tidyp instead of tidy.
  • Fixed bug #74707 (Tidy has incorrect ReflectionFunction param counts for functions taking tidy).
  • Fixed arginfo for tidy::__construct().
tokenizer
  • Fixed bug #76437 (token_get_all with TOKEN_PARSE flag fails to recognise close tag).
  • Fixed bug #75218 (Change remaining uncatchable fatal errors for parsing into ParseError).
  • Fixed bug #76538 (token_get_all with TOKEN_PARSE flag fails to recognise close tag with newline).
  • Fixed bug #76991 (Incorrect tokenization of multiple invalid flexible heredoc strings).
xml
  • Fixed bug #71592 (External entity processing never fails).
zlib
  • Added zlib/level context option for compress.zlib wrapper.
To Top