This Release is Outdated
The latest release of PHP 8.3 is PHP
8.3.31
.
It is recommended to upgrade to the latest release.
PHP 8.3.6 Release Announcement
The PHP development team announces the immediate availability of PHP 8.3.6. This is a security release.
All PHP 8.3 users are encouraged to upgrade to this version.
For source downloads of PHP 8.3.6 please visit our downloads page,
Windows source and binaries can be found on windows.php.net/download/.
The list of changes is recorded in the ChangeLog.
Source Code
-
PHP 8.3.6 (tar.gz)
sha256: 39695f5bd107892e36fd2ed6b3d3a78140fd4b05d556d6c6531a921633cacb5f
-
PHP 8.3.6 (tar.bz2)
sha256: 6324b1ddd8eb3025b041034b88dc2bc0b4819b0022129eeaeba37e47803108bc
-
PHP 8.3.6 (tar.xz)
sha256: 53c8386b2123af97626d3438b3e4058e0c5914cb74b048a6676c57ac647f5eae
Change Log
-
core
- Fixed GH-13569 (GC buffer unnecessarily grows up to GC_MAX_BUF_SIZE when scanning WeakMaps).
- Fixed bug GH-13612 (Corrupted memory in destructor with weak references).
- Fixed bug GH-13446 (Restore exception handler after it finishes).
- Fixed bug GH-13784 (AX_GCC_FUNC_ATTRIBUTE failure).
- Fixed bug GH-13670 (GC does not scale well with a lot of objects created in destructor).
-
dom
- Add some missing ZPP checks.
- Fix potential memory leak in XPath evaluation results.
-
fpm
- Fixed GH-11086 (FPM: config test runs twice in daemonised mode).
- Fixed incorrect check in fpm_shm_free().
-
gd
- Fixed bug GH-12019 (add GDLIB_CFLAGS in feature tests).
-
gettext
- Fixed sigabrt raised with dcgettext/dcngettext calls with gettext 0.22.5 with category set to LC_ALL.
-
mysqlnd
- Fix GH-13452 (Fixed handshake response [mysqlnd]).
- Fix incorrect charset length in check_mb_eucjpms().
-
opcache
- Fixed GH-13508 (JITed QM_ASSIGN may be optimized out when op1 is null).
- Fixed GH-13712 (Segmentation fault for enabled observers when calling trait method of internal trait when opcache is loaded).
-
random
- Fixed bug GH-13544 (Pre-PHP 8.2 compatibility for mt_srand with unknown modes).
- Fixed bug GH-13690 (Global Mt19937 is not properly reset in-between requests when MT_RAND_PHP is used).
-
session
- Fixed bug GH-13680 (Segfault with session_decode and compilation error).
-
spl
- Fixed bug GH-13685 (Unexpected null pointer in zend_string.h).
-
standard
- Fixed bug GH-11808 (Live filesystem modified by tests).
- Fixed GH-13402 (Added validation of `\n` in $additional_headers of mail()).
- Fixed bug GH-13203 (file_put_contents fail on strings over 4GB on Windows).
- Fixed bug GHSA-pc52-254m-w9w7 (Command injection via array-ish $command parameter of proc_open). (CVE-2024-1874)
- Fixed bug GHSA-wpj3-hf5j-x4v4 (__Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix). (CVE-2024-2756)
- Fixed bug GHSA-h746-cjrr-wfmr (password_verify can erroneously return true, opening ATO risk). (CVE-2024-3096)
- Fixed bug GHSA-fjp9-9hwx-59fq (mb_encode_mimeheader runs endlessly for some inputs). (CVE-2024-2757)