The latest release of PHP 8.2 is
8.2.33 which includes important security patches.
Source Code
Change Log
-
core
-
Fixed bug
GH-13612 (Corrupted memory in destructor with weak references).
-
Fixed bug
GH-13784 (AX_GCC_FUNC_ATTRIBUTE failure).
-
Fixed bug
GH-13670 (GC does not scale well with a lot of objects created in destructor).
-
dom
-
Add some missing ZPP checks.
-
Fix potential memory leak in XPath evaluation results.
-
Fix phpdoc for DOMDocument load methods.
-
fpm
-
gd
-
Fixed bug
GH-12019 (add GDLIB_CFLAGS in feature tests).
-
gettext
-
mysqlnd
-
opcache
-
Fixed
GH-13508 (JITed QM_ASSIGN may be optimized out when op1 is null).
-
Fixed
GH-13712 (Segmentation fault for enabled observers when calling trait method of internal trait when opcache is loaded).
-
pdo
-
random
-
Fixed bug
GH-13544 (Pre-PHP 8.2 compatibility for mt_srand with unknown modes).
-
Fixed bug
GH-13690 (Global Mt19937 is not properly reset in-between requests when MT_RAND_PHP is used).
-
session
-
Fixed bug
GH-13680 (Segfault with session_decode and compilation error).
-
sockets
-
Fixed bug
GH-13604 (socket_getsockname returns random characters in the end of the socket name).
-
spl
-
Fixed bug
GH-13531 (Unable to resize SplfixedArray after being unserialized in PHP 8.2.15).
-
Fixed bug
GH-13685 (Unexpected null pointer in zend_string.h).
-
standard
-
Fixed bug
GH-11808 (Live filesystem modified by tests).
-
Fixed
GH-13402 (Added validation of `\n` in $additional_headers of mail()).
-
Fixed bug
GH-13203 (file_put_contents fail on strings over 4GB on Windows).
-
Fixed bug
GHSA-pc52-254m-w9w7 (Command injection via array-ish $command parameter of proc_open). (CVE-2024-1874)
-
Fixed bug
GHSA-wpj3-hf5j-x4v4 (__Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix). (CVE-2024-2756)
-
Fixed bug
GHSA-h746-cjrr-wfmr (password_verify can erroneously return true, opening ATO risk). (CVE-2024-3096)
-
xml
-
Fixed bug
GH-13517 (Multiple test failures when building with --with-expat).