Home » Releases » 8.3 » 8.3.33 »

PHP 8.3.6

The latest release of PHP 8.3 is 8.3.33 which includes important security patches.

Source Code

  • PHP 8.3.6 (tar.gz)

    • sha256: 39695f5bd107892e36fd2ed6b3d3a78140fd4b05d556d6c6531a921633cacb5f
  • PHP 8.3.6 (tar.bz2)

    • sha256: 6324b1ddd8eb3025b041034b88dc2bc0b4819b0022129eeaeba37e47803108bc
  • PHP 8.3.6 (tar.xz)

    • sha256: 53c8386b2123af97626d3438b3e4058e0c5914cb74b048a6676c57ac647f5eae

Change Log

  • core

    • Fixed GH-13569 (GC buffer unnecessarily grows up to GC_MAX_BUF_SIZE when scanning WeakMaps).
      Arnaud
    • Fixed bug GH-13612 (Corrupted memory in destructor with weak references).
      nielsdos
    • Fixed bug GH-13446 (Restore exception handler after it finishes).
      ilutov
    • Fixed bug GH-13784 (AX_GCC_FUNC_ATTRIBUTE failure).
      Remi
    • Fixed bug GH-13670 (GC does not scale well with a lot of objects created in destructor).
      Arnaud
  • dom

    • Add some missing ZPP checks.
      nielsdos
    • Fix potential memory leak in XPath evaluation results.
      nielsdos
  • fpm

    • Fixed GH-11086 (FPM: config test runs twice in daemonised mode).
      Jakub Zelenka
    • Fixed incorrect check in fpm_shm_free().
      nielsdos
  • gd

    • Fixed bug GH-12019 (add GDLIB_CFLAGS in feature tests).
      Michael Orlitzky
  • gettext

    • Fixed sigabrt raised with dcgettext/dcngettext calls with gettext 0.22.5 with category set to LC_ALL.
      David Carlier
  • mysqlnd

    • Fix GH-13452 (Fixed handshake response [mysqlnd]).
      Saki Takamachi
    • Fix incorrect charset length in check_mb_eucjpms().
      nielsdos
  • opcache

    • Fixed GH-13508 (JITed QM_ASSIGN may be optimized out when op1 is null).
      Arnaud
      Dmitry
    • Fixed GH-13712 (Segmentation fault for enabled observers when calling trait method of internal trait when opcache is loaded).
      Bob
  • random

    • Fixed bug GH-13544 (Pre-PHP 8.2 compatibility for mt_srand with unknown modes).
      timwolla
    • Fixed bug GH-13690 (Global Mt19937 is not properly reset in-between requests when MT_RAND_PHP is used).
      timwolla
  • session

    • Fixed bug GH-13680 (Segfault with session_decode and compilation error).
      nielsdos
  • spl

    • Fixed bug GH-13685 (Unexpected null pointer in zend_string.h).
      nielsdos
  • standard

    • Fixed bug GH-11808 (Live filesystem modified by tests).
      nielsdos
    • Fixed GH-13402 (Added validation of `\n` in $additional_headers of mail()).
      SakiTakamachi
    • Fixed bug GH-13203 (file_put_contents fail on strings over 4GB on Windows).
      divinity76
    • Fixed bug GHSA-pc52-254m-w9w7 (Command injection via array-ish $command parameter of proc_open). (CVE-2024-1874)
      Jakub Zelenka
    • Fixed bug GHSA-wpj3-hf5j-x4v4 (__Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix). (CVE-2024-2756)
      nielsdos
    • Fixed bug GHSA-h746-cjrr-wfmr (password_verify can erroneously return true, opening ATO risk). (CVE-2024-3096)
      Jakub Zelenka
    • Fixed bug GHSA-fjp9-9hwx-59fq (mb_encode_mimeheader runs endlessly for some inputs). (CVE-2024-2757)
      Alex Dowad

PHP 8.3


  Represents a security release