Skip to content

Commit a2e765b

Browse files
committed
Announce PHP 8.5.11
1 parent 967eedf commit a2e765b

7 files changed

Lines changed: 216 additions & 10 deletions

File tree

‎include/release-qa.php‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -88,10 +88,10 @@
8888
'active' => true,
8989
'release' => [
9090
'type' => 'RC',
91-
'number' => 1,
92-
'sha256_bz2' => '24574eb0c8c1bceac833a5b984fcfb0cde50a019f6a757c35f28da3dc97300b9',
93-
'sha256_gz' => 'dd0a2dc233ee6dd6d8ef389b671fefc5cd0f49b859d16e53d875582c5e248bbb',
94-
'sha256_xz' => '84e5d0abc91f6b1f69de6c5ec5d3720124582417c7ce6c5df742dcbada179a82',
91+
'number' => 0,
92+
'sha256_bz2' => '',
93+
'sha256_gz' => '',
94+
'sha256_xz' => '',
9595
'date' => '10 September 2026',
9696
'baseurl' => 'https://downloads.php.net/~edorian/',
9797
],

‎include/releases.inc‎

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,43 @@
22
$OLDRELEASES = array (
33
8 =>
44
array (
5+
'8.5.10' =>
6+
array (
7+
'announcement' =>
8+
array (
9+
'English' => '/releases/8_5_10.php',
10+
),
11+
'tags' =>
12+
array (
13+
0 => '',
14+
),
15+
'date' => '27 Aug 2026',
16+
'source' =>
17+
array (
18+
0 =>
19+
array (
20+
'filename' => 'php-8.5.10.tar.gz',
21+
'name' => 'PHP 8.5.10 (tar.gz)',
22+
'sha256' => 'f5c0ac99b85b3d677de475c2e4f509f9b4f54663f3ee5a84d6d9481a521d4100',
23+
'date' => '27 Aug 2026',
24+
),
25+
1 =>
26+
array (
27+
'filename' => 'php-8.5.10.tar.bz2',
28+
'name' => 'PHP 8.5.10 (tar.bz2)',
29+
'sha256' => 'd79bd4f3a9248e5cb5833766ba0d51cd35dd01b8727f23f30bcdba6fabc51d3e',
30+
'date' => '27 Aug 2026',
31+
),
32+
2 =>
33+
array (
34+
'filename' => 'php-8.5.10.tar.xz',
35+
'name' => 'PHP 8.5.10 (tar.xz)',
36+
'sha256' => '6a8bebaa4d5a979a38db29a9373e9851f60c6b11f72172c585947e78f3081957',
37+
'date' => '27 Aug 2026',
38+
),
39+
),
40+
'museum' => false,
41+
),
542
'8.5.9' =>
643
array (
744
'announcement' =>

‎include/version.inc‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -20,15 +20,15 @@ $RELEASES = (function () {
2020

2121
/* PHP 8.5 Release */
2222
$data['8.5'] = [
23-
'version' => '8.5.10',
24-
'date' => '27 Aug 2026',
25-
'tags' => [''], // Set to ['security'] for security releases.
23+
'version' => '8.5.11',
24+
'date' => '24 Sep 2026',
25+
'tags' => ['security'], // Set to ['security'] for security releases.
2626
'sha256' => [
2727
// WARNING: Order of SHA256 entries here is DIFFERENT from the
2828
// order in the manifest
29-
'tar.gz' => 'f5c0ac99b85b3d677de475c2e4f509f9b4f54663f3ee5a84d6d9481a521d4100',
30-
'tar.bz2' => 'd79bd4f3a9248e5cb5833766ba0d51cd35dd01b8727f23f30bcdba6fabc51d3e',
31-
'tar.xz' => '6a8bebaa4d5a979a38db29a9373e9851f60c6b11f72172c585947e78f3081957',
29+
'tar.gz' => '338630ba9450f0b938bef8d740162c61c33bf64a1b421c6333c01df8a9fdb0ab',
30+
'tar.bz2' => 'dc940716a8c73e531c0078eecb955d595d321ec2cc9d47149cf0089ea6e18f64',
31+
'tar.xz' => 'd9be75c08e8c316f4c8f4194d8fbe1750a15f6a6d9d4e3fe72082abeeb800360',
3232
]
3333
];
3434

‎public/ChangeLog-8.php‎

Lines changed: 131 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,137 @@
99

1010
<a id="PHP_8_5"></a>
1111

12+
<section class="version" id="8.5.11"><!-- {{{ 8.5.11 -->
13+
<h3>Version 8.5.11</h3>
14+
<b><?php release_date('24-Sep-2026'); ?></b>
15+
<ul><li>BCMath:
16+
<ul>
17+
<li>Fixed out-of-bounds read in bc_is_zero_for_scale() when scale exceeds n_scale.</li>
18+
</ul></li>
19+
<li>Core:
20+
<ul>
21+
<li>Fixed out-of-bounds reads during automatic UTF-16/32 encoding detection.</li>
22+
<li>Fixed bug <?php githubissuel('php/php-src', 15375); ?> (Nested "yield from" skips items after a valid() or next() call on the inner generator).</li>
23+
<li>Fixed bug <?php githubissuel('php/php-src', 23232); ?> (lone namespace separator asks the autoloader for an empty class name).</li>
24+
<li>Fixed bug <?php githubissuel('php/php-src', 23301); ?> (Nested "yield from" yields a value twice when the middle generator delegates again).</li>
25+
</ul></li>
26+
<li>DOM:
27+
<ul>
28+
<li>Fixed NamedNodeMap::getNamedItemNS() with an empty URI not matching the null namespace in spec-following mode.</li>
29+
<li>Fixed stale getElementsByClassName() and other node list caches after className/classList writes and attribute removals.</li>
30+
<li>Fixed a use-after-free when cloning a DOMNameSpaceNode after DOMDocument::xinclude().</li>
31+
<li>Fixed a crash in DOMXPath when a php:function callback receives a nodeset and a later callback returns a node from another document.</li>
32+
<li>Fixed bug <?php githubissuel('php/php-src', 23331); ?> (UAF when node_list_unlink() skips attribute children that still have a live wrapper).</li>
33+
<li>Fixed a use-after-free when Dom\Element::setAttributeNS() replaces the value of an attribute whose child still has a live wrapper.</li>
34+
</ul></li>
35+
<li>GD:
36+
<ul>
37+
<li>Fixed imageaffinematrixget() and imageaffinematrixconcat() reporting the wrong argument in error messages.</li>
38+
</ul></li>
39+
<li>FPM:
40+
<ul>
41+
<li>Fixed bug <?php githubissuel('php/php-src', 19320); ?> (FPM UID and GID overflow).</li>
42+
<li>Fixed <?php githubsecurityl('php/php-src', '62xp-839h-2637'); ?> (IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison). (CVE-2026-91768)</li>
43+
</ul></li>
44+
<li>Intl:
45+
<ul>
46+
<li>Fixed grapheme_strpos() and grapheme_strrpos() with an empty needle returning UTF-16 offsets instead of grapheme offsets.</li>
47+
<li>Fixed a memory leak when dumping IntlCalendar instances.</li>
48+
<li>Fixed a memory leak when iterating IntlBreakIterator::getPartsIterator() results.</li>
49+
<li>Fixed a double-free when IntlGregorianCalendar construction fails after the ICU constructor adopts the TimeZone.</li>
50+
<li>Fixed bug <?php githubissuel('php/php-src', 23094); ?> (NumberFormatter parsing offsets use UTF-16 positions for UTF-8 strings).</li>
51+
<li>Fixed Locale::parseLocale() reading past a trailing '-' or '_'.</li>
52+
<li>Fixed grapheme_str_split() treating UBRK_DONE as a byte index.</li>
53+
<li>Fixed a leak in Locale::getKeywords() when a keyword value cannot be read.</li>
54+
<li>Fixed a use-after-free when IntlRuleBasedBreakIterator is constructed from compiled rules.</li>
55+
</ul></li>
56+
<li>MBString:
57+
<ul>
58+
<li>Fixed mb_ereg_replace() emitting a NUL or out-of-bounds bytes in the replacement when a \k&lt;name&gt; backref has no closing delimiter.</li>
59+
</ul></li>
60+
<li>MySQLnd:
61+
<ul>
62+
<li>Fixed <?php githubsecurityl('php/php-src', 'r6x9-5r99-36j7'); ?> (Various packet overreads in mysqlnd wire protocol). (CVE-2025-1218)</li>
63+
</ul></li>
64+
<li>ODBC:
65+
<ul>
66+
<li>Fixed odbc_field_len(), odbc_field_scale() and odbc_field_type() returning uninitialized memory when SQLColAttribute fails.</li>
67+
</ul></li>
68+
<li>Opcache:
69+
<ul>
70+
<li>Fixed opcache.protect_memory race under ZTS.</li>
71+
<li>Fixed a tracing JIT crash when compiling a side trace for a method of a class that could not be stored in the inheritance cache.</li>
72+
<li>Fixed a crash when the huge page SHM remap discarded mappings outside the reserved address range.</li>
73+
</ul></li>
74+
<li>OpenSSL:
75+
<ul>
76+
<li>Fixed <?php githubsecurityl('php/php-src', 'vvx9-73fr-5jjx'); ?> (TLS hostname verification falls back to CN after SAN mismatch). (CVE-2026-91769)</li>
77+
<li>Fixed <?php githubsecurityl('php/php-src', 'xr7j-rvgx-xq5p'); ?> (Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN). (CVE-2026-91767)</li>
78+
</ul></li>
79+
<li>PDO:
80+
<ul>
81+
<li>Fixed a leak when a persistent connection failed a liveness check with no other live PDO handle.</li>
82+
</ul></li>
83+
<li>PDO_PGSQL:
84+
<ul>
85+
<li>Fixed PDO::CURSOR_SCROLL statements failing under lazy fetching (PDO::ATTR_PREFETCH =&gt; 0).</li>
86+
</ul></li>
87+
<li>PDO Sqlite:
88+
<ul>
89+
<li>Fixed bug <?php githubissuel('php/php-src', 20214); ?> (PDO::FETCH_DEFAULT unexpected behavior with PDOStatement::setFetchMode).</li>
90+
</ul></li>
91+
<li>Phar:
92+
<ul>
93+
<li>Fixed bug <?php githubissuel('php/php-src', 23418); ?> (Use-after-free when looking up mounted directories).</li>
94+
<li>Fixed bug <?php githubissuel('php/php-src', 23477); ?> (Memory leak on duplicate native Phar manifest entries).</li>
95+
<li>Fixed <?php githubsecurityl('php/php-src', 'j3wh-g957-2m85'); ?> (Integer overflow in phar_tar_number() allowing TAR archive entry injection). (CVE-2026-6103)</li>
96+
</ul></li>
97+
<li>Readline:
98+
<ul>
99+
<li>Fixed the interactive shell not waiting for the pager process to exit.</li>
100+
</ul></li>
101+
<li>SOAP:
102+
<ul>
103+
<li>Fixed WSDL cache corruption when a soap:header defines headerfaults.</li>
104+
<li>Fixed stack overflow when parsing a WSDL with self-referential schema groups or attributeGroups.</li>
105+
<li>Fixed <?php githubsecurityl('php/php-src', 'rgrp-mwpx-f6rm'); ?> (Unbounded recursion in server-side cleanup_xml_node()). (CVE-2026-91765)</li>
106+
<li>Fixed <?php githubsecurityl('php/php-src', 'cj93-vc83-wgqv'); ?> (Integer overflow to buffer overflow in SOAP HTTP parsing). (CVE-2025-14181)</li>
107+
</ul></li>
108+
<li>Standard:
109+
<ul>
110+
<li>Fixed a segfault when a stream filter callback unsets StreamBucket::$data before re-attaching the bucket.</li>
111+
<li>Fixed <?php githubsecurityl('php/php-src', '7875-c8px-7q5f'); ?> (Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header). (CVE-2026-93682)</li>
112+
<li>Fixed read buffer compaction in php_stream_filter_flush().</li>
113+
<li>Fixed bug <?php githubissuel('php/php-src', 22410); ?> (Incorrect float behavior with large numbers).</li>
114+
<li>Fixed <?php githubissuel('php/php-src', 23338); ?> (fsockopen()/pfsockopen() ValueError reported wrong argument number for $timeout).</li>
115+
<li>Fixed bug <?php githubissuel('php/php-src', 23576); ?> (Next index for array returned from array_keys() is wrong).</li>
116+
<li>Fixed <?php githubsecurityl('php/php-src', '88hq-2827-7pg6'); ?> (Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL). (CVE-2026-92842)</li>
117+
<li>Fixed <?php githubsecurityl('php/php-src', 'fpwc-w8rq-cr92'); ?> (Cross-origin credential leak in HTTP stream wrapper redirects). (CVE-2026-91766)</li>
118+
</ul></li>
119+
<li>SimpleXML:
120+
<ul>
121+
<li>Fixed writing to a dimension of the object returned by attributes() not creating the attribute.</li>
122+
<li>Fixed child elements of the element returned by SimpleXMLElement::addChild() not being accessible by property name when namespaces are involved.</li>
123+
</ul></li>
124+
<li>Windows:
125+
<ul>
126+
<li>Fixed <?php githubsecurityl('php/php-src', '9f67-6fw4-hpfp'); ?> (Reserved device names are not rejected before file and stream I/O). (CVE-2026-17545)</li>
127+
</ul></li>
128+
<li>Zip:
129+
<ul>
130+
<li>Fixed bug <?php githubissuel('php/php-src', 17787); ?> (ZipArchive stream stops reading early when the archive is freed while the stream is still open).</li>
131+
<li>Fixed bug <?php githubissuel('php/php-src', 23276); ?> (ZipArchive subclass storing its own stream cannot be garbage collected).</li>
132+
</ul></li>
133+
<li>SAPI:
134+
<ul>
135+
<li>Fixed fuzzer targets failing to build in isolation.</li>
136+
<li>Fixed returns uninitialized value on LiteSpeed lsapi SAPI (Go Kudo)</li>
137+
</ul></li>
138+
</ul>
139+
<!-- }}} --></section>
140+
141+
142+
12143
<section class="version" id="8.5.10"><!-- {{{ 8.5.10 -->
13144
<h3>Version 8.5.10</h3>
14145
<b><?php release_date('27-Aug-2026'); ?></b>

‎public/archive/archive.xml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@
99
<uri>http://php.net/contact</uri>
1010
<email>php-webmaster@lists.php.net</email>
1111
</author>
12+
<xi:include href="entries/2026-09-24-3.xml"/>
1213
<xi:include href="entries/2026-09-24-2.xml"/>
1314
<xi:include href="entries/2026-09-24-1.xml"/>
1415
<xi:include href="entries/2026-09-11-1.xml"/>
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
<?xml version="1.0" encoding="utf-8"?>
2+
<entry xmlns="http://www.w3.org/2005/Atom">
3+
<title>PHP 8.5.11 Released!</title>
4+
<id>https://www.php.net/archive/2026.php#2026-09-24-3</id>
5+
<published>2026-09-24T11:40:51+00:00</published>
6+
<updated>2026-09-24T11:40:51+00:00</updated>
7+
<link href="https://www.php.net/index.php#2026-09-24-3" rel="alternate" type="text/html"/>
8+
<link href="https://www.php.net/archive/2026.php#2026-09-24-3" rel="via" type="text/html"/>
9+
<category term="releases" label="New PHP release"/>
10+
<category term="frontpage" label="PHP.net frontpage news"/>
11+
<content type="xhtml">
12+
<div xmlns="http://www.w3.org/1999/xhtml"><p>The PHP development team announces the immediate availability of PHP 8.5.11. This is a security release.</p>
13+
14+
<p>All PHP 8.5 users are encouraged to upgrade to this version.</p>
15+
16+
<p>For source downloads of PHP 8.5.11 please visit our <a href="https://www.php.net/downloads.php">downloads page</a>,
17+
Windows source and binaries can also be found <a href="https://www.php.net/downloads.php?os=windows&amp;version=8.5">there</a>.
18+
The list of changes is recorded in the <a href="https://www.php.net/ChangeLog-8.php#8.5.11">ChangeLog</a>.
19+
</p> </div>
20+
</content>
21+
</entry>

‎public/releases/8_5_11.php‎

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
<?php
2+
$_SERVER['BASE_PAGE'] = 'releases/8_5_11.php';
3+
require_once __DIR__ . '/../../include/prepend.inc';
4+
site_header('PHP 8.5.11 Release Announcement', ['cache' => true, 'cache_control' => 30 * 60]);
5+
?>
6+
<h1>PHP 8.5.11 Release Announcement</h1>
7+
8+
<p>The PHP development team announces the immediate availability of PHP 8.5.11. This is a security release.</p>
9+
10+
<p>All PHP 8.5 users are encouraged to upgrade to this version.</p>
11+
12+
<p>For source downloads of PHP 8.5.11 please visit our <a href="https://www.php.net/downloads.php">downloads page</a>,
13+
Windows source and binaries can also be found <a href="https://www.php.net/downloads.php?os=windows&amp;version=8.5">there</a>.
14+
The list of changes is recorded in the <a href="https://www.php.net/ChangeLog-8.php#8.5.11">ChangeLog</a>.
15+
</p>
16+
<?php site_footer();

0 commit comments

Comments
 (0)