본문 바로가기
← PHP 소식
PHP 8.2.20보안

PHP 8.2.20 변경 기록과 적용 점검

릴리스: 2024년 6월 6일

게시: 2026년 8월 6일

PHP 8.2.20 공식 변경 기록에서 구성요소와 CVE를 추출하고 사용 환경별 확인 순서를 제공합니다.

PHP 8.2.20 변경 사항

공식 php-src 태그의 NEWS에서 이 버전의 항목만 추출했습니다. 아래 구성요소와 확인 순서는 원문에 따라 자동 구성됩니다. 애플리케이션 호환성이나 취약점 영향 여부를 판정하지 않습니다.

변경된 구성요소

CGI · CLI · Core · DOM · FFI · Filter · FPM · Hash · Intl · Ini · MySQLnd · Opcache · OpenSSL · Standard · XML · XMLReader

원문에 명시된 CVE

사용 환경별 확인 순서

  • php -vphp -m으로 실제 실행 버전과 확장 목록을 확인하고 아래 원문에서 사용 중인 구성요소의 변경을 찾으세요.
  • composer check-platform-reqs로 설치 환경의 요구사항을 확인하세요. 성공하더라도 동작 호환성까지 보장하지는 않습니다.
  • PHP-FPM을 사용한다면 스테이징에서 프로세스 재시작과 오류 로그를 확인하세요.
  • TLS 연결을 사용한다면 외부 API·메일 서버 연결과 인증서 검증을 점검하세요.
  • 배포 전 스테이징에서 애플리케이션 테스트를 실행하고, 배포 후 웹 프로세스와 큐 워커가 새 PHP를 사용하는지 확인하세요.

공식 변경 기록

06 Jun 2024, PHP 8.2.20

  • CGI: . Fixed buffer limit on Windows, replacing read call usage by _read. (David Carlier) . Fixed bug GHSA-3qgc-jrrr-25jv (Bypass of CVE-2012-1823, Argument Injection in PHP-CGI). (CVE-2024-4577) (nielsdos)

  • CLI: . Fixed bug GH-14189 (PHP Interactive shell input state incorrectly handles quoted heredoc literals.). (nielsdos)

  • Core: . Fixed bug GH-13970 (Incorrect validation of #[Attribute] flags type for non-compile-time expressions). (ilutov) . Fixed bug GH-14140 (Floating point bug in range operation on Apple Silicon hardware). (Derick, Saki)

  • DOM: . Fix crashes when entity declaration is removed while still having entity references. (nielsdos) . Fix references not handled correctly in C14N. (nielsdos) . Fix crash when calling childNodes next() when iterator is exhausted. (nielsdos) . Fix crash in ParentNode::append() when dealing with a fragment containing text nodes. (nielsdos)

  • FFI: . Fixed bug GH-14215 (Cannot use FFI::load on CRLF header file with apache2handler). (nielsdos)

  • Filter: . Fixed bug GHSA-w8qr-v226-r27w (Filter bypass in filter_var FILTER_VALIDATE_URL). (CVE-2024-5458) (nielsdos)

  • FPM: . Fix bug GH-14175 (Show decimal number instead of scientific notation in systemd status). (Benjamin Cremer)

  • Hash: . ext/hash: Swap the checking order of __has_builtin and __GNUC__ (Saki Takamachi)

  • Intl: . Fixed build regression on systems without C++17 compilers. (Calvin Buckley, Peter Kokot)

  • Ini: . Fixed bug GH-14100 (Corrected spelling mistake in php.ini files). (Marcus Xavier)

  • MySQLnd: . Fix bug GH-14255 (mysqli_fetch_assoc reports error from nested query). (Kamil Tekiela)

  • Opcache: . Fixed bug GH-14109 (Fix accidental persisting of internal class constant in shm). (ilutov)

  • OpenSSL: . The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https://github.com/openssl/openssl/pull/13817 (rsa_pkcs1_implicit_rejection). These changes are part of OpenSSL 3.2 and have also been backported to stable versions of various Linux distributions, as well as to the PHP builds provided for Windows since the previous release. All distributors and builders should ensure that this version is used to prevent PHP from being vulnerable. (CVE-2024-2408)

  • Standard: . Fixed bug GHSA-9fcc-425m-g385 (Bypass of CVE-2024-1874). (CVE-2024-5585) (nielsdos)

  • XML: . Fixed bug GH-14124 (Segmentation fault with XML extension under certain memory limit). (nielsdos)

  • XMLReader: . Fixed bug GH-14183 (XMLReader::open() can't be overridden). (nielsdos)

출처

PHP 8.2.20 공식 NEWS · 현재 PHP 지원 일정

원문에 없는 지원 종료일, CVE, Laravel 호환성 결론은 자동으로 추가하지 않습니다.

php.net 공식 릴리스 노트 보기 →