본문 바로가기
← PHP 소식
PHP 8.3.19보안

PHP 8.3.19 변경 기록과 적용 점검

릴리스: 2025년 3월 13일

게시: 2026년 8월 6일

PHP 8.3.19 공식 변경 기록에서 구성요소와 CVE를 추출하고 사용 환경별 확인 순서를 제공합니다.

PHP 8.3.19 변경 사항

공식 php-src 태그의 NEWS에서 이 버전의 항목만 추출했습니다. 아래 구성요소와 확인 순서는 원문에 따라 자동 구성됩니다. 애플리케이션 호환성이나 취약점 영향 여부를 판정하지 않습니다.

변경된 구성요소

BCMath · Core · DOM · FFI · FPM · GD · LDAP · LibXML · MBString · Opcache · PDO_SQLite · Phar · PHPDBG · Reflection · Standard · Streams · Windows · Zlib

원문에 명시된 CVE

사용 환경별 확인 순서

  • php -vphp -m으로 실제 실행 버전과 확장 목록을 확인하고 아래 원문에서 사용 중인 구성요소의 변경을 찾으세요.
  • composer check-platform-reqs로 설치 환경의 요구사항을 확인하세요. 성공하더라도 동작 호환성까지 보장하지는 않습니다.
  • PHP-FPM을 사용한다면 스테이징에서 프로세스 재시작과 오류 로그를 확인하세요.
  • PDO를 사용한다면 실제 데이터베이스 드라이버로 조회·트랜잭션 테스트를 실행하세요.
  • GD를 사용한다면 이미지 업로드·리사이즈 처리를 실제 파일로 확인하세요.
  • BCMath를 사용한다면 금액·정밀도·부호 경계값의 계산 결과를 확인하세요.
  • 배포 전 스테이징에서 애플리케이션 테스트를 실행하고, 배포 후 웹 프로세스와 큐 워커가 새 PHP를 사용하는지 확인하세요.

공식 변경 기록

13 Mar 2025, PHP 8.3.19

  • BCMath: . Fixed bug GH-17398 (bcmul memory leak). (SakiTakamachi)

  • Core: . Fixed bug GH-17623 (Broken stack overflow detection for variable compilation). (ilutov) . Fixed bug GH-17618 (UnhandledMatchError does not take zend.exception_ignore_args=1 into account). (timwolla) . Fix fallback paths in fast_long_{add,sub}_function. (nielsdos) . Fixed bug GH-17718 (Calling static methods on an interface that has __callStatic is allowed). (timwolla) . Fixed bug GH-17797 (zend_test_compile_string crash on invalid script path). (David Carlier) . Fixed GHSA-rwp7-7vc6-8477 (Reference counting in php_request_shutdown causes Use-After-Free). (CVE-2024-11235) (ilutov)

  • DOM: . Fixed bug GH-17847 (xinclude destroys live node). (nielsdos)

  • FFI: . Fix FFI Parsing of Pointer Declaration Lists. (davnotdev)

  • FPM: . Fixed bug GH-17643 (FPM with httpd ProxyPass encoded PATH_INFO env). (Jakub Zelenka)

  • GD: . Fixed bug GH-17772 (imagepalettetotruecolor crash with memory_limit=2M). (David Carlier)

  • LDAP: . Fixed bug GH-17704 (ldap_search fails when $attributes contains a non-packed array with numerical keys). (nielsdos, 7u83)

  • LibXML: . Fixed GHSA-wg4p-4hqh-c3g9 (Reocurrence of #72714). (nielsdos) . Fixed GHSA-p3x9-6h7p-cgfc (libxml streams use wrong content-type header when requesting a redirected resource). (CVE-2025-1219) (timwolla)

  • MBString: . Fixed bug GH-17503 (Undefined float conversion in mb_convert_variables). (cmb)

  • Opcache: . Fixed bug GH-17654 (Multiple classes using same trait causes function JIT crash). (nielsdos) . Fixed bug GH-17577 (JIT packed type guard crash). (nielsdos, Dmitry) . Fixed bug GH-17899 (zend_test_compile_string with invalid path when opcache is enabled). (David Carlier) . Fixed bug GH-17868 (Cannot allocate memory with tracing JIT). (nielsdos)

  • PDO_SQLite: . Fixed GH-17837 ()::getColumnMeta() on unexecuted statement segfaults). (cmb) . Fix cycle leak in sqlite3 setAuthorizer(). (nielsdos)

  • Phar: . Fixed bug GH-17808: PharFileInfo refcount bug. (nielsdos)

  • PHPDBG: . Partially fixed bug GH-17387 (Trivial crash in phpdbg lexer). (nielsdos) . Fix memory leak in phpdbg calling registered function. (nielsdos)

  • Reflection: . Fixed bug GH-15902 (Core dumped in ext/reflection/php_reflection.c). (DanielEScherzer)

  • Standard: . Fixed bug #72666 (stat cache clearing inconsistent between file:// paths and plain paths). (Jakub Zelenka)

  • Streams: . Fixed bug GH-17650 (realloc with size 0 in user_filters.c). (nielsdos) . Fix memory leak on overflow in _php_stream_scandir(). (nielsdos) . Fixed GHSA-hgf54-96fm-v528 (Stream HTTP wrapper header check might omit basic auth header). (CVE-2025-1736) (Jakub Zelenka) . Fixed GHSA-52jp-hrpf-2jff (Stream HTTP wrapper truncate redirect location to 1024 bytes). (CVE-2025-1861) (Jakub Zelenka) . Fixed GHSA-pcmh-g36c-qc44 (Streams HTTP wrapper does not fail for headers without colon). (CVE-2025-1734) (Jakub Zelenka) . Fixed GHSA-v8xr-gpvj-cx9g (Header parser of http stream wrapper does not handle folded headers). (CVE-2025-1217) (Jakub Zelenka)

  • Windows: . Fixed phpize for Windows 11 (24H2). (bwoebi) . Fixed GH-17855 (CURL_STATICLIB flag set even if linked with shared lib). (cmb)

  • Zlib: . Fixed bug GH-17745 (zlib extension incorrectly handles object arguments). (nielsdos) . Fix memory leak when encoding check fails. (nielsdos) . Fix zlib support for large files. (nielsdos)

출처

PHP 8.3.19 공식 NEWS · 현재 PHP 지원 일정

원문에 없는 지원 종료일, CVE, Laravel 호환성 결론은 자동으로 추가하지 않습니다.

php.net 공식 릴리스 노트 보기 →