Commit 9c20c86bcc9 for php

commit 9c20c86bcc94b5974310a0246e460994ec876522
Merge: be4e9ee7198 08a49a92256
Author: Ilia Alshanetsky <ilia@ilia.ws>
Date:   Wed Sep 30 08:50:46 2026 -0400

    Merge branch 'PHP-8.4' into PHP-8.5

    * PHP-8.4:
      Fix HashTable UAF when rebound from a parameter __toString()

diff --cc ext/pdo/php_pdo_driver.h
index 9c5986ff8bc,3f9ef4e214d..6b09e861fed
--- a/ext/pdo/php_pdo_driver.h
+++ b/ext/pdo/php_pdo_driver.h
@@@ -576,8 -566,21 +576,9 @@@ struct _pdo_stmt_t
  	/* if true, the statement supports placeholders and can implement
  	 * bindParam() for its prepared statements, if false, PDO should
  	 * emulate prepare and bind on its behalf */
 -	unsigned supports_placeholders:2;
 -	unsigned in_param_event:1;
 -
 -	unsigned _reserved:28;
 -
 -	/* the number of columns in the result set; not valid until after
 -	 * the statement has been executed at least once.  In some cases, might
 -	 * not be valid until fetch (at the driver level) has been called at least once.
 -	 * */
 -	int column_count;
 -	struct pdo_column_data *columns;
 -
 -	/* we want to keep the dbh alive while we live, so we own a reference */
 -	zval database_object_handle;
 -	pdo_dbh_t *dbh;
 +	uint16_t supports_placeholders:2;
- 	uint16_t reserved: 12;
++	uint16_t in_param_event:1;
++	uint16_t reserved: 11;

  	/* keep track of bound input parameters.  Some drivers support
  	 * input/output parameters, but you can't rely on that working */