[CLSA-2026:1779209104] Fix of 7 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-19 16:45:09 UTC
Description:
* SECURITY UPDATE: soap extension use-after-free via apache:Map duplicate keys - debian/patches/php-8.1-CVE-2026-6722.patch: backport upstream commit aee3b3ac9b in ext/soap/php_encoding.c — add Z_TRY_ADDREF_P on soap_add_xml_ref insertion and change SOAP_GLOBAL(ref_map) destructor to ZVAL_PTR_DTOR. - CVE-2026-6722 * SECURITY UPDATE: pdo_firebird SQL injection via NUL bytes in quoted strings - debian/patches/php-8.1-CVE-2025-14179.patch: backport upstream commit 3f40b65323 in ext/pdo_firebird/firebird_driver.c — replace strncat/strncpy/strcpy in preprocess() with memcpy plus explicit length tracking. - CVE-2025-14179 * SECURITY UPDATE: soap extension NULL pointer dereference via apache:Map item missing element - debian/patches/php-8.1-CVE-2026-7262.patch: backport upstream commit 79551ab8b1 in ext/soap/php_encoding.c — fix typo'd null check in to_zval_map() (was checking xmlKey, should check xmlValue). - CVE-2026-7262 * SECURITY UPDATE: php-fpm status endpoint XSS via unescaped request_uri - debian/patches/php-8.1-CVE-2026-6735.patch: backport upstream commit 99a5ad7441 in sapi/fpm/fpm/fpm_status.c — escape proc->request_uri with php_escape_html_entities_ex() / php_json_encode_string() and fix the broken "ENT_HTML_IGNORE_ERRORS & ENT_COMPAT" flag (bitwise- AND of two flag constants evaluates to 0). Applies with line offsets only against PHP 8.1.34. - CVE-2026-6735 * SECURITY UPDATE: mbstring NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() - debian/patches/php-8.1-CVE-2026-7259.patch: backport upstream commit 79a054eae0 in ext/mbstring/php_mbregex.c — resolve the mbfl encoding before storing it in MBREX(current_mbctype_mbfl_encoding) and return FAILURE if NULL (encodings supported by Oniguruma but not mbfl such as iso-8859-11, UJIS, KOI8-R). - CVE-2026-7259 * SECURITY UPDATE: soap SoapServer use-after-free after header parsing failure when SOAP_PERSISTENCE_SESSION is set - debian/patches/php-8.1-CVE-2026-7261.patch: backport upstream commit db2a7f9348 in ext/soap/soap.c — guard both zval_ptr_dtor(soap_obj) call sites in PHP_METHOD(SoapServer, handle) with "if (service->soap_class.persistence != SOAP_PERSISTENCE_SESSION)". Adapted to 8.1's fault path (extra zend_string_release(fn_name) before each dtor). - CVE-2026-7261 * SECURITY UPDATE: metaphone() signed integer overflow on >INT_MAX input - debian/patches/php-8.1-CVE-2026-7568.patch: backport upstream commit 47def8ce1d in ext/standard/metaphone.c — retype w_idx and Lookahead's how_far/idx from int to size_t to avoid signed overflow while walking strings larger than 2 GB on 64-bit builds. - CVE-2026-7568
Updated packages:
  • alt-php81_8.1.34-13_amd64.deb
    sha:9ba16aaedae441af6346cfcffc347898fbb2a09e
  • alt-php81-bcmath_8.1.34-13_amd64.deb
    sha:42a0fa01b23e7b2482b3db3afbdd55a5c5c452da
  • alt-php81-cli_8.1.34-13_amd64.deb
    sha:f708fdb322a7d689f5b80bd3458ffe802513f790
  • alt-php81-common_8.1.34-13_amd64.deb
    sha:b7120e4eb7a97f10294e5a22349959db70ecb2a6
  • alt-php81-dba_8.1.34-13_amd64.deb
    sha:1b2578eeb1615f337d8774c9a361782104387319
  • alt-php81-dev_8.1.34-13_amd64.deb
    sha:70f71c908d65d8013d39dd69028f5833daabddd0
  • alt-php81-enchant_8.1.34-13_amd64.deb
    sha:e6e1f027780193c0471449044cdecfe86363b3e9
  • alt-php81-firebird_8.1.34-13_amd64.deb
    sha:6ceb4cbef70aa0b11dcee2d79625d1d1fe439417
  • alt-php81-fpm_8.1.34-13_amd64.deb
    sha:d986a0b5f8c4799ad073e9008105dd3259150b46
  • alt-php81-gd_8.1.34-13_amd64.deb
    sha:c36bb988bb9e73ad612888610d368fdaaa15472a
  • alt-php81-imap_8.1.34-13_amd64.deb
    sha:35cf572d1d63468f20c4a689db56bb05cd6ac357
  • alt-php81-intl_8.1.34-13_amd64.deb
    sha:88611da807fefeecf7249b0182e976bf152faf34
  • alt-php81-ldap_8.1.34-13_amd64.deb
    sha:b464de891dff538083f63e5b1c7b73509446be08
  • alt-php81-mbstring_8.1.34-13_amd64.deb
    sha:3605da98ee200220ff2581a51149bc3974d32bc9
  • alt-php81-mysqlnd_8.1.34-13_amd64.deb
    sha:78858bd2c59cba7b2975c2af5c1d9cc10755691b
  • alt-php81-odbc_8.1.34-13_amd64.deb
    sha:06ed380e48cffc100ee9af38af4a9ce24f915d58
  • alt-php81-opcache_8.1.34-13_amd64.deb
    sha:1af16e680650ef576d2f723b6a5e4e978c70d281
  • alt-php81-pdo_8.1.34-13_amd64.deb
    sha:6f8de49544203a0b88879a95bb8c8188576dadf3
  • alt-php81-pgsql_8.1.34-13_amd64.deb
    sha:8b0f79ce0046fc95c0298560eb573e0f30fd27ee
  • alt-php81-process_8.1.34-13_amd64.deb
    sha:4feab1be415393bd9aef6592d10d1bf69c30f205
  • alt-php81-pspell_8.1.34-13_amd64.deb
    sha:81b2a22eb1840a5217a6a3208fb8c85e3b9583f0
  • alt-php81-snmp_8.1.34-13_amd64.deb
    sha:2837cc33b273c0ae3a2e67b67ef094f06ff23ba7
  • alt-php81-soap_8.1.34-13_amd64.deb
    sha:a3b20ac22c82bb767e6186d35cb4dd746a93c149
  • alt-php81-sodium_8.1.34-13_amd64.deb
    sha:7c020f8bc10fa5865231a9852ea0ca7993cee44f
  • alt-php81-tidy_8.1.34-13_amd64.deb
    sha:a9448cd5be34fa4a79250cbf3a42078e4b386d21
  • alt-php81-xml_8.1.34-13_amd64.deb
    sha:0b734ff1b5e965148541f39a71505d5edfeb9c3e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.