Release date:
2026-05-22 10:38:16 UTC
Description:
* SECURITY UPDATE: soap extension use-after-free via apache:Map duplicate keys
- debian/patches/php-7.4-CVE-2026-6722.patch: backport upstream commit
aee3b3ac9b in ext/soap/php_encoding.c — add Z_TRY_ADDREF_P on
soap_add_xml_ref insertion and change SOAP_GLOBAL(ref_map) destructor
to ZVAL_PTR_DTOR.
- CVE-2026-6722
* SECURITY UPDATE: soap extension NULL pointer dereference via apache:Map
item missing element
- debian/patches/php-7.4-CVE-2026-7262.patch: backport upstream commit
79551ab8b1 in ext/soap/php_encoding.c — fix typo'd null check in
to_zval_map() (was checking xmlKey, should check xmlValue).
- CVE-2026-7262
* SECURITY UPDATE: php-fpm status endpoint XSS via unescaped request_uri
- debian/patches/php-7.4-CVE-2026-6735.patch: backport upstream commit
99a5ad7441 in sapi/fpm/fpm/fpm_status.c — escape proc.request_uri
with php_escape_html_entities_ex() and fix the broken
"ENT_HTML_IGNORE_ERRORS & ENT_COMPAT" flag (bitwise-AND of two flag
constants evaluates to 0). Adapted to 7.x layout (struct access
"proc.X", single encode flag, older 6-arg
php_escape_html_entities_ex signature).
- CVE-2026-6735
* SECURITY UPDATE: soap SoapServer use-after-free after header parsing
failure when SOAP_PERSISTENCE_SESSION is set
- debian/patches/php-7.4-CVE-2026-7261.patch: backport upstream commit
db2a7f9348 in ext/soap/soap.c — guard both zval_ptr_dtor(soap_obj)
call sites in PHP_METHOD(SoapServer, handle) with
"if (service->soap_class.persistence != SOAP_PERSISTENCE_SESSION)".
- CVE-2026-7261
* SECURITY UPDATE: metaphone() signed integer overflow on >INT_MAX input
- debian/patches/php-7.4-CVE-2026-7568.patch: backport upstream commit
47def8ce1d in ext/standard/metaphone.c — retype w_idx and
Lookahead's how_far/idx from int to size_t to avoid signed
overflow while walking strings larger than 2 GB on 64-bit builds.
- CVE-2026-7568
Updated packages:
-
alt-php74_7.4.33-55_amd64.deb
sha:a366dd82802c5d904f0cf6f343d926deded8d04c
-
alt-php74-bcmath_7.4.33-55_amd64.deb
sha:fab2532e6d7494f601e95f382a45605678420184
-
alt-php74-cli_7.4.33-55_amd64.deb
sha:03ff5c1f17d470219df0157e71afbfe2a18683fe
-
alt-php74-common_7.4.33-55_amd64.deb
sha:ee43a05e6bb93f066c4a7e76594a429bb5c77829
-
alt-php74-dba_7.4.33-55_amd64.deb
sha:ea391c629684c849c0c7ddab394a1b0105b7e3f4
-
alt-php74-dev_7.4.33-55_amd64.deb
sha:576f0676048769b2027d1d760f4d3ddd948930fd
-
alt-php74-enchant_7.4.33-55_amd64.deb
sha:ccc1eb6ff379bd54e00297a8151807db0396d804
-
alt-php74-firebird_7.4.33-55_amd64.deb
sha:33f2c16754c2b00f15d56a86b08c401f2d3ffea7
-
alt-php74-fpm_7.4.33-55_amd64.deb
sha:f737457db16dc9793058dd4830b21ab20d959227
-
alt-php74-gd_7.4.33-55_amd64.deb
sha:6fdc7f0b589313ce7ed70e2185ad720de63857d4
-
alt-php74-imap_7.4.33-55_amd64.deb
sha:6bfe38db5851bdd582ae3a87bc82eb27dfe0a3fb
-
alt-php74-intl_7.4.33-55_amd64.deb
sha:ae4044d0d48542ccb8ccc8d59bbd2a68ef7749a1
-
alt-php74-ldap_7.4.33-55_amd64.deb
sha:4a1f2cf9dda555850b7d1c51a369b570a79ba3b5
-
alt-php74-mbstring_7.4.33-55_amd64.deb
sha:bf55a25d9cda48229a02b0c5e67b0e3a0895b747
-
alt-php74-mysqlnd_7.4.33-55_amd64.deb
sha:11549e765a7bb01e420459c7a493d23824ad5b11
-
alt-php74-odbc_7.4.33-55_amd64.deb
sha:e1c373cb5a0106c64be8a7ef44e3206923e0da8a
-
alt-php74-opcache_7.4.33-55_amd64.deb
sha:9876834b9ec328b69e1954ceb3c152c75301ddee
-
alt-php74-pdo_7.4.33-55_amd64.deb
sha:e7a468f833da3b49315e639ae1ffd4461879269e
-
alt-php74-pgsql_7.4.33-55_amd64.deb
sha:225ed4d4c2266582a0ff677e35a123ede83100f8
-
alt-php74-process_7.4.33-55_amd64.deb
sha:cfe747ffc9c56cc1e896580ab184be49b2a01d65
-
alt-php74-pspell_7.4.33-55_amd64.deb
sha:105f6a89cd81b78c8f0ea8e85ebc5025542a4e82
-
alt-php74-snmp_7.4.33-55_amd64.deb
sha:1d9b4907132f043160e9be7dc0701cb24bf7bc36
-
alt-php74-soap_7.4.33-55_amd64.deb
sha:f94cc21d7c49379777cfbcdd3922d2e92a244b62
-
alt-php74-sodium_7.4.33-55_amd64.deb
sha:af2c0ea029808d8589886b3d0e54d493b29c15c0
-
alt-php74-tidy_7.4.33-55_amd64.deb
sha:d8eac0b7c4cd5d8c52013e350915a1412c1f8fe2
-
alt-php74-xml_7.4.33-55_amd64.deb
sha:fa6c1aa83d2ddd3b9eca3a201f5d2cf549bb4a27
-
alt-php74-xmlrpc_7.4.33-55_amd64.deb
sha:2837205aaa7acc21409919d272994f966d8c1b82
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.