[CLSA-2026:1779452761] Fix of 5 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-22 12:26:06 UTC
Description:
* SECURITY UPDATE: soap extension use-after-free via apache:Map duplicate keys - debian/patches/php-7.4-CVE-2026-6722.patch: backport upstream commit aee3b3ac9b in ext/soap/php_encoding.c — add Z_TRY_ADDREF_P on soap_add_xml_ref insertion and change SOAP_GLOBAL(ref_map) destructor to ZVAL_PTR_DTOR. - CVE-2026-6722 * SECURITY UPDATE: soap extension NULL pointer dereference via apache:Map item missing element - debian/patches/php-7.4-CVE-2026-7262.patch: backport upstream commit 79551ab8b1 in ext/soap/php_encoding.c — fix typo'd null check in to_zval_map() (was checking xmlKey, should check xmlValue). - CVE-2026-7262 * SECURITY UPDATE: php-fpm status endpoint XSS via unescaped request_uri - debian/patches/php-7.4-CVE-2026-6735.patch: backport upstream commit 99a5ad7441 in sapi/fpm/fpm/fpm_status.c — escape proc.request_uri with php_escape_html_entities_ex() and fix the broken "ENT_HTML_IGNORE_ERRORS & ENT_COMPAT" flag (bitwise-AND of two flag constants evaluates to 0). Adapted to 7.x layout (struct access "proc.X", single encode flag, older 6-arg php_escape_html_entities_ex signature). - CVE-2026-6735 * SECURITY UPDATE: soap SoapServer use-after-free after header parsing failure when SOAP_PERSISTENCE_SESSION is set - debian/patches/php-7.4-CVE-2026-7261.patch: backport upstream commit db2a7f9348 in ext/soap/soap.c — guard both zval_ptr_dtor(soap_obj) call sites in PHP_METHOD(SoapServer, handle) with "if (service->soap_class.persistence != SOAP_PERSISTENCE_SESSION)". - CVE-2026-7261 * SECURITY UPDATE: metaphone() signed integer overflow on >INT_MAX input - debian/patches/php-7.4-CVE-2026-7568.patch: backport upstream commit 47def8ce1d in ext/standard/metaphone.c — retype w_idx and Lookahead's how_far/idx from int to size_t to avoid signed overflow while walking strings larger than 2 GB on 64-bit builds. - CVE-2026-7568
Updated packages:
  • alt-php74_7.4.33-55_amd64.deb
    sha:4a8f647201fcce3c3e07df9bd062c616d2740e57
  • alt-php74-bcmath_7.4.33-55_amd64.deb
    sha:3a9e2644bd3fa19def956a385d01a8c28a464633
  • alt-php74-cli_7.4.33-55_amd64.deb
    sha:d0163089c1473a3fa3c4775907528b5ba8d3b223
  • alt-php74-common_7.4.33-55_amd64.deb
    sha:3d76ba12326a930cbefd39030a3514c11fb86ac6
  • alt-php74-dba_7.4.33-55_amd64.deb
    sha:56f6f8b237b30bb8f329ebe1a3ca6d4df3f49eae
  • alt-php74-dev_7.4.33-55_amd64.deb
    sha:271733a26c1aa568c16b43afa81b59abec4401e8
  • alt-php74-enchant_7.4.33-55_amd64.deb
    sha:9837fa1824ac4de17c4a0601a46ac219f3d26919
  • alt-php74-firebird_7.4.33-55_amd64.deb
    sha:e3d566674c03a397a63828c250143f7fcdb76b06
  • alt-php74-fpm_7.4.33-55_amd64.deb
    sha:486352f22a58f3890289c6c3689fa04e9e5c4848
  • alt-php74-gd_7.4.33-55_amd64.deb
    sha:bfe8823e327e27b353dcc391cab5eb51aa083a46
  • alt-php74-imap_7.4.33-55_amd64.deb
    sha:91931cc28fb67416f5d0a66411c64be403cd6445
  • alt-php74-intl_7.4.33-55_amd64.deb
    sha:718ac65ed4b4521a898e506f92b0b4667cdbdf08
  • alt-php74-ldap_7.4.33-55_amd64.deb
    sha:b633944f4a6c59453a94313937dbe7727f6ac08c
  • alt-php74-mbstring_7.4.33-55_amd64.deb
    sha:33aa823618329e6dc7358fd714ad716f1246e9df
  • alt-php74-mysqlnd_7.4.33-55_amd64.deb
    sha:ba511c1999cba33bb4ed3cf90dd0e021681cc861
  • alt-php74-odbc_7.4.33-55_amd64.deb
    sha:c9911b2c889328cf509c430f1f47ef5fef52275c
  • alt-php74-opcache_7.4.33-55_amd64.deb
    sha:505173df5a36e243608840eb21dab5b99c26f4ea
  • alt-php74-pdo_7.4.33-55_amd64.deb
    sha:05d1a484147e47007d9a626f751d54500065e160
  • alt-php74-pgsql_7.4.33-55_amd64.deb
    sha:97a61d6aea0962bec5ef6465b9fe0f281cea28fe
  • alt-php74-process_7.4.33-55_amd64.deb
    sha:fa90373c5e21befc2a3e682b6558878eb5093262
  • alt-php74-pspell_7.4.33-55_amd64.deb
    sha:3db66c24c29cdc08f68fef05ee74b0ead77195d2
  • alt-php74-snmp_7.4.33-55_amd64.deb
    sha:55b05c1989afb9f234dad3e16b7088ea10f9fa0b
  • alt-php74-soap_7.4.33-55_amd64.deb
    sha:9d17ff72b88ec40e10da2ba2cd08d262f9857d10
  • alt-php74-tidy_7.4.33-55_amd64.deb
    sha:40972ac008d2d513cb8cfb7a0ae0938efe451cef
  • alt-php74-xml_7.4.33-55_amd64.deb
    sha:15dad07b1653bd03a29d93967d96fca93f54c260
  • alt-php74-xmlrpc_7.4.33-55_amd64.deb
    sha:4a869089d16bafb28e95922afb633acbdd3e5d75
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.