[CLSA-2026:1779207978] Fix of 7 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-19 16:26:24 UTC
Description:
* SECURITY UPDATE: soap extension use-after-free via apache:Map duplicate keys - debian/patches/php-8.1-CVE-2026-6722.patch: backport upstream commit aee3b3ac9b in ext/soap/php_encoding.c — add Z_TRY_ADDREF_P on soap_add_xml_ref insertion and change SOAP_GLOBAL(ref_map) destructor to ZVAL_PTR_DTOR. - CVE-2026-6722 * SECURITY UPDATE: pdo_firebird SQL injection via NUL bytes in quoted strings - debian/patches/php-8.1-CVE-2025-14179.patch: backport upstream commit 3f40b65323 in ext/pdo_firebird/firebird_driver.c — replace strncat/strncpy/strcpy in preprocess() with memcpy plus explicit length tracking. - CVE-2025-14179 * SECURITY UPDATE: soap extension NULL pointer dereference via apache:Map item missing element - debian/patches/php-8.1-CVE-2026-7262.patch: backport upstream commit 79551ab8b1 in ext/soap/php_encoding.c — fix typo'd null check in to_zval_map() (was checking xmlKey, should check xmlValue). - CVE-2026-7262 * SECURITY UPDATE: php-fpm status endpoint XSS via unescaped request_uri - debian/patches/php-8.1-CVE-2026-6735.patch: backport upstream commit 99a5ad7441 in sapi/fpm/fpm/fpm_status.c — escape proc->request_uri with php_escape_html_entities_ex() / php_json_encode_string() and fix the broken "ENT_HTML_IGNORE_ERRORS & ENT_COMPAT" flag (bitwise- AND of two flag constants evaluates to 0). Applies with line offsets only against PHP 8.1.34. - CVE-2026-6735 * SECURITY UPDATE: mbstring NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() - debian/patches/php-8.1-CVE-2026-7259.patch: backport upstream commit 79a054eae0 in ext/mbstring/php_mbregex.c — resolve the mbfl encoding before storing it in MBREX(current_mbctype_mbfl_encoding) and return FAILURE if NULL (encodings supported by Oniguruma but not mbfl such as iso-8859-11, UJIS, KOI8-R). - CVE-2026-7259 * SECURITY UPDATE: soap SoapServer use-after-free after header parsing failure when SOAP_PERSISTENCE_SESSION is set - debian/patches/php-8.1-CVE-2026-7261.patch: backport upstream commit db2a7f9348 in ext/soap/soap.c — guard both zval_ptr_dtor(soap_obj) call sites in PHP_METHOD(SoapServer, handle) with "if (service->soap_class.persistence != SOAP_PERSISTENCE_SESSION)". Adapted to 8.1's fault path (extra zend_string_release(fn_name) before each dtor). - CVE-2026-7261 * SECURITY UPDATE: metaphone() signed integer overflow on >INT_MAX input - debian/patches/php-8.1-CVE-2026-7568.patch: backport upstream commit 47def8ce1d in ext/standard/metaphone.c — retype w_idx and Lookahead's how_far/idx from int to size_t to avoid signed overflow while walking strings larger than 2 GB on 64-bit builds. - CVE-2026-7568
Updated packages:
  • alt-php81_8.1.34-13_amd64.deb
    sha:57f5af02489eb86ae97e3b61a173d227fe654b19
  • alt-php81-bcmath_8.1.34-13_amd64.deb
    sha:0c1eac22e2de90930b324846602b6dad350de20a
  • alt-php81-cli_8.1.34-13_amd64.deb
    sha:c40e6efa03a457ed81ba94ca14256b05e9e94150
  • alt-php81-common_8.1.34-13_amd64.deb
    sha:48a45cc9759f8fe03a7f67324963d4a4b7bc8721
  • alt-php81-dba_8.1.34-13_amd64.deb
    sha:4caac7160f185b67a8b569bfef86ad179a05750a
  • alt-php81-dev_8.1.34-13_amd64.deb
    sha:36bef2e02aacb41c68b3c4702148c8e93c326340
  • alt-php81-enchant_8.1.34-13_amd64.deb
    sha:d17531c70592e86986ea51bb6f663598333c8732
  • alt-php81-firebird_8.1.34-13_amd64.deb
    sha:e124dc5cdc927ea1c88acd75be8b96fffdb7e724
  • alt-php81-fpm_8.1.34-13_amd64.deb
    sha:2af8b9169215b810b81fa84d4f591dabad969e11
  • alt-php81-gd_8.1.34-13_amd64.deb
    sha:c265df53a0d615a9e603fb71735ac358db6b1fbc
  • alt-php81-imap_8.1.34-13_amd64.deb
    sha:651453d7a8fd3a7ff246d88fe5119bada21403ec
  • alt-php81-intl_8.1.34-13_amd64.deb
    sha:4d58e999d95ae6791572e9e34d57d54e44a1dc44
  • alt-php81-ldap_8.1.34-13_amd64.deb
    sha:8d252f9b8dc974ca74acde6dac08c37bbd484647
  • alt-php81-mbstring_8.1.34-13_amd64.deb
    sha:a58777909010ba77437ae864bc161311ad3a2280
  • alt-php81-mysqlnd_8.1.34-13_amd64.deb
    sha:7a41c6d223f31813f5bc0f4b8f95614d95261c3b
  • alt-php81-odbc_8.1.34-13_amd64.deb
    sha:d59d450fbbe7d493a15a543805f7487deb3dc37a
  • alt-php81-opcache_8.1.34-13_amd64.deb
    sha:ba71b7dca3c2415e95810e745b21199995c2254a
  • alt-php81-pdo_8.1.34-13_amd64.deb
    sha:8433ddd22c1c7721b55860c30bac3e75a42124d9
  • alt-php81-pgsql_8.1.34-13_amd64.deb
    sha:bbabd3beb85a5061ed1896d55e060602389a8cd0
  • alt-php81-process_8.1.34-13_amd64.deb
    sha:9a4b52c46a5aae199ddda556ab21cce92c09da14
  • alt-php81-pspell_8.1.34-13_amd64.deb
    sha:b4dea21cd085f9803d0008d081363c56a93f1062
  • alt-php81-snmp_8.1.34-13_amd64.deb
    sha:ab0b919c0be677b7797759c418e47505bb016ead
  • alt-php81-soap_8.1.34-13_amd64.deb
    sha:d9d04e3d2050563f3129c05aaf2a83ff1f9bcd28
  • alt-php81-sodium_8.1.34-13_amd64.deb
    sha:9ab1e4f4e19518d217235d95326bb791193a0a19
  • alt-php81-tidy_8.1.34-13_amd64.deb
    sha:4893036a623c4292c77bffaf1220dad079223fab
  • alt-php81-xml_8.1.34-13_amd64.deb
    sha:91957a778a76945d2894e15790220678a0492bca
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.