[CLSA-2026:1779459727] Fix of 5 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-22 14:22:24 UTC
Description:
* SECURITY UPDATE: soap extension use-after-free via apache:Map duplicate keys - debian/patches/php-7.1-CVE-2026-6722.patch: backport upstream commit aee3b3ac9b in ext/soap/php_encoding.c — add Z_TRY_ADDREF_P on soap_add_xml_ref insertion and change SOAP_GLOBAL(ref_map) destructor to ZVAL_PTR_DTOR. - CVE-2026-6722 * SECURITY UPDATE: soap extension NULL pointer dereference via apache:Map item missing element - debian/patches/php-7.1-CVE-2026-7262.patch: backport upstream commit 79551ab8b1 in ext/soap/php_encoding.c — fix typo'd null check in to_zval_map() (was checking xmlKey, should check xmlValue). - CVE-2026-7262 * SECURITY UPDATE: php-fpm status endpoint XSS via unescaped request_uri - debian/patches/php-7.1-CVE-2026-6735.patch: backport upstream commit 99a5ad7441 in sapi/fpm/fpm/fpm_status.c — escape proc.request_uri with php_escape_html_entities_ex() and fix the broken "ENT_HTML_IGNORE_ERRORS & ENT_COMPAT" flag (bitwise-AND of two flag constants evaluates to 0). Adapted to 7.x layout (struct access "proc.X", single encode flag, older 6-arg php_escape_html_entities_ex signature). - CVE-2026-6735 * SECURITY UPDATE: soap SoapServer use-after-free after header parsing failure when SOAP_PERSISTENCE_SESSION is set - debian/patches/php-7.1-CVE-2026-7261.patch: backport upstream commit db2a7f9348 in ext/soap/soap.c — guard both zval_ptr_dtor(soap_obj) call sites in PHP_METHOD(SoapServer, handle) with "if (service->soap_class.persistence != SOAP_PERSISTENCE_SESSION)". - CVE-2026-7261 * SECURITY UPDATE: metaphone() signed integer overflow on >INT_MAX input - debian/patches/php-7.1-CVE-2026-7568.patch: backport upstream commit 47def8ce1d in ext/standard/metaphone.c — retype w_idx and Lookahead's how_far/idx from int to size_t to avoid signed overflow while walking strings larger than 2 GB on 64-bit builds. - CVE-2026-7568
Updated packages:
  • alt-php71_7.1.33-90_amd64.deb
    sha:8fc4d07f2eae24fd0a03f3672cb388e33b7518d4
  • alt-php71-bcmath_7.1.33-90_amd64.deb
    sha:6ce59357e3105dbdb7de5370aa6a5975fe7200ac
  • alt-php71-cli_7.1.33-90_amd64.deb
    sha:f8645084f398d244009b1a45d97889543f6a2085
  • alt-php71-common_7.1.33-90_amd64.deb
    sha:32f4a6e10fbb25b4f6e99c21559d9722f2245d65
  • alt-php71-dba_7.1.33-90_amd64.deb
    sha:3e7635531feb9b41716733d316a8815f3df6a7d2
  • alt-php71-dev_7.1.33-90_amd64.deb
    sha:1b5b83935f08d965ec82632c2ba1e3435f2e15af
  • alt-php71-enchant_7.1.33-90_amd64.deb
    sha:88408708735f89462ffeb21130baf054ad418f55
  • alt-php71-firebird_7.1.33-90_amd64.deb
    sha:545787dad533f9d2d7e2d0ebc3dbef36eb6026c9
  • alt-php71-fpm_7.1.33-90_amd64.deb
    sha:e3bb8e60ed79dd4bb9053339897f66a12d0503f0
  • alt-php71-gd_7.1.33-90_amd64.deb
    sha:30a6ee2e0108facbfda5d5e9af47dbfb522080b4
  • alt-php71-imap_7.1.33-90_amd64.deb
    sha:bb5d81c1dbe3e84cc1fb78a339fcd47bf29a3057
  • alt-php71-intl_7.1.33-90_amd64.deb
    sha:885f26200e0de74437b6e76a1aba90fe6cd71bbc
  • alt-php71-ldap_7.1.33-90_amd64.deb
    sha:b89e1431ff23355ec0110eb3d2f757f4e2033b05
  • alt-php71-mbstring_7.1.33-90_amd64.deb
    sha:0815925639e4a4c0dd19f938601c0113b169646d
  • alt-php71-mcrypt_7.1.33-90_amd64.deb
    sha:ffcecfef6570cb5bec1bd20342bd81ff6d349c24
  • alt-php71-mysqlnd_7.1.33-90_amd64.deb
    sha:e4165594f14a4b2efa4a76c7cf842a90c2ab175f
  • alt-php71-odbc_7.1.33-90_amd64.deb
    sha:27f35af34ea55419c8c9d096d89b898830648bd5
  • alt-php71-opcache_7.1.33-90_amd64.deb
    sha:32e844aa33c07ec597453d309aa7ee15aacb3fe5
  • alt-php71-pdo_7.1.33-90_amd64.deb
    sha:2807e1a7864dc13e3db054d014f427ccc1dc7b3c
  • alt-php71-pgsql_7.1.33-90_amd64.deb
    sha:ba08bce81c806180752a84fee2cc1217f540d337
  • alt-php71-process_7.1.33-90_amd64.deb
    sha:1b9451b41b1bab1ebeacb79ba0e3d55ddff351ce
  • alt-php71-pspell_7.1.33-90_amd64.deb
    sha:e8967967053c091b6536f103105267bcd3c9ee25
  • alt-php71-recode_7.1.33-90_amd64.deb
    sha:f8d1c0e660475140d9c8d1166777d16c032c94f1
  • alt-php71-snmp_7.1.33-90_amd64.deb
    sha:373215b3e1dac7ebe576c7b083f5105e4efa556f
  • alt-php71-soap_7.1.33-90_amd64.deb
    sha:105767437a9cbfdd63a4a5fee17f01ab18898c46
  • alt-php71-tidy_7.1.33-90_amd64.deb
    sha:eacf1c0cc1f5d01e8f566cfd835ad4ff2d326ebc
  • alt-php71-xml_7.1.33-90_amd64.deb
    sha:51ec0f89ec70e6fc591756e39c149c9361cd811a
  • alt-php71-xmlrpc_7.1.33-90_amd64.deb
    sha:0052d29ee02a79084282607e1fa046fc1931f176
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.