Release date:
2026-05-19 19:24:32 UTC
Description:
* SECURITY UPDATE: soap extension use-after-free via apache:Map duplicate keys
- debian/patches/php-8.1-CVE-2026-6722.patch: backport upstream commit
aee3b3ac9b in ext/soap/php_encoding.c — add Z_TRY_ADDREF_P on
soap_add_xml_ref insertion and change SOAP_GLOBAL(ref_map) destructor
to ZVAL_PTR_DTOR.
- CVE-2026-6722
* SECURITY UPDATE: pdo_firebird SQL injection via NUL bytes in quoted strings
- debian/patches/php-8.1-CVE-2025-14179.patch: backport upstream commit
3f40b65323 in ext/pdo_firebird/firebird_driver.c — replace
strncat/strncpy/strcpy in preprocess() with memcpy plus explicit length
tracking.
- CVE-2025-14179
* SECURITY UPDATE: soap extension NULL pointer dereference via apache:Map
item missing element
- debian/patches/php-8.1-CVE-2026-7262.patch: backport upstream commit
79551ab8b1 in ext/soap/php_encoding.c — fix typo'd null check in
to_zval_map() (was checking xmlKey, should check xmlValue).
- CVE-2026-7262
* SECURITY UPDATE: php-fpm status endpoint XSS via unescaped request_uri
- debian/patches/php-8.1-CVE-2026-6735.patch: backport upstream commit
99a5ad7441 in sapi/fpm/fpm/fpm_status.c — escape proc->request_uri
with php_escape_html_entities_ex() / php_json_encode_string() and
fix the broken "ENT_HTML_IGNORE_ERRORS & ENT_COMPAT" flag (bitwise-
AND of two flag constants evaluates to 0). Applies with line
offsets only against PHP 8.1.34.
- CVE-2026-6735
* SECURITY UPDATE: mbstring NULL pointer dereference in
php_mb_check_encoding() via mb_ereg_search_init()
- debian/patches/php-8.1-CVE-2026-7259.patch: backport upstream commit
79a054eae0 in ext/mbstring/php_mbregex.c — resolve the mbfl
encoding before storing it in MBREX(current_mbctype_mbfl_encoding)
and return FAILURE if NULL (encodings supported by Oniguruma but
not mbfl such as iso-8859-11, UJIS, KOI8-R).
- CVE-2026-7259
* SECURITY UPDATE: soap SoapServer use-after-free after header parsing
failure when SOAP_PERSISTENCE_SESSION is set
- debian/patches/php-8.1-CVE-2026-7261.patch: backport upstream commit
db2a7f9348 in ext/soap/soap.c — guard both zval_ptr_dtor(soap_obj)
call sites in PHP_METHOD(SoapServer, handle) with
"if (service->soap_class.persistence != SOAP_PERSISTENCE_SESSION)".
Adapted to 8.1's fault path (extra zend_string_release(fn_name)
before each dtor).
- CVE-2026-7261
* SECURITY UPDATE: metaphone() signed integer overflow on >INT_MAX input
- debian/patches/php-8.1-CVE-2026-7568.patch: backport upstream commit
47def8ce1d in ext/standard/metaphone.c — retype w_idx and
Lookahead's how_far/idx from int to size_t to avoid signed overflow
while walking strings larger than 2 GB on 64-bit builds.
- CVE-2026-7568
Updated packages:
-
alt-php81_8.1.34-13_amd64.deb
sha:9ba16aaedae441af6346cfcffc347898fbb2a09e
-
alt-php81-bcmath_8.1.34-13_amd64.deb
sha:deacdd08947cad8b41f4984bfecc28f651c83c92
-
alt-php81-cli_8.1.34-13_amd64.deb
sha:2054909b9754d47483750a818db71e9f5018788c
-
alt-php81-common_8.1.34-13_amd64.deb
sha:c96504685b987fd74966fdc3e148eafe1e4efa7a
-
alt-php81-dba_8.1.34-13_amd64.deb
sha:2f9c2315c4ae60b90b4260da54c124b937fdfead
-
alt-php81-dev_8.1.34-13_amd64.deb
sha:96a787f0f302cd096d69c83f625c2072083ee1e0
-
alt-php81-enchant_8.1.34-13_amd64.deb
sha:21e4fd42b283c7f9d9d96864d669750aee10acce
-
alt-php81-firebird_8.1.34-13_amd64.deb
sha:be7088d327ef32e6434d5ef4f8f294d33d138c7c
-
alt-php81-fpm_8.1.34-13_amd64.deb
sha:b47d4287b2b2a87de5ff14ee626cc74c3c0c6bcc
-
alt-php81-gd_8.1.34-13_amd64.deb
sha:581404cd9e1bf743d417dd8ba52342966fa568cf
-
alt-php81-imap_8.1.34-13_amd64.deb
sha:87d8b38983a4ec2ace81537c86c3b1f3863ccc9b
-
alt-php81-intl_8.1.34-13_amd64.deb
sha:b121a34d904ccfbc0342f7f97dadd5281ee5706f
-
alt-php81-ldap_8.1.34-13_amd64.deb
sha:ae73de4af7350d67093468df97910df527a83ac0
-
alt-php81-mbstring_8.1.34-13_amd64.deb
sha:d5337c0caf12fea530196281023b4e776d58c6cf
-
alt-php81-mysqlnd_8.1.34-13_amd64.deb
sha:896d7fab585d88e05087d9bcb830427ce90e234c
-
alt-php81-odbc_8.1.34-13_amd64.deb
sha:33093a20676ae4174a1c41329c52724852aebb8a
-
alt-php81-opcache_8.1.34-13_amd64.deb
sha:6aa0c742e058cd13e41523270366eaf63a415653
-
alt-php81-pdo_8.1.34-13_amd64.deb
sha:daa8aeddd6d0de47182cbb98f1d581b8ee91e9f2
-
alt-php81-pgsql_8.1.34-13_amd64.deb
sha:12c66f98820533f56cd3b0980dc4302708ba6710
-
alt-php81-process_8.1.34-13_amd64.deb
sha:6eb8f37cb725d16b01fee810195fd2f0b7194ab1
-
alt-php81-pspell_8.1.34-13_amd64.deb
sha:16d015b1300b4da445f2105239bb6bb0d5973e0d
-
alt-php81-snmp_8.1.34-13_amd64.deb
sha:cacef5cefa47a50a7bcc786dc74acdceb01a416e
-
alt-php81-soap_8.1.34-13_amd64.deb
sha:163c88c323da1b3d3f488e304b70e9e9283b9968
-
alt-php81-sodium_8.1.34-13_amd64.deb
sha:4b60bd7a36e829fde7cc4b74ffafb53af05bb626
-
alt-php81-tidy_8.1.34-13_amd64.deb
sha:132a3cdfe6bd544d578330e765d95a1858ce5057
-
alt-php81-xml_8.1.34-13_amd64.deb
sha:1e230dca172073b722fabd52b5f0a0ecffd4e766
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.