Release date:
2026-05-22 14:30:36 UTC
Description:
* SECURITY UPDATE: soap extension use-after-free via apache:Map duplicate keys
- debian/patches/php-7.2-CVE-2026-6722.patch: backport upstream commit
aee3b3ac9b in ext/soap/php_encoding.c — add Z_TRY_ADDREF_P on
soap_add_xml_ref insertion and change SOAP_GLOBAL(ref_map) destructor
to ZVAL_PTR_DTOR.
- CVE-2026-6722
* SECURITY UPDATE: soap extension NULL pointer dereference via apache:Map
item missing element
- debian/patches/php-7.2-CVE-2026-7262.patch: backport upstream commit
79551ab8b1 in ext/soap/php_encoding.c — fix typo'd null check in
to_zval_map() (was checking xmlKey, should check xmlValue).
- CVE-2026-7262
* SECURITY UPDATE: php-fpm status endpoint XSS via unescaped request_uri
- debian/patches/php-7.2-CVE-2026-6735.patch: backport upstream commit
99a5ad7441 in sapi/fpm/fpm/fpm_status.c — escape proc.request_uri
with php_escape_html_entities_ex() and fix the broken
"ENT_HTML_IGNORE_ERRORS & ENT_COMPAT" flag (bitwise-AND of two flag
constants evaluates to 0). Adapted to 7.x layout (struct access
"proc.X", single encode flag, older 6-arg
php_escape_html_entities_ex signature).
- CVE-2026-6735
* SECURITY UPDATE: soap SoapServer use-after-free after header parsing
failure when SOAP_PERSISTENCE_SESSION is set
- debian/patches/php-7.2-CVE-2026-7261.patch: backport upstream commit
db2a7f9348 in ext/soap/soap.c — guard both zval_ptr_dtor(soap_obj)
call sites in PHP_METHOD(SoapServer, handle) with
"if (service->soap_class.persistence != SOAP_PERSISTENCE_SESSION)".
- CVE-2026-7261
* SECURITY UPDATE: metaphone() signed integer overflow on >INT_MAX input
- debian/patches/php-7.2-CVE-2026-7568.patch: backport upstream commit
47def8ce1d in ext/standard/metaphone.c — retype w_idx and
Lookahead's how_far/idx from int to size_t to avoid signed
overflow while walking strings larger than 2 GB on 64-bit builds.
- CVE-2026-7568
Updated packages:
-
alt-php72_7.2.34-74_amd64.deb
sha:d89c6ae76ae55f00c7324d5c8a2e309b19e7dfea
-
alt-php72-bcmath_7.2.34-74_amd64.deb
sha:2fc36d378ebd6895708b0630004b60831f07799f
-
alt-php72-cli_7.2.34-74_amd64.deb
sha:0d3c728817befa814b96cb2ad7bbbf978ab2da70
-
alt-php72-common_7.2.34-74_amd64.deb
sha:5905a93a7ebf0ccbd899ae38cfff7f44673d1ac5
-
alt-php72-dba_7.2.34-74_amd64.deb
sha:86b8357eaf8f3b8f574a3053b95a193aa728b143
-
alt-php72-dev_7.2.34-74_amd64.deb
sha:c5e24c59ee1f2463b8d2ffef5a094153f653d699
-
alt-php72-enchant_7.2.34-74_amd64.deb
sha:0c94ef7ed5f8eb2240ac54528c9f136a1877341e
-
alt-php72-firebird_7.2.34-74_amd64.deb
sha:e8569eb6aa76728ee8989b51911cff7393900353
-
alt-php72-fpm_7.2.34-74_amd64.deb
sha:2678fee966e73e078418835a58f1be4339dcba00
-
alt-php72-gd_7.2.34-74_amd64.deb
sha:fbb67143b7473efb2826bf58c3b20702a5304f76
-
alt-php72-imap_7.2.34-74_amd64.deb
sha:d299659c3e50ef850a8438aef340acf9246243b2
-
alt-php72-intl_7.2.34-74_amd64.deb
sha:7bcb7e3bed1c311f5b4eca7d66e90e4b8b8063f8
-
alt-php72-ldap_7.2.34-74_amd64.deb
sha:d600deaadcf6c161e0f6e82e571e3a307d4b97c8
-
alt-php72-mbstring_7.2.34-74_amd64.deb
sha:9911b760ae13290992da74ed0fabc88428f375b8
-
alt-php72-mysqlnd_7.2.34-74_amd64.deb
sha:f9ea8c5157d221f0b29d4b638e7e7849f7886587
-
alt-php72-odbc_7.2.34-74_amd64.deb
sha:0353c73a210acf70307412b0d063b87feb548b96
-
alt-php72-opcache_7.2.34-74_amd64.deb
sha:a8f138b922e8d3678976d1135d0432b0eb74c7ba
-
alt-php72-pdo_7.2.34-74_amd64.deb
sha:29f0a353c4660b9f57185c2544f5248e7f4e6dee
-
alt-php72-pgsql_7.2.34-74_amd64.deb
sha:0af9684d59ceff6ac651278ee7ada873d1ef82d7
-
alt-php72-process_7.2.34-74_amd64.deb
sha:e4c08d605d8c22c462e88eb361e08dc266ff0f15
-
alt-php72-pspell_7.2.34-74_amd64.deb
sha:9595716ceedb7fec5f3698c8e400929e618206ba
-
alt-php72-recode_7.2.34-74_amd64.deb
sha:8cac1bba0208c51fb5f6175802b552a3421169b6
-
alt-php72-snmp_7.2.34-74_amd64.deb
sha:2e2f30f0e392fc20cf0f2e5eb20560e9b45518c3
-
alt-php72-soap_7.2.34-74_amd64.deb
sha:365b893fe774a969331115d7d0ee94a22cbd1782
-
alt-php72-sodium_7.2.34-74_amd64.deb
sha:39e0e883f4bca34539bbcb1d507026f452c226db
-
alt-php72-tidy_7.2.34-74_amd64.deb
sha:61c44db6e8335bf09cbbfd69e1fda64d84d3be34
-
alt-php72-xml_7.2.34-74_amd64.deb
sha:19aa247aaee2edc9dcbfecc1227c9f1e66458c9a
-
alt-php72-xmlrpc_7.2.34-74_amd64.deb
sha:29be0335845a00de8eb1de32c11266f86a2e83d3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.