[CLSA-2026:1779206686] alt-php81: Fix of 7 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-19 16:04:51 UTC
Description:
- CVE-2026-6722: soap extension use-after-free via apache:Map duplicate keys - CVE-2025-14179: pdo_firebird SQL injection via NUL bytes in quoted strings - CVE-2026-7262: soap extension NULL pointer deref via apache:Map missing value - CVE-2026-6735: php-fpm status endpoint XSS via unescaped request_uri - CVE-2026-7259: mbstring NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() with Oniguruma-only encodings (iso-8859-11, UJIS, KOI8-R, ...) - CVE-2026-7261: soap SoapServer use-after-free after header parsing failure when SOAP_PERSISTENCE_SESSION is set - CVE-2026-7568: metaphone() signed integer overflow when called with >INT_MAX byte input on 64-bit builds
Updated packages:
  • alt-php81-8.1.34-11.el10.x86_64.rpm
    sha:780e762f2b730821c7b488f77d53bcb326c48f9c549b012c7d8ef9cbd7d867f2
  • alt-php81-bcmath-8.1.34-11.el10.x86_64.rpm
    sha:396c8fcec94e37b5fad9341b0aeeb082ffefeb00bce22e537e308f079977b820
  • alt-php81-cli-8.1.34-11.el10.x86_64.rpm
    sha:d17418f631b9b89124f1d9d228b0199ee1b56ebcc01e9f92affec8ce2f9c4e71
  • alt-php81-common-8.1.34-11.el10.x86_64.rpm
    sha:dea31865120a4898cf88210c038cf15007f7ac26e8ffc707e50e7a932967cbb0
  • alt-php81-dba-8.1.34-11.el10.x86_64.rpm
    sha:80dabb039267132daafadeaeccd7d9e50159e9e2beee56c8851dfb6229e549c5
  • alt-php81-devel-8.1.34-11.el10.x86_64.rpm
    sha:78131e4242f14f47e02a502eb35b5202184905c8e55189aa68661ec40841b376
  • alt-php81-enchant-8.1.34-11.el10.x86_64.rpm
    sha:781daaa35f0d33e644303412fd9e3b81906d5b6a9d218116c0a71a52236d51e7
  • alt-php81-firebird-8.1.34-11.el10.x86_64.rpm
    sha:86c4fb59c64ae9133cc04d5997123614778cefbbe1ee5dc7a7bed1be15971f4b
  • alt-php81-gd-8.1.34-11.el10.x86_64.rpm
    sha:921b92697beb0f65d3543e397f3a6bfa1c31b43120329015c0843e4fc4933651
  • alt-php81-gmp-8.1.34-11.el10.x86_64.rpm
    sha:1f3807ab8bd1eb668670bd6d72cd73646c2397a903b7bb832cacd700a11e9025
  • alt-php81-imap-8.1.34-11.el10.x86_64.rpm
    sha:f63942ae559978d3cd34521711fa2c18f76bd4d93c707c24fa3b1143194f5864
  • alt-php81-intl-8.1.34-11.el10.x86_64.rpm
    sha:6c8ddabbb28b53818a611bd505076c07da5bf51a5d3d48bd130303e225ca9507
  • alt-php81-ldap-8.1.34-11.el10.x86_64.rpm
    sha:1e041a6399c84ade6090ede8b162f9684edd534cbe388a59d59a3b5412386ef4
  • alt-php81-mbstring-8.1.34-11.el10.x86_64.rpm
    sha:605169476f45fce7cd365d217c6cff42e6c0451978da2333a0b8a63581486dc4
  • alt-php81-mysqlnd-8.1.34-11.el10.x86_64.rpm
    sha:1bf7ca83f8d2e51bd91a4940dc77ff8c1795291481b46f53ab7c5088764fbb73
  • alt-php81-odbc-8.1.34-11.el10.x86_64.rpm
    sha:b10461dba0b80e21a8bfc017109783e142638646cf1b1c4895913c4b3312ea95
  • alt-php81-opcache-8.1.34-11.el10.x86_64.rpm
    sha:74bbdbaaa4753fa311a02782521c253abfb494f96cb0c4d9bdcb8c5df0754c8e
  • alt-php81-pdo-8.1.34-11.el10.x86_64.rpm
    sha:9d942f192e6dbf12454894506799fb5d3b67f63c8a65a84a70962e2795f23d6d
  • alt-php81-pgsql-8.1.34-11.el10.x86_64.rpm
    sha:2328a114b03fed26ae55e343fb05e06519d0388eefbfa51efc1f002b0529c8d4
  • alt-php81-php-fpm-8.1.34-11.el10.x86_64.rpm
    sha:e04a99f75767904a87216aa8f8f7a3a2fa70f2638ed4b73254ca16e5c61bb17d
  • alt-php81-process-8.1.34-11.el10.x86_64.rpm
    sha:7b74d219c1f5d5613b6b0836357ccd9b11199f6a2c3129a38636e4bf447d7163
  • alt-php81-pspell-8.1.34-11.el10.x86_64.rpm
    sha:31a98b76b62d0b17accec922c366014e145058114fccbf6dd5d76d182314d879
  • alt-php81-snmp-8.1.34-11.el10.x86_64.rpm
    sha:d668649de2f14b9bbfe0514e7a3402bb621978752f163078b2328b619a3b6965
  • alt-php81-soap-8.1.34-11.el10.x86_64.rpm
    sha:47c6846a3e29c0e8d3292d30c6988071fa85253d11ec7955a151f758f61ac4cc
  • alt-php81-sodium-8.1.34-11.el10.x86_64.rpm
    sha:a4ebf660c39cb875ebde08d2c43a0b2e76b99d10858a2fb05a2b8f5de086c928
  • alt-php81-tidy-8.1.34-11.el10.x86_64.rpm
    sha:7b84720f67ef75b579492695963ff775a17914fd31b74883e5c84725e6b62e04
  • alt-php81-xml-8.1.34-11.el10.x86_64.rpm
    sha:0fc47b347b211c363df7647fccc1ef95a8ed1dea60938700ef466500fbc166e3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.