Release date:
2026-05-20 16:36:05 UTC
Description:
- CVE-2026-6722: soap extension use-after-free via apache:Map duplicate keys
(5.3 backport applies addref half only; ref_map ZVAL_PTR_DTOR is
intentionally omitted because ref_map is heterogeneous in 5.x and the
dtor would corrupt the xmlNodePtr entries — see patch header)
- CVE-2026-7262: soap extension NULL pointer deref via apache:Map missing value
- CVE-2026-7261: soap extension use-after-free with SOAP_PERSISTENCE_SESSION header parsing failure
- CVE-2026-6735: php-fpm status endpoint XSS via unescaped request_uri and query_string
(5.3 backport applies HTML entity escape to both HTML and JSON /status
endpoints since php_json_encode_string() isn't exported on 5.x — JSON
consumers will see HTML entities in request_uri/query_string fields)
Updated packages:
-
alt-php53-5.3.29-193.el10.x86_64.rpm
sha:e9bdda590c3a4712610f3fd8396157ffd6e033dabc06ed504737fe6e7773ac73
-
alt-php53-bcmath-5.3.29-193.el10.x86_64.rpm
sha:44da3f6c02beb31b614a8487ab4084933ee746c5a9d81ee251446457d5b106ad
-
alt-php53-cli-5.3.29-193.el10.x86_64.rpm
sha:1ba188c979d2d9e383a7216bfad1ad5bb0e8fc91e422bf988b38089ac7603ff3
-
alt-php53-common-5.3.29-193.el10.x86_64.rpm
sha:ac2854b47dcda193480a71a7d162d31a7c46ad93a57e2464d4c61d8b6247523a
-
alt-php53-dba-5.3.29-193.el10.x86_64.rpm
sha:68b58090bd07800c19b2bfd09b849fafde8af677a8392f9295eb397487900e69
-
alt-php53-devel-5.3.29-193.el10.x86_64.rpm
sha:cfd23f969e18c2f764c33a8a46bbb623765ecec0b0c6ec92b2a31134abe2fddc
-
alt-php53-enchant-5.3.29-193.el10.x86_64.rpm
sha:5c5c8fd16ebc32de8071e10e8fd3b486e752dd0c79e05503c0d0d1b606562cf3
-
alt-php53-gd-5.3.29-193.el10.x86_64.rpm
sha:c27c4a0b0697a32fb073df96dcd18f86fb0530aa1d932a38ebea03896c25900d
-
alt-php53-imap-5.3.29-193.el10.x86_64.rpm
sha:c06bf7016f0db42439ec0de9ab5ef6331e0f5fa2777f14d76c0fc1ba58793da3
-
alt-php53-intl-5.3.29-193.el10.x86_64.rpm
sha:0dc5a1a2d4fed3ab06e7fd65e10b9eab9b6e0be38f5af40d982e8bbff6ed3fe1
-
alt-php53-ldap-5.3.29-193.el10.x86_64.rpm
sha:0540cc60940765afdfc408e62101d8176f8d801f9a3e828cea86ae325f9f7e89
-
alt-php53-mbstring-5.3.29-193.el10.x86_64.rpm
sha:f81a86cfae02a9db7a89bbff8426832efb7672930f45af43c5782babf67ac0d2
-
alt-php53-mcrypt-5.3.29-193.el10.x86_64.rpm
sha:101b0bc2fa5a3cc90de9e797aac2b736ccf361ade12b77ec1d9a208787134abc
-
alt-php53-mssql-5.3.29-193.el10.x86_64.rpm
sha:1995d83e68e209f67b7428ab42d5e44bfce9f726666f0f1252cc657b28104f6b
-
alt-php53-mysqlnd-5.3.29-193.el10.x86_64.rpm
sha:b090c915e96c9307237d23aa8ba7c78c66cf2427457fd07cd8785774e0fc28a6
-
alt-php53-odbc-5.3.29-193.el10.x86_64.rpm
sha:e89264456ed86acc984a002f56e089df78bc59aaee7554928ec618ebb905329e
-
alt-php53-pdo-5.3.29-193.el10.x86_64.rpm
sha:5245a94553b48f9a28af022a1a4290d5ccf7f9c664a5bac7bde8176ad3104906
-
alt-php53-pgsql-5.3.29-193.el10.x86_64.rpm
sha:f14e19527deb7d5944ed395101f0ad9f6533bd7a1396c8fe17117cc9514ecafc
-
alt-php53-php-fpm-5.3.29-193.el10.x86_64.rpm
sha:22fa7731a232d4b97808cc2aec43b4098264f655d705d627648fa6c20b26683e
-
alt-php53-process-5.3.29-193.el10.x86_64.rpm
sha:c9a3804233273db4baab59c3d00c790fcfb97e49df63a0698b8f567c06e92ddc
-
alt-php53-pspell-5.3.29-193.el10.x86_64.rpm
sha:cf2495fc030eeaec174d04b695d4cf791a7b91f8d77950021bcdb0742a1347b9
-
alt-php53-recode-5.3.29-193.el10.x86_64.rpm
sha:630ed54439750315add6cd6303c413734b187289f865af51cedabcc78236c914
-
alt-php53-snmp-5.3.29-193.el10.x86_64.rpm
sha:7467b65bf52ed1e8cdd5658125609ceec5250e5d4b0a1f27bf5fe54e190cc2dd
-
alt-php53-soap-5.3.29-193.el10.x86_64.rpm
sha:fe2669acba077f3d65f8a1b3d0464213154c0715174d2ea96ad9b5ae54fc8c5d
-
alt-php53-sqlite-5.3.29-193.el10.x86_64.rpm
sha:ec72a4850b81ed6507a3c6d027cac13f515ffab36032c81afd2cd61a8fa0a5ee
-
alt-php53-sybase-5.3.29-193.el10.x86_64.rpm
sha:73f28ffbec93158ab129cf738eea86dee154d0b8df93d056d43b526c4dc7954d
-
alt-php53-tidy-5.3.29-193.el10.x86_64.rpm
sha:3562a1ea1d231a9b4380def118425265d1f26802c905c2f6ed0efbf0752045fc
-
alt-php53-xml-5.3.29-193.el10.x86_64.rpm
sha:1795788404040a0906b7b46b60a2cbd7ff745deda376819113d25bb6c829e1a8
-
alt-php53-xmlrpc-5.3.29-193.el10.x86_64.rpm
sha:b64de4cb4b7fb1e70e7a733579df9f70a37abb5e75f885ea64d35c99d15be7c8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.