[CLSA-2026:1779209472] alt-php81: Fix of 7 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-19 16:51:18 UTC
Description:
- CVE-2026-6722: soap extension use-after-free via apache:Map duplicate keys - CVE-2025-14179: pdo_firebird SQL injection via NUL bytes in quoted strings - CVE-2026-7262: soap extension NULL pointer deref via apache:Map missing value - CVE-2026-6735: php-fpm status endpoint XSS via unescaped request_uri - CVE-2026-7259: mbstring NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() with Oniguruma-only encodings (iso-8859-11, UJIS, KOI8-R, ...) - CVE-2026-7261: soap SoapServer use-after-free after header parsing failure when SOAP_PERSISTENCE_SESSION is set - CVE-2026-7568: metaphone() signed integer overflow when called with >INT_MAX byte input on 64-bit builds
Updated packages:
  • alt-php81-8.1.34-11.el7.x86_64.rpm
    sha:80a999953a4c189ff6ce6f3c894d774dcf7eac984451402ea7cc6f08bfee8b19
  • alt-php81-bcmath-8.1.34-11.el7.x86_64.rpm
    sha:93b0a2c6d22f208f90d3ef3a1dd6fc09096f287d51347c567a2ac4fb80e0176a
  • alt-php81-cli-8.1.34-11.el7.x86_64.rpm
    sha:388dc028cb60685917c69cf553da491c13756bfbc896cfc8a62bb5df451376c0
  • alt-php81-common-8.1.34-11.el7.x86_64.rpm
    sha:ee19931760df9fb4692b301c35d85d27e6a9709a0e0019235a9e0409c7a8c121
  • alt-php81-dba-8.1.34-11.el7.x86_64.rpm
    sha:23fefa16fcd19fc489f6b7ae25caaa1147f9dc861a044ccd6c25c58ce2802b51
  • alt-php81-devel-8.1.34-11.el7.x86_64.rpm
    sha:f3bfa84c27236f24b9f878d5ad497594a1bd705f5c81edb6229a0080eb6e55bd
  • alt-php81-enchant-8.1.34-11.el7.x86_64.rpm
    sha:727ba8b3ad0461318a9c8a5a1c383050e8c1b3182aced95a011d866601580dfd
  • alt-php81-firebird-8.1.34-11.el7.x86_64.rpm
    sha:0637ffc73f8eeb85c31f1670dab513d3c1c85a027ce77bc374c3423635f4c539
  • alt-php81-gd-8.1.34-11.el7.x86_64.rpm
    sha:94b471314788668ed6fef3459c4d730a498879a6d00bd9782c1cf74c00a43066
  • alt-php81-gmp-8.1.34-11.el7.x86_64.rpm
    sha:291036566b14cc82536d3639753b8acdf494d9d3c2cff1d8ac58bd79690eceaa
  • alt-php81-imap-8.1.34-11.el7.x86_64.rpm
    sha:d971ee59f36f8f34162c1d6e0c6a39d28f41b8d4230993b203bbac5957b8e859
  • alt-php81-intl-8.1.34-11.el7.x86_64.rpm
    sha:452ee8b4fdc610939051e9db7e1ee3ea1cd6626f4b8eeaf7a41775c82c5c4ce4
  • alt-php81-ldap-8.1.34-11.el7.x86_64.rpm
    sha:52a65ab481cb29ee79e643e839f52213fa0a7bb844805009ff886d2b13a21f69
  • alt-php81-mbstring-8.1.34-11.el7.x86_64.rpm
    sha:aedbae81f8f6768640742e901a9910af8fb591fd516bb1e4aa2b2d8f0585d44e
  • alt-php81-mysqlnd-8.1.34-11.el7.x86_64.rpm
    sha:0200edf7501c193172222e1878f8e6805ecb160dd6b0953c9224746711f13a7a
  • alt-php81-odbc-8.1.34-11.el7.x86_64.rpm
    sha:b9b5be16c1a07eadcf43337d4d52a7dc3020bc8a4c6baa0c553a7553ecc79b05
  • alt-php81-opcache-8.1.34-11.el7.x86_64.rpm
    sha:9e655248fd10d7f8159d3f36be2d1516e09296d33ff17fd148c664fca3c8365c
  • alt-php81-pdo-8.1.34-11.el7.x86_64.rpm
    sha:46a4da1f6bbf465b67d8698f5d14e7431b1c34b95323c30efa600a6d7131bcb5
  • alt-php81-pgsql-8.1.34-11.el7.x86_64.rpm
    sha:8dd4da348e5613081ce62e45ef904c6e3bbf3bb9d702d427dac0bfb95ca3b6ac
  • alt-php81-php-fpm-8.1.34-11.el7.x86_64.rpm
    sha:168acef348e4b82fa36d900de52c57a33807de799c8ee08432047c77b2b14f7f
  • alt-php81-process-8.1.34-11.el7.x86_64.rpm
    sha:45d7ed9d3c6cac9a10408c4eea29da70eda6c07fbbc9709c973fda0b78d58961
  • alt-php81-pspell-8.1.34-11.el7.x86_64.rpm
    sha:07c7ec2cb8e872d1cf72fa8a7f25b30404e829ec32bf73a414681ec76daea9ea
  • alt-php81-snmp-8.1.34-11.el7.x86_64.rpm
    sha:e82907c3705d49a223d1247def09a9f6708306968e980968200ec8b89ae99a32
  • alt-php81-soap-8.1.34-11.el7.x86_64.rpm
    sha:8a11953dba54084a224adca79f0f84af14c8283e6df54baaf066585cf3883e18
  • alt-php81-sodium-8.1.34-11.el7.x86_64.rpm
    sha:a2e70546bfe70604b34b5f5e880065cca8b58aefc7be0d75a81f954e3abfdc85
  • alt-php81-tidy-8.1.34-11.el7.x86_64.rpm
    sha:8046185b8a9f9f035b692b40c906385921e761a5eee3d056176d5ae4e8c67365
  • alt-php81-xml-8.1.34-11.el7.x86_64.rpm
    sha:031ec7ec9fc99869702dbfccfbd2b536235aec3582072134f41974b176918c0e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.