[CLSA-2026:1779208716] alt-php81: Fix of 7 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-19 16:38:41 UTC
Description:
- CVE-2026-6722: soap extension use-after-free via apache:Map duplicate keys - CVE-2025-14179: pdo_firebird SQL injection via NUL bytes in quoted strings - CVE-2026-7262: soap extension NULL pointer deref via apache:Map missing value - CVE-2026-6735: php-fpm status endpoint XSS via unescaped request_uri - CVE-2026-7259: mbstring NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() with Oniguruma-only encodings (iso-8859-11, UJIS, KOI8-R, ...) - CVE-2026-7261: soap SoapServer use-after-free after header parsing failure when SOAP_PERSISTENCE_SESSION is set - CVE-2026-7568: metaphone() signed integer overflow when called with >INT_MAX byte input on 64-bit builds
Updated packages:
  • alt-php81-8.1.34-11.el9.x86_64.rpm
    sha:d5dbec8abe4d4f5d25640708e178dd8899cc2725a8aa36fce1bbece90e4eae18
  • alt-php81-bcmath-8.1.34-11.el9.x86_64.rpm
    sha:4b0abbc1052d80183c90fc48ff16974573d7578367d067ade007cfba21ca9e4f
  • alt-php81-cli-8.1.34-11.el9.x86_64.rpm
    sha:9d94ea6fdf79e921a253b3953686191e669b707f0e27a0446ae83fc716312276
  • alt-php81-common-8.1.34-11.el9.x86_64.rpm
    sha:3879481131a4adf7fe1798163f584de2f9299a6e79dec398760a7a5296c39ed3
  • alt-php81-dba-8.1.34-11.el9.x86_64.rpm
    sha:848e5d90b69b772fada0e06094e6ad64a82b173e8207d3b102af7ecdbac3d731
  • alt-php81-devel-8.1.34-11.el9.x86_64.rpm
    sha:6d21b543e01a535a27009445515834165926b6610a6d2a27dc571b799a5d3165
  • alt-php81-enchant-8.1.34-11.el9.x86_64.rpm
    sha:b04468e570111c0d1c0ed3f7d6639d7e814b03c586276a2b72426dee5f96b5d3
  • alt-php81-firebird-8.1.34-11.el9.x86_64.rpm
    sha:92af63768dddcb61c76d653a996bc999463847e30a90cf5353bcb571b7c7feae
  • alt-php81-gd-8.1.34-11.el9.x86_64.rpm
    sha:92e5d2bc7b9897a04e7d4820d89918c503bfbb79ee33143992b438f872398bcb
  • alt-php81-gmp-8.1.34-11.el9.x86_64.rpm
    sha:d98f50141ad816eb57b05f28777e4d53f4c158895f7f85dcaf42ff7f90802c2d
  • alt-php81-imap-8.1.34-11.el9.x86_64.rpm
    sha:a827f1457507a569366fe55f81bc4a20e10478e20354bc03a73048aced4a8b7a
  • alt-php81-intl-8.1.34-11.el9.x86_64.rpm
    sha:ecc9c760a37b1796ebd51cebf557564b731cecacfbe85965fea6dbba2c926596
  • alt-php81-ldap-8.1.34-11.el9.x86_64.rpm
    sha:e2cedad89453977337716654c95be10d2afc8725198403fd2c28fa9b3e6ac48e
  • alt-php81-mbstring-8.1.34-11.el9.x86_64.rpm
    sha:8fa87c30b8cca090ef782e453d9d3401b509ee969a301ffdc9af5bf495dddd5a
  • alt-php81-mysqlnd-8.1.34-11.el9.x86_64.rpm
    sha:2cef7ebd67d1082843bb5362074edfd9b11c8449678e8e60c3ff86f02c696075
  • alt-php81-odbc-8.1.34-11.el9.x86_64.rpm
    sha:2e5d3ed0b4559f23ec3607a002ee70f0a47552236b12f4ca7263fd6f44b032fa
  • alt-php81-opcache-8.1.34-11.el9.x86_64.rpm
    sha:da823da9654e5e87c3903fa51d9ade83b0ad5296c2eb626c5509ec13eaa91b99
  • alt-php81-pdo-8.1.34-11.el9.x86_64.rpm
    sha:30502e7541fe3a8382ab5245f4f6a5e90ae58b387506f1107ae1209b4509e286
  • alt-php81-pgsql-8.1.34-11.el9.x86_64.rpm
    sha:2da1f93baf909056661921c7b870f448f2e46e12681f43380e9f0c95614a8abc
  • alt-php81-php-fpm-8.1.34-11.el9.x86_64.rpm
    sha:f3caa6a3ff644273e23d83b08dc5ef35182248d5fd7e8b0b2cb75018f0756dd3
  • alt-php81-process-8.1.34-11.el9.x86_64.rpm
    sha:a9c0e53d39b50baa9e46792c7c3d8c5b302c3ccc7f134576f3968d42b7b68c79
  • alt-php81-pspell-8.1.34-11.el9.x86_64.rpm
    sha:3e5b6bb03de45ba27b45ff5aa56cd82ead69f35c5c80fdf2eaabb1bf51835f79
  • alt-php81-snmp-8.1.34-11.el9.x86_64.rpm
    sha:f39a4df45a8171cfc92f962f8e112e31622549867510db8a98573ea8bdebbbbf
  • alt-php81-soap-8.1.34-11.el9.x86_64.rpm
    sha:39ddfe567bc35ce4e3f0948b9c5b594fe996bc5baa3ab3c146d61ce6ec7207a5
  • alt-php81-sodium-8.1.34-11.el9.x86_64.rpm
    sha:f804f0c572d65363f36abe71f9028b3629d13d7112ae0a8f79cc53fd55979ecd
  • alt-php81-tidy-8.1.34-11.el9.x86_64.rpm
    sha:3fb6f65496a1882400eab48e39f526fba6d1f2dd4fa74d5ca19065dfb0ef54eb
  • alt-php81-xml-8.1.34-11.el9.x86_64.rpm
    sha:2df5397c5bad412bbf4f44467a3a4fbea7c4ff51d83b82d49fbafec2b7497c87
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.