[CLSA-2026:1779464307] Fix of 5 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-22 15:38:32 UTC
Description:
* SECURITY UPDATE: soap extension use-after-free via apache:Map duplicate keys - debian/patches/php-7.3-CVE-2026-6722.patch: backport upstream commit aee3b3ac9b in ext/soap/php_encoding.c — add Z_TRY_ADDREF_P on soap_add_xml_ref insertion and change SOAP_GLOBAL(ref_map) destructor to ZVAL_PTR_DTOR. - CVE-2026-6722 * SECURITY UPDATE: soap extension NULL pointer dereference via apache:Map item missing element - debian/patches/php-7.3-CVE-2026-7262.patch: backport upstream commit 79551ab8b1 in ext/soap/php_encoding.c — fix typo'd null check in to_zval_map() (was checking xmlKey, should check xmlValue). - CVE-2026-7262 * SECURITY UPDATE: php-fpm status endpoint XSS via unescaped request_uri - debian/patches/php-7.3-CVE-2026-6735.patch: backport upstream commit 99a5ad7441 in sapi/fpm/fpm/fpm_status.c — escape proc.request_uri with php_escape_html_entities_ex() and fix the broken "ENT_HTML_IGNORE_ERRORS & ENT_COMPAT" flag (bitwise-AND of two flag constants evaluates to 0). Adapted to 7.x layout (struct access "proc.X", single encode flag, older 6-arg php_escape_html_entities_ex signature). - CVE-2026-6735 * SECURITY UPDATE: soap SoapServer use-after-free after header parsing failure when SOAP_PERSISTENCE_SESSION is set - debian/patches/php-7.3-CVE-2026-7261.patch: backport upstream commit db2a7f9348 in ext/soap/soap.c — guard both zval_ptr_dtor(soap_obj) call sites in PHP_METHOD(SoapServer, handle) with "if (service->soap_class.persistence != SOAP_PERSISTENCE_SESSION)". - CVE-2026-7261 * SECURITY UPDATE: metaphone() signed integer overflow on >INT_MAX input - debian/patches/php-7.3-CVE-2026-7568.patch: backport upstream commit 47def8ce1d in ext/standard/metaphone.c — retype w_idx and Lookahead's how_far/idx from int to size_t to avoid signed overflow while walking strings larger than 2 GB on 64-bit builds. - CVE-2026-7568
Updated packages:
  • alt-php73_7.3.33-59_amd64.deb
    sha:60a60f0dc3a400321dc47bf864bdbc6a42cde9cd
  • alt-php73-bcmath_7.3.33-59_amd64.deb
    sha:7b8e43d0ebe10786e26dc23a790d2ba77f1a726e
  • alt-php73-cli_7.3.33-59_amd64.deb
    sha:1d82f2cd85d768219969948b26af7fda3a84f85a
  • alt-php73-common_7.3.33-59_amd64.deb
    sha:6487456f6b55323fd51ba13453aa6dacb3b46d6d
  • alt-php73-dba_7.3.33-59_amd64.deb
    sha:b4ae44a574949345b83199e32207f24d3b73829b
  • alt-php73-dev_7.3.33-59_amd64.deb
    sha:bdfd2469d5e342817d044e9b9f174ead92ede649
  • alt-php73-enchant_7.3.33-59_amd64.deb
    sha:7071e386bd4d0337424ea02d7bae093c830a37d5
  • alt-php73-firebird_7.3.33-59_amd64.deb
    sha:6901388d74a18b4c522809da88a6feac2cf75cd3
  • alt-php73-fpm_7.3.33-59_amd64.deb
    sha:4ae262b4485f7f8a35e1651825411f4d2addf8ec
  • alt-php73-gd_7.3.33-59_amd64.deb
    sha:52a5fed219b770a52f115f70f7e585e17756552a
  • alt-php73-imap_7.3.33-59_amd64.deb
    sha:08402e900e1b261258dde63d04905ff1294b8678
  • alt-php73-intl_7.3.33-59_amd64.deb
    sha:1b1fa581020974058a29dc8f1fccbfe333802fc6
  • alt-php73-ldap_7.3.33-59_amd64.deb
    sha:d59cf409fdde020a066fafc1319c6f2bf4c3dd84
  • alt-php73-mbstring_7.3.33-59_amd64.deb
    sha:574af880ae0a138db4c4573a13f2f33b9b96ea0c
  • alt-php73-mysqlnd_7.3.33-59_amd64.deb
    sha:165e1ff6edf9f7351d8cc2ee73f43f9e9bef2f1c
  • alt-php73-odbc_7.3.33-59_amd64.deb
    sha:efb952f9251ae3db06c2b2dc6d501a6833a5017d
  • alt-php73-opcache_7.3.33-59_amd64.deb
    sha:39cfa67d2bf2469a71aa23023c1fdec372f4ef2d
  • alt-php73-pdo_7.3.33-59_amd64.deb
    sha:dee242b49854b5978f32b4f1b888c3636e155b6f
  • alt-php73-pgsql_7.3.33-59_amd64.deb
    sha:aafaf7a547f431b95234dde1d26b798f807e9549
  • alt-php73-process_7.3.33-59_amd64.deb
    sha:1e9960b8b803748adf1f4ba1c17ec12dc3d22023
  • alt-php73-pspell_7.3.33-59_amd64.deb
    sha:c7d085cc5cdfb39ef5eed7d60707b0a16c24b880
  • alt-php73-recode_7.3.33-59_amd64.deb
    sha:21cb0981a6b7de4870f62d771be69d27f4ec396e
  • alt-php73-snmp_7.3.33-59_amd64.deb
    sha:0daf8c7ba90cc15cb7f4a34026c2d420fef00b5f
  • alt-php73-soap_7.3.33-59_amd64.deb
    sha:b097c0a565afb526ca8fa680040e28be67afbdba
  • alt-php73-sodium_7.3.33-59_amd64.deb
    sha:9f046d173f74c043927fab316945072d3dc913ba
  • alt-php73-tidy_7.3.33-59_amd64.deb
    sha:97ef1452c5caec2db87a17b2ed1a5889b5511c60
  • alt-php73-xml_7.3.33-59_amd64.deb
    sha:063d2e8162f4c856398952b6afd8ac7cf41b460b
  • alt-php73-xmlrpc_7.3.33-59_amd64.deb
    sha:f72ad7477fa8e02a50cdb593631fdef81256b499
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.