[CLSA-2026:1779469715] Fix of 5 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-22 17:08:50 UTC
Description:
* SECURITY UPDATE: soap extension use-after-free via apache:Map duplicate keys - debian/patches/php-7.4-CVE-2026-6722.patch: backport upstream commit aee3b3ac9b in ext/soap/php_encoding.c — add Z_TRY_ADDREF_P on soap_add_xml_ref insertion and change SOAP_GLOBAL(ref_map) destructor to ZVAL_PTR_DTOR. - CVE-2026-6722 * SECURITY UPDATE: soap extension NULL pointer dereference via apache:Map item missing element - debian/patches/php-7.4-CVE-2026-7262.patch: backport upstream commit 79551ab8b1 in ext/soap/php_encoding.c — fix typo'd null check in to_zval_map() (was checking xmlKey, should check xmlValue). - CVE-2026-7262 * SECURITY UPDATE: php-fpm status endpoint XSS via unescaped request_uri - debian/patches/php-7.4-CVE-2026-6735.patch: backport upstream commit 99a5ad7441 in sapi/fpm/fpm/fpm_status.c — escape proc.request_uri with php_escape_html_entities_ex() and fix the broken "ENT_HTML_IGNORE_ERRORS & ENT_COMPAT" flag (bitwise-AND of two flag constants evaluates to 0). Adapted to 7.x layout (struct access "proc.X", single encode flag, older 6-arg php_escape_html_entities_ex signature). - CVE-2026-6735 * SECURITY UPDATE: soap SoapServer use-after-free after header parsing failure when SOAP_PERSISTENCE_SESSION is set - debian/patches/php-7.4-CVE-2026-7261.patch: backport upstream commit db2a7f9348 in ext/soap/soap.c — guard both zval_ptr_dtor(soap_obj) call sites in PHP_METHOD(SoapServer, handle) with "if (service->soap_class.persistence != SOAP_PERSISTENCE_SESSION)". - CVE-2026-7261 * SECURITY UPDATE: metaphone() signed integer overflow on >INT_MAX input - debian/patches/php-7.4-CVE-2026-7568.patch: backport upstream commit 47def8ce1d in ext/standard/metaphone.c — retype w_idx and Lookahead's how_far/idx from int to size_t to avoid signed overflow while walking strings larger than 2 GB on 64-bit builds. - CVE-2026-7568
Updated packages:
  • alt-php74_7.4.33-55_amd64.deb
    sha:a366dd82802c5d904f0cf6f343d926deded8d04c
  • alt-php74-bcmath_7.4.33-55_amd64.deb
    sha:9c9c9c02311a2fbacd741d924ef5b77c94f5c371
  • alt-php74-cli_7.4.33-55_amd64.deb
    sha:92c42ea4a1ac6e02978dd8a9d54811198139fa23
  • alt-php74-common_7.4.33-55_amd64.deb
    sha:d78a6973ba56e48509cc43babc11161e574c1185
  • alt-php74-dba_7.4.33-55_amd64.deb
    sha:b48e2559efd00e633bde146f3229414237c8e689
  • alt-php74-dev_7.4.33-55_amd64.deb
    sha:3a02eae3a2f6d8707693a7c3b2332a5c51c087dc
  • alt-php74-enchant_7.4.33-55_amd64.deb
    sha:0165c90dc8d53b668ad30d0c27728a993f6dbdcc
  • alt-php74-firebird_7.4.33-55_amd64.deb
    sha:deeeedf5436b5e9c20bb80e8ce77d084915304bc
  • alt-php74-fpm_7.4.33-55_amd64.deb
    sha:23f29c080bb36778970f0447ddc247667a14e022
  • alt-php74-gd_7.4.33-55_amd64.deb
    sha:0bfb964308992c471d64b068591b9c47e5606831
  • alt-php74-imap_7.4.33-55_amd64.deb
    sha:f559a60a472659042220761695f19675757a8e37
  • alt-php74-intl_7.4.33-55_amd64.deb
    sha:f710d91497604cb8644a779be1a518800f755f83
  • alt-php74-ldap_7.4.33-55_amd64.deb
    sha:aab1e358f2a7c90937ca75d6ea82c716f87fbb6c
  • alt-php74-mbstring_7.4.33-55_amd64.deb
    sha:2e893c5b6a4e750ef289fd0c9c955b6eb4690d0b
  • alt-php74-mysqlnd_7.4.33-55_amd64.deb
    sha:568341568cc40b8db96c5dd2ad96367966fca2c0
  • alt-php74-odbc_7.4.33-55_amd64.deb
    sha:c15415c349abd37c41c0a5440bbe1b8a06810a6f
  • alt-php74-opcache_7.4.33-55_amd64.deb
    sha:5099bbe75e10a3eb2cbbe042e5994552a1572291
  • alt-php74-pdo_7.4.33-55_amd64.deb
    sha:ba4aa538434db0389bbe5e24e651cfcb52ac9275
  • alt-php74-pgsql_7.4.33-55_amd64.deb
    sha:3d012a59ecb78c7b45c044d31de4f404266574d9
  • alt-php74-process_7.4.33-55_amd64.deb
    sha:f4f1f20d2eef78353b237937a8492816639eda64
  • alt-php74-pspell_7.4.33-55_amd64.deb
    sha:b676262af56b05553733413dcf74382184c2377a
  • alt-php74-snmp_7.4.33-55_amd64.deb
    sha:b6056a21437fa6927385d16f321710ef65bcb806
  • alt-php74-soap_7.4.33-55_amd64.deb
    sha:79b8a4e62e632ecbde194c0290ffcaec8eb685d8
  • alt-php74-sodium_7.4.33-55_amd64.deb
    sha:24140b2408ce61335cf43c2a8dcc8958d2ed42c3
  • alt-php74-tidy_7.4.33-55_amd64.deb
    sha:437565eedc1d4f643c283d2096265cbba987c871
  • alt-php74-xml_7.4.33-55_amd64.deb
    sha:05b7a22f9bb053bd80781bd76893be3d0fa9f8ac
  • alt-php74-xmlrpc_7.4.33-55_amd64.deb
    sha:da39b96a9457dbc237cd81d4b9d2584c42015a96
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.