[CLSA-2026:1779363568] alt-php56: Fix of 4 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-21 11:39:48 UTC
Description:
- CVE-2026-6722: soap extension use-after-free via apache:Map duplicate keys (5.6 backport applies addref half only; ref_map ZVAL_PTR_DTOR is intentionally omitted because ref_map is heterogeneous in 5.x and the dtor would corrupt the xmlNodePtr entries — see patch header) - CVE-2026-7262: soap extension NULL pointer deref via apache:Map missing value - CVE-2026-7261: soap extension use-after-free with SOAP_PERSISTENCE_SESSION header parsing failure - CVE-2026-6735: php-fpm status endpoint XSS via unescaped request_uri and query_string (5.6 backport applies HTML entity escape to both HTML and JSON /status endpoints since php_json_encode_string() isn't exported on 5.x — JSON consumers will see HTML entities in request_uri/query_string fields)
Updated packages:
  • alt-php56-5.6.40-122.el10.x86_64.rpm
    sha:24c342087a8d941dd6abad27174c5aa3d4d20e6fd61a8c14eb2aedbf16fcf2f4
  • alt-php56-bcmath-5.6.40-122.el10.x86_64.rpm
    sha:e9bff03dbedf9abe2851b64a345a17e6db608fe4cd9770f18a2e27a91c937612
  • alt-php56-cli-5.6.40-122.el10.x86_64.rpm
    sha:36c63a050143430757773b2a0ffc2c36ec044a87e155ea49b1b675e73594f06b
  • alt-php56-common-5.6.40-122.el10.x86_64.rpm
    sha:ff43e75f345ef7abf6d14181a404900e4e66c1ba3af1912a77484ed9f5b057a4
  • alt-php56-dba-5.6.40-122.el10.x86_64.rpm
    sha:415182aebb72ac3adc0adc6086c685ade23726301ff3be286b65f8af28a9227f
  • alt-php56-dbx-5.6.40-122.el10.x86_64.rpm
    sha:e3e06a166d3b23b76eb406d97e138ece50d6168d75b46925680d368ccd9d4b44
  • alt-php56-devel-5.6.40-122.el10.x86_64.rpm
    sha:e2e645fad3646694d1fb843120aabd9848a6526466bdac7fb9cbef7b71fbc6bd
  • alt-php56-enchant-5.6.40-122.el10.x86_64.rpm
    sha:1cfb9e9c02f0fc6454561257580f10c49ec8b86202bb16c966bbf4b461f628ab
  • alt-php56-firebird-5.6.40-122.el10.x86_64.rpm
    sha:ddc2220a612f532c1b5bb58735a83fea3245186537c1125714c14588770abfa7
  • alt-php56-gd-5.6.40-122.el10.x86_64.rpm
    sha:39a1e909958aac7a5e2e009a3e4007ffdf043ad52cefa0a045f8bed11605fd3d
  • alt-php56-imap-5.6.40-122.el10.x86_64.rpm
    sha:9c37a15990626fbae2c3afcee2dad62dcdce81c35469e96275535fa5b4ccb3f9
  • alt-php56-intl-5.6.40-122.el10.x86_64.rpm
    sha:f928ee6e50fc39b261e154225a8fa6b1d5a4538d5e8422068dabccd7eae64abb
  • alt-php56-ldap-5.6.40-122.el10.x86_64.rpm
    sha:bdc9a1d20263ff5b82677c7655d064bba68e91e2ba649950d78a4bd9a26c72ac
  • alt-php56-mbstring-5.6.40-122.el10.x86_64.rpm
    sha:ace14aadbcf221897b965bd157dd69a2c54a70486dfe224ac724174114ed00ca
  • alt-php56-mcrypt-5.6.40-122.el10.x86_64.rpm
    sha:6ab19d51e9ee667814a3827c08cae46e1edcdcf3a9ea8103c1d203cb5df07240
  • alt-php56-mssql-5.6.40-122.el10.x86_64.rpm
    sha:8acb409b206dd25df19b759a6cd39abfbd2e657300ef94b58ebca72b17fb4624
  • alt-php56-mysqlnd-5.6.40-122.el10.x86_64.rpm
    sha:14498190aff206b6c5f04de88bd50bfe335cbd4c47a1398fea9eda9dc6f15bef
  • alt-php56-odbc-5.6.40-122.el10.x86_64.rpm
    sha:8b94851b417816c714065eb1e15e636eedee8d2cfc52b56978397a345b401e54
  • alt-php56-opcache-5.6.40-122.el10.x86_64.rpm
    sha:f625325e1c1b7d42b8ee33273a94550052f04048e2e32bdfd3643fd1bcca569e
  • alt-php56-pdo-5.6.40-122.el10.x86_64.rpm
    sha:7ae78f0d4d188e0b3c44b384b45ef1c35bfb128767d3d74857286532b0e3f84c
  • alt-php56-pgsql-5.6.40-122.el10.x86_64.rpm
    sha:f65f37224f7c7d7e456f956cb35fbd2fb55294054e1addfaecc9525d0e66d228
  • alt-php56-php-fpm-5.6.40-122.el10.x86_64.rpm
    sha:05b118f01e859d5885c3abaa23025b84caac9da3668f27d4a801957f7b2f716f
  • alt-php56-process-5.6.40-122.el10.x86_64.rpm
    sha:14f88e47d81c39dc7861ab6f131edfcc77fb6f6556158160c3d99ed3c5f5d462
  • alt-php56-pspell-5.6.40-122.el10.x86_64.rpm
    sha:46333d6f4789e151b058da13a806ce2a57e3ec5243676354d779d795e2163ba6
  • alt-php56-recode-5.6.40-122.el10.x86_64.rpm
    sha:d9d882df1a281bb2b1ec8b29caed62be8a7d4e83cb11b784b792817b797d3365
  • alt-php56-snmp-5.6.40-122.el10.x86_64.rpm
    sha:82965efdb3ec0d517eac74153b610f9deaa82a7be65b4f523a8d995c50e6bfb1
  • alt-php56-soap-5.6.40-122.el10.x86_64.rpm
    sha:49a5991ca11a3c2092f0a2036f524ac832b5989dbed969be7ae16ff9fdb456ac
  • alt-php56-sybase-5.6.40-122.el10.x86_64.rpm
    sha:57329359494c635739047223fb7edc491bda505e4782c2dae45ccd134bdfaaca
  • alt-php56-tidy-5.6.40-122.el10.x86_64.rpm
    sha:26ae527fceb7d3e6a5e2acd62588313d5a46151c18d49df3ce55593a3ec80661
  • alt-php56-xml-5.6.40-122.el10.x86_64.rpm
    sha:6d2616b7f59d29f24c14d9bb8f51a6c7ab0e39d1c0c4721b5a24097a2aed965f
  • alt-php56-xmlrpc-5.6.40-122.el10.x86_64.rpm
    sha:b1bfbfae383aace5f4b2bccca5b0339d163f00c04429c135f889944b4135e9d3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.