[CLSA-2026:1779390103] alt-php55: Fix of 4 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-21 19:01:49 UTC
Description:
- CVE-2026-6722: soap extension use-after-free via apache:Map duplicate keys (5.5 backport applies addref half only; ref_map ZVAL_PTR_DTOR is intentionally omitted because ref_map is heterogeneous in 5.x and the dtor would corrupt the xmlNodePtr entries — see patch header) - CVE-2026-7262: soap extension NULL pointer deref via apache:Map missing value - CVE-2026-7261: soap extension use-after-free with SOAP_PERSISTENCE_SESSION header parsing failure - CVE-2026-6735: php-fpm status endpoint XSS via unescaped request_uri and query_string (5.5 backport applies HTML entity escape to both HTML and JSON /status endpoints since php_json_encode_string() isn't exported on 5.x — JSON consumers will see HTML entities in request_uri/query_string fields)
Updated packages:
  • alt-php55-5.5.38-159.el8.x86_64.rpm
    sha:108de54c205210dfc8d7ebb280e497e171137dfef0c77bd36a893cadad692a00
  • alt-php55-bcmath-5.5.38-159.el8.x86_64.rpm
    sha:1de58019ac8fa3b6c9572092fe84ae6ae6e3b639861da0b0ee504524ede916aa
  • alt-php55-cli-5.5.38-159.el8.x86_64.rpm
    sha:71bddfdfba36e96de95111b19051464fc59758a470299e5a9ff8b6bc4667584d
  • alt-php55-common-5.5.38-159.el8.x86_64.rpm
    sha:e06a57b6c818b3f05909be4ceffc05b713a9bc7478078980b621570c62435961
  • alt-php55-dba-5.5.38-159.el8.x86_64.rpm
    sha:e2485da344176c113c8f0f7891956ccd36528b555d141d0a2ae5300437ff9d4c
  • alt-php55-dbx-5.5.38-159.el8.x86_64.rpm
    sha:acc4a9c8fab6334f6ab77fdc2297457c0dc7d4a81b7702a83a7d30caa079afc6
  • alt-php55-devel-5.5.38-159.el8.x86_64.rpm
    sha:a3c93860496917fe070ffb777db513acb1f89e30a461f167c907f1ae21292dcf
  • alt-php55-enchant-5.5.38-159.el8.x86_64.rpm
    sha:34eb603de91036b407c31fd62d1788412beda54602f1ffde9f26569046cb62e9
  • alt-php55-firebird-5.5.38-159.el8.x86_64.rpm
    sha:17e13b53e03583f139d74fc36169adb34889183ad1591d2eff142446b911d723
  • alt-php55-gd-5.5.38-159.el8.x86_64.rpm
    sha:aade86b6eb9bb3a1e0ca6776a91e7bfdb3912e6bd6c5d165c6d0fe753277c30a
  • alt-php55-imap-5.5.38-159.el8.x86_64.rpm
    sha:a47e36316cca341084d13c3c02ac36c39516c38d6bd3792f7d4f4c99cb882bea
  • alt-php55-intl-5.5.38-159.el8.x86_64.rpm
    sha:1c9ab012133880666943b97b9e83a0d7cbe797620b241c875e2523cad6dee926
  • alt-php55-ldap-5.5.38-159.el8.x86_64.rpm
    sha:4bbe90602cf4af01e9350c4fd0a476ab301e11fc29d1a252d7ed768904795733
  • alt-php55-mbstring-5.5.38-159.el8.x86_64.rpm
    sha:219d6f62b14196125afd4173a037750d57cac5ed9b107ca86a63318be7b4dda1
  • alt-php55-mcrypt-5.5.38-159.el8.x86_64.rpm
    sha:171a372d276095cae9c02e13712582baba5b387a599132376474f977788f711a
  • alt-php55-mssql-5.5.38-159.el8.x86_64.rpm
    sha:499f3a55dc2e83981dd5aae3a63f1c6e0751e9220d5e5b3f1cfadd8eada16879
  • alt-php55-mysqlnd-5.5.38-159.el8.x86_64.rpm
    sha:3d083e8d67d30b7aa16e362f75fd35f55369325322eb9f22ee49ac883098ce74
  • alt-php55-odbc-5.5.38-159.el8.x86_64.rpm
    sha:1c217bf17fb48e4921daa4d1f857f658c24c0446f1385d7e7daa2ed197573ad4
  • alt-php55-opcache-5.5.38-159.el8.x86_64.rpm
    sha:430a02cbe159972a1612084f39499de7f764eb76ad5e6c9cfb28061acc96e811
  • alt-php55-pdo-5.5.38-159.el8.x86_64.rpm
    sha:64d41a587b2f62dc37864e543226e2370838aac75385e128436944ded80fde21
  • alt-php55-pgsql-5.5.38-159.el8.x86_64.rpm
    sha:8f3a02cc1b51b51bbbd736ef1af343ad3d0216e543eefc009ee2b998e9091465
  • alt-php55-php-fpm-5.5.38-159.el8.x86_64.rpm
    sha:c55a8bc4ba5ad5cb3f348dbfa9890872e73ff0696d9850ed89778a6a1ebe6c28
  • alt-php55-process-5.5.38-159.el8.x86_64.rpm
    sha:eb6ac070b7477a942a9fe6b3b7ff278304ad05d27d8f9a5594de78cdae248a7e
  • alt-php55-pspell-5.5.38-159.el8.x86_64.rpm
    sha:90eb96eb94402214a12a08062fbf4414418d7630eac2edf406772b57ebdb4fc3
  • alt-php55-recode-5.5.38-159.el8.x86_64.rpm
    sha:8cd5414d1422c81228735f4308ab37b47d5784c272a0eeaebc73081a693938a0
  • alt-php55-snmp-5.5.38-159.el8.x86_64.rpm
    sha:b423c23268a7a6f0a3382cfe5bda74332d9d58a8e56ee7677587317ffdf94de4
  • alt-php55-soap-5.5.38-159.el8.x86_64.rpm
    sha:dfc4b95cc2b56ce764546b840d7116dff346ba80722d237b8316bbbeb9ee347d
  • alt-php55-sybase-5.5.38-159.el8.x86_64.rpm
    sha:022c3ba6c1813f4828644d3fea53f58d9100400504551caa92da55447762a58b
  • alt-php55-tidy-5.5.38-159.el8.x86_64.rpm
    sha:692f9b8abcaf8262a77175034ce780df5b5b9b61fe78b1fcc8d2dccf39842c02
  • alt-php55-xml-5.5.38-159.el8.x86_64.rpm
    sha:28dcb487032a31df6607631cc94e3bad51b90c2d5fcbad783b6805b581d1b65a
  • alt-php55-xmlrpc-5.5.38-159.el8.x86_64.rpm
    sha:f275caa16c40ac1223a17afd25938af09b9e58d74d49c17cfb56dfd280cc46af
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.