[CLSA-2026:1779366899] alt-php56: Fix of 4 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-21 14:21:52 UTC
Description:
- CVE-2026-6722: soap extension use-after-free via apache:Map duplicate keys (5.6 backport applies addref half only; ref_map ZVAL_PTR_DTOR is intentionally omitted because ref_map is heterogeneous in 5.x and the dtor would corrupt the xmlNodePtr entries — see patch header) - CVE-2026-7262: soap extension NULL pointer deref via apache:Map missing value - CVE-2026-7261: soap extension use-after-free with SOAP_PERSISTENCE_SESSION header parsing failure - CVE-2026-6735: php-fpm status endpoint XSS via unescaped request_uri and query_string (5.6 backport applies HTML entity escape to both HTML and JSON /status endpoints since php_json_encode_string() isn't exported on 5.x — JSON consumers will see HTML entities in request_uri/query_string fields)
Updated packages:
  • alt-php56-5.6.40-122.el9.x86_64.rpm
    sha:f94c47cb9b5c586f8b0edbe9c374173295e6dedec0379280f943b6f79b72ee68
  • alt-php56-bcmath-5.6.40-122.el9.x86_64.rpm
    sha:3ceaab4bc37ccc3f35887fba311a7a97e50b0d85e4b1b9a9b18c596c94187a6a
  • alt-php56-cli-5.6.40-122.el9.x86_64.rpm
    sha:10e3c742b0aaa3ee3203c65d0b894b303fa389b17bd5b6e7da7138d5ead5f626
  • alt-php56-common-5.6.40-122.el9.x86_64.rpm
    sha:793d7405a846e1b199e118d365da439f03b8a5fda6df5369bd81a62de177e95f
  • alt-php56-dba-5.6.40-122.el9.x86_64.rpm
    sha:7c8c88830b5b5733b3fb78df2657fc57621e4910b80303b98d2ac75c07bf5582
  • alt-php56-dbx-5.6.40-122.el9.x86_64.rpm
    sha:c85ba6723e682a2907e9b3286d0d9570ed76bc540d34d6562341691d742aef7c
  • alt-php56-devel-5.6.40-122.el9.x86_64.rpm
    sha:fd30e2ee191c7862b89b9002f18c1a8b0de700f29dac713b0e979897367a0a04
  • alt-php56-enchant-5.6.40-122.el9.x86_64.rpm
    sha:3c15127472ad19a040ba91ba24d06fd64fd743dff1b3dda43d5f9e801dbaa286
  • alt-php56-firebird-5.6.40-122.el9.x86_64.rpm
    sha:8a681e7f8f9f0d21c4db67e676d473464fa694a36fdb307b137bdac43f5c8d96
  • alt-php56-gd-5.6.40-122.el9.x86_64.rpm
    sha:55bdbd542a1fddb9bd7699a844793d26db4b971e47286f917affd12e8022a3b9
  • alt-php56-imap-5.6.40-122.el9.x86_64.rpm
    sha:c1812f020b07b0c7d2975972a97c2d28fb6d07bdffcec4bd45078f5abecb4282
  • alt-php56-intl-5.6.40-122.el9.x86_64.rpm
    sha:a5b3f6f6a1fe43988ec89f2bf3812c989ede20f2b88adc4064dabab79fb53bef
  • alt-php56-ldap-5.6.40-122.el9.x86_64.rpm
    sha:283b46e4b900357536144882261e9f0cb26ad1bab8f7f25c8bf4d44ea78215ef
  • alt-php56-mbstring-5.6.40-122.el9.x86_64.rpm
    sha:16971a94e1bd73b03f08b9095ce0051dc19596477c2faa0a741da9688511a3f7
  • alt-php56-mcrypt-5.6.40-122.el9.x86_64.rpm
    sha:51840528c3ed241b57518ea1c3a669de85a787777f70621d56b862c06196a30a
  • alt-php56-mssql-5.6.40-122.el9.x86_64.rpm
    sha:3c8996ddb5002299d18c1f289c37899cc1922038d6d54bba7e25157ec49b2b45
  • alt-php56-mysqlnd-5.6.40-122.el9.x86_64.rpm
    sha:909eac2741b5dfde7cb79b0cbc0eb1e6f7a498f013b927d1f54e952c4a7354b0
  • alt-php56-odbc-5.6.40-122.el9.x86_64.rpm
    sha:791974b627e44a787ff5b16d4bc533f6bc3ba622ee73f442c870599cecfd6c62
  • alt-php56-opcache-5.6.40-122.el9.x86_64.rpm
    sha:337c509c375ad5e65d15af1988c5ac7303b69f28565ad8abcf624d592667d757
  • alt-php56-pdo-5.6.40-122.el9.x86_64.rpm
    sha:4ce22f687007a26258b2f8d4412f9be6017ec5fd181981df4304d4c8de9ba8d0
  • alt-php56-pgsql-5.6.40-122.el9.x86_64.rpm
    sha:1c2fdae8432f8174384472064241e7af30f834401c9fe9a1ab971607618cc9cf
  • alt-php56-php-fpm-5.6.40-122.el9.x86_64.rpm
    sha:8f10576b9a5055ed70d99e68006241d01f5acdd4078f3635de209485fe00899d
  • alt-php56-process-5.6.40-122.el9.x86_64.rpm
    sha:9591099e7ab1c71203393f374b7d99a8167916044fb216da4d81f19dbf25f6f0
  • alt-php56-pspell-5.6.40-122.el9.x86_64.rpm
    sha:6fba96ff67522db151bc13066b8a8cfb3ca07cd10a8aebf5bb39fd3aea2293dc
  • alt-php56-recode-5.6.40-122.el9.x86_64.rpm
    sha:1fda8d8aa6f60fcb3a6ba8fe994dd462c9a69c3b5d311027feffef1aeaf30d9a
  • alt-php56-snmp-5.6.40-122.el9.x86_64.rpm
    sha:e64c83bc874e2a46437ec6e4c11a018762e6250030b2789e5154e8f136474a79
  • alt-php56-soap-5.6.40-122.el9.x86_64.rpm
    sha:90b7dc9da80ddf2ae4a41f5365406642b533782bd8638b6f1fc9996bafca76d6
  • alt-php56-sybase-5.6.40-122.el9.x86_64.rpm
    sha:8f65291c198417ae06d153ed7f11be3a55c65aed3e026e7158ff2b19ae456f87
  • alt-php56-tidy-5.6.40-122.el9.x86_64.rpm
    sha:a2d142f9464f3babb142695bf14de99a3403c82532b228019b9117fa1a406488
  • alt-php56-xml-5.6.40-122.el9.x86_64.rpm
    sha:cae7fe15671f7aeeb2d211a6d2dc5d2afc4bbcac8816a7aef54ca6771b93e65e
  • alt-php56-xmlrpc-5.6.40-122.el9.x86_64.rpm
    sha:73ccc045d0a952ba920b76b89289a0c5955fb7e68fa92a8e56553908714f1811
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.