[CLSA-2026:1779375064] alt-php55: Fix of 4 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-21 14:51:09 UTC
Description:
- CVE-2026-6722: soap extension use-after-free via apache:Map duplicate keys (5.5 backport applies addref half only; ref_map ZVAL_PTR_DTOR is intentionally omitted because ref_map is heterogeneous in 5.x and the dtor would corrupt the xmlNodePtr entries — see patch header) - CVE-2026-7262: soap extension NULL pointer deref via apache:Map missing value - CVE-2026-7261: soap extension use-after-free with SOAP_PERSISTENCE_SESSION header parsing failure - CVE-2026-6735: php-fpm status endpoint XSS via unescaped request_uri and query_string (5.5 backport applies HTML entity escape to both HTML and JSON /status endpoints since php_json_encode_string() isn't exported on 5.x — JSON consumers will see HTML entities in request_uri/query_string fields)
Updated packages:
  • alt-php55-5.5.38-159.el9.x86_64.rpm
    sha:b3e4ead8ecc7248cf6a3741a838abecd25c858341f2408023dbc6e9abaaf51d1
  • alt-php55-bcmath-5.5.38-159.el9.x86_64.rpm
    sha:327d5bad1c7ba8867603e496a68c9d9189abc4dc2a43d460ab08344283bd010c
  • alt-php55-cli-5.5.38-159.el9.x86_64.rpm
    sha:095737a57efef7ca14cbb930a34ba80ebb6fb9591fca5abb73117d7d97987e1d
  • alt-php55-common-5.5.38-159.el9.x86_64.rpm
    sha:d26d5c2681f07c6c3c01adc617efd55c2b333b10386d754e8e8c63d15d154161
  • alt-php55-dba-5.5.38-159.el9.x86_64.rpm
    sha:121c56da4f6f1c7894a3c88fa85f1f241a36834cb05a716ac5acddbad2d98047
  • alt-php55-dbx-5.5.38-159.el9.x86_64.rpm
    sha:829bd1e61596ec96259cf5716539d97ee4b228035b3e1819e15209f708031ea5
  • alt-php55-devel-5.5.38-159.el9.x86_64.rpm
    sha:30755e8de752ee86fdcf5dd13446b393cdb414ff9c7ae37df4be5f111d2b9bdf
  • alt-php55-enchant-5.5.38-159.el9.x86_64.rpm
    sha:dd9f5ff2148d556051b24d299bebcf68321847665291a47210afca8f8cd62253
  • alt-php55-firebird-5.5.38-159.el9.x86_64.rpm
    sha:8a94febda73a2858d86a01f543bc983088916e33faa08f88ecb57cb968a2fb78
  • alt-php55-gd-5.5.38-159.el9.x86_64.rpm
    sha:52618f63fb8eef3e9abcabf407c9d667c4853f4cee1a97feb37edd0ad1af3688
  • alt-php55-imap-5.5.38-159.el9.x86_64.rpm
    sha:a796e51cf224b55be8f3fe07f67fe1f17328a2764dd4e7bdba23cb8ac13f9103
  • alt-php55-intl-5.5.38-159.el9.x86_64.rpm
    sha:ce30b861de3f759b9d38bbad503109c189eb60d2f15372e70b6af08fa94d09cc
  • alt-php55-ldap-5.5.38-159.el9.x86_64.rpm
    sha:67a61db15c874e023045cd4da54e45e08c9b3c277151d85381d73cab3b670b80
  • alt-php55-mbstring-5.5.38-159.el9.x86_64.rpm
    sha:d8505bfe8eb2c7fb5fdc1ae080102ff29043fd1a5e1e9a21126d9a91c337c484
  • alt-php55-mcrypt-5.5.38-159.el9.x86_64.rpm
    sha:8e6f915484cb3a184e46be8ec905598c9e32176a4080fc085e423213efc7867c
  • alt-php55-mssql-5.5.38-159.el9.x86_64.rpm
    sha:fee0eda210ed34bd90d7c303ef5c768ddbf997794f983f4626b8a432d7d7d375
  • alt-php55-mysqlnd-5.5.38-159.el9.x86_64.rpm
    sha:daf07bbdfc0fa9c1627c74205efcafaeb7b8f85bef733195d7e284485a58d13c
  • alt-php55-odbc-5.5.38-159.el9.x86_64.rpm
    sha:f8c5f740e6b76299973ac9dfbeb34652bec3ba582fed3db95e77dbe818d040c0
  • alt-php55-opcache-5.5.38-159.el9.x86_64.rpm
    sha:1e6065e28de4dedb37c07d24b0a4d3c131064a9804c46d37ad4cd8a3a9fae874
  • alt-php55-pdo-5.5.38-159.el9.x86_64.rpm
    sha:0f4530ba0ef0639ac336209f0e530e4d3b6deaf7a98b0362cc61d3a2bf446638
  • alt-php55-pgsql-5.5.38-159.el9.x86_64.rpm
    sha:251eea41dfe3beb0d3b9e95cbf49534fe66ea923eebc22a524249e80a766aee9
  • alt-php55-php-fpm-5.5.38-159.el9.x86_64.rpm
    sha:495adbeb9df9614f241be6929fc8cec054dcebf24d8d5ddf0390b51c67448922
  • alt-php55-process-5.5.38-159.el9.x86_64.rpm
    sha:2d0e4b197298b5805c15e4fcda01062dd007f19cc4015f78a9d530277127cf64
  • alt-php55-pspell-5.5.38-159.el9.x86_64.rpm
    sha:2f43c301bc4a5f54cfc3752aed0cd591de43423c2b62d266ee7cb615403b5715
  • alt-php55-recode-5.5.38-159.el9.x86_64.rpm
    sha:9b410b8d631235d8521461acdbf02c90c1395117eeec7fadae9c3757aa0a007f
  • alt-php55-snmp-5.5.38-159.el9.x86_64.rpm
    sha:3984175bd710f30591eecb879c501d2ebf502547c8eeeb1bed83c5730d08d2ad
  • alt-php55-soap-5.5.38-159.el9.x86_64.rpm
    sha:bfc6bde0a48b73d487cc61f2381567e9db76ae3ad9ed330eb468d420b10eda26
  • alt-php55-sybase-5.5.38-159.el9.x86_64.rpm
    sha:fed21a71b7953f57e3dfb289e129fe76df6478c398623fafaf3351e17c660f3e
  • alt-php55-tidy-5.5.38-159.el9.x86_64.rpm
    sha:be86b3860181609b470495d9c57c9869368efa3460b4c83ba27e3e04c96fa221
  • alt-php55-xml-5.5.38-159.el9.x86_64.rpm
    sha:cb8a0db0a41b03911fbbbda1a97478bdb83143545cc48fbafbc41a6b1343b0e6
  • alt-php55-xmlrpc-5.5.38-159.el9.x86_64.rpm
    sha:7bb36a0b4092caee212272dc4c0403e5835e6bf8fc00e0afa9ec195a29017c7d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.