[CLSA-2026:1779454400] php: Fix of 6 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-22 12:53:25 UTC
Description:
- CVE-2026-7262: fix broken Apache map value NULL check in soap encoder (GHSA-hmxp-6pc4-f3vv) - CVE-2026-7568: fix signed integer overflow of char array offset in metaphone (GHSA-96wq-48vp-hh57) - CVE-2026-7261: fix use-after-free after SOAP header parsing failure with SOAP_PERSISTENCE_SESSION (GHSA-m33r-qmcv-p97q) - CVE-2026-7258: fix out-of-bounds read in urldecode() via signed-char to ctype.h (GHSA-m8rr-4c36-8gq4) - CVE-2025-14179: fix SQL injection in pdo_firebird quoter via NUL bytes in quoted strings (GHSA-w476-322c-wpvm) - CVE-2026-6722: fix stale SOAP_GLOBAL ref_map pointer with Apache Map (GHSA-85c2-q967-79q5)
Updated packages:
  • php-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:7813ccd89a690993d2809147d355c68303060bdafebbbcd3b239bf2d0d550b22
  • php-bcmath-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:4df3f60f5d6f9c38ce115f71403e542e59e01193503bc4433060bfed90a27bab
  • php-cli-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:f27d18545e06567a58a0f58c524d466d5ba61e166cc4703f7c00860765fa9956
  • php-common-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:5b658639fbd335ad6763d2e9ed2833aee98a572bcbc36dffe3a5c95c7ed78a6c
  • php-dba-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:86d7359e6978a4891eae326dd2c7de55ee7bb66705857a084f70d894ac639110
  • php-devel-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:254aed96de79e2518a420469319ffaaea258bf5ec93ba9bf2a3df0ac610a1deb
  • php-embedded-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:a503a7390f963fd732bb4a9ee88715e1dd11299090c4540fc42eb58d04c8fd47
  • php-enchant-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:5b31cfe1439423c812e6aab06f10f66b24c2c14d7c601e63a4c4195ddc4cc49b
  • php-fpm-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:139b98b1ae543de722801b83e311dd86fd48a5a352bdfeaf7cae12efcec6b60a
  • php-gd-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:e57a84b5e17100f8d053f605aa2bcc4b9982bb92542c468fc53e5c866ccd411c
  • php-intl-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:09daa627f82d1015ed584c7901f7e1c212681a29333fddeb7dff547d7b10d162
  • php-ldap-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:1145ed73a92d4bb1396d6824b058cc6b5fcda5680f3cfe217be418e418382ad6
  • php-mbstring-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:73db936ea64dc654ae1ddc0346e36b752e751df83574997d0a106c11b2be4ef6
  • php-mysqlnd-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:a63fb9ce39979d160689492857a06c8c1df645df2cad8fb053bffc26b1723a98
  • php-odbc-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:7da9463091b9fc33dad540b9e993733ad004745049753de2ed0ddfc84022a481
  • php-pdo-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:73e2c1c25fc6a13ec3adb95cf0920c3242767d9dcea1febf82da671e60fc6851
  • php-pgsql-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:67cf8128e8d585ef66d5f49e169de1954dd1e89fcc2e0f3d9b95726a49224f8b
  • php-process-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:8b776daa778a8c3f0991a1a182c97e534f0f161856d430b608045d44b2983c8b
  • php-pspell-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:027bcfe81c00cd780cec7864e410da83bf8a21c26ce706d3df2b5bb01a996734
  • php-recode-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:5ad840646fb3ebba45737a97347355a8886be49adc5d2386a4f52736b1ab9bf6
  • php-snmp-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:5f0f98ce6dd677c7fe9be8f9821cf7fe64479f5ef050e12dd792ffe99d80ac98
  • php-soap-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:113b5dbbfaa2a768c16b0c8411f52bea73c41c23485eb0d01efd691d1d7dbe5e
  • php-xml-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:a9a049d66e52e3d34bc389c93e50a1d81eaaba28c4ae6e0e07b648a2bd346e75
  • php-xmlrpc-5.4.16-46.amzn2.0.6.tuxcare.els6.x86_64.rpm
    sha:1695d72d58c4f2ffde1c826ceb3de8d06bcbad8125289d3681f393fca2013875
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.