Release date:
2026-05-22 14:54:49 UTC
Description:
* SECURITY UPDATE: soap extension use-after-free via apache:Map duplicate keys
- debian/patches/php-7.4-CVE-2026-6722.patch: backport upstream commit
aee3b3ac9b in ext/soap/php_encoding.c — add Z_TRY_ADDREF_P on
soap_add_xml_ref insertion and change SOAP_GLOBAL(ref_map) destructor
to ZVAL_PTR_DTOR.
- CVE-2026-6722
* SECURITY UPDATE: soap extension NULL pointer dereference via apache:Map
item missing element
- debian/patches/php-7.4-CVE-2026-7262.patch: backport upstream commit
79551ab8b1 in ext/soap/php_encoding.c — fix typo'd null check in
to_zval_map() (was checking xmlKey, should check xmlValue).
- CVE-2026-7262
* SECURITY UPDATE: php-fpm status endpoint XSS via unescaped request_uri
- debian/patches/php-7.4-CVE-2026-6735.patch: backport upstream commit
99a5ad7441 in sapi/fpm/fpm/fpm_status.c — escape proc.request_uri
with php_escape_html_entities_ex() and fix the broken
"ENT_HTML_IGNORE_ERRORS & ENT_COMPAT" flag (bitwise-AND of two flag
constants evaluates to 0). Adapted to 7.x layout (struct access
"proc.X", single encode flag, older 6-arg
php_escape_html_entities_ex signature).
- CVE-2026-6735
* SECURITY UPDATE: soap SoapServer use-after-free after header parsing
failure when SOAP_PERSISTENCE_SESSION is set
- debian/patches/php-7.4-CVE-2026-7261.patch: backport upstream commit
db2a7f9348 in ext/soap/soap.c — guard both zval_ptr_dtor(soap_obj)
call sites in PHP_METHOD(SoapServer, handle) with
"if (service->soap_class.persistence != SOAP_PERSISTENCE_SESSION)".
- CVE-2026-7261
* SECURITY UPDATE: metaphone() signed integer overflow on >INT_MAX input
- debian/patches/php-7.4-CVE-2026-7568.patch: backport upstream commit
47def8ce1d in ext/standard/metaphone.c — retype w_idx and
Lookahead's how_far/idx from int to size_t to avoid signed
overflow while walking strings larger than 2 GB on 64-bit builds.
- CVE-2026-7568
Updated packages:
-
alt-php74_7.4.33-55_amd64.deb
sha:a366dd82802c5d904f0cf6f343d926deded8d04c
-
alt-php74-bcmath_7.4.33-55_amd64.deb
sha:55f8f496bde7bf352846965f53a7797d16bc3312
-
alt-php74-cli_7.4.33-55_amd64.deb
sha:c578d3e144c641b2627c75a6458efb7df1654725
-
alt-php74-common_7.4.33-55_amd64.deb
sha:b4d3f6a4b35372fa82dcd3edcd8a23ce2a450e57
-
alt-php74-dba_7.4.33-55_amd64.deb
sha:8b43d665eae0b781a0a23c5aa40a3336a272af33
-
alt-php74-dev_7.4.33-55_amd64.deb
sha:b44cb36bf6eccc650aefd02a68f0b4588eb542b1
-
alt-php74-enchant_7.4.33-55_amd64.deb
sha:6a481cbc105f914ff56e7a1322cac0456dea1c9e
-
alt-php74-firebird_7.4.33-55_amd64.deb
sha:59d10103af763f79fa8bc04d349153955337fb93
-
alt-php74-fpm_7.4.33-55_amd64.deb
sha:6aec5013b6d56bff013c6768f0089cf23216ea52
-
alt-php74-gd_7.4.33-55_amd64.deb
sha:c3d6ed3f28058e456cd03002b35774f6de679dbd
-
alt-php74-imap_7.4.33-55_amd64.deb
sha:5d1e09962737dc321b191f58be80763c4f9e9ba4
-
alt-php74-intl_7.4.33-55_amd64.deb
sha:765cc4c15f80049528404c941d7808f26e8342b1
-
alt-php74-ldap_7.4.33-55_amd64.deb
sha:5d5f85c2b2628e9b0d26ed5435da3e2a6afbfedf
-
alt-php74-mbstring_7.4.33-55_amd64.deb
sha:0d7f02fafb6d58136c1ad3ab269f35fb80f24262
-
alt-php74-mysqlnd_7.4.33-55_amd64.deb
sha:c59061ffc2233b63a4b89b2a453ac94f1d282f1a
-
alt-php74-odbc_7.4.33-55_amd64.deb
sha:5eb5b75d68d8f15c354feac1f1c562f90ef02901
-
alt-php74-opcache_7.4.33-55_amd64.deb
sha:a06fced9e86f400911e61cbf2a4fd087fd877eeb
-
alt-php74-pdo_7.4.33-55_amd64.deb
sha:d234153dea67f5703c12be880817bf09c761858d
-
alt-php74-pgsql_7.4.33-55_amd64.deb
sha:cc56c721f5fad294e58ade3bf998cb2efb1e950c
-
alt-php74-process_7.4.33-55_amd64.deb
sha:c939cd509bb3e5f8f93c7558c5aebbd930b7ca1b
-
alt-php74-pspell_7.4.33-55_amd64.deb
sha:f1f2f7f9e26038f18424682c7f8d0e0fdd49d8f9
-
alt-php74-snmp_7.4.33-55_amd64.deb
sha:d59edb43addb161c6f722718491bdaa9ee44be9b
-
alt-php74-soap_7.4.33-55_amd64.deb
sha:9687a6b619503e29d423a4d0e505009400474a12
-
alt-php74-sodium_7.4.33-55_amd64.deb
sha:bee040b286cab6d7eaaad657706da300973d7eb2
-
alt-php74-tidy_7.4.33-55_amd64.deb
sha:8ae56c2cf52724d4eae4beaac05942676034d644
-
alt-php74-xml_7.4.33-55_amd64.deb
sha:38dafa6949af47fb73b5dc4d058615f1d58e9def
-
alt-php74-xmlrpc_7.4.33-55_amd64.deb
sha:f5f7e89e9e2982194c246da64d00eee0e7e8919d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.