[CLSA-2026:1779461683] Fix of 5 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-22 14:54:49 UTC
Description:
* SECURITY UPDATE: soap extension use-after-free via apache:Map duplicate keys - debian/patches/php-7.4-CVE-2026-6722.patch: backport upstream commit aee3b3ac9b in ext/soap/php_encoding.c — add Z_TRY_ADDREF_P on soap_add_xml_ref insertion and change SOAP_GLOBAL(ref_map) destructor to ZVAL_PTR_DTOR. - CVE-2026-6722 * SECURITY UPDATE: soap extension NULL pointer dereference via apache:Map item missing element - debian/patches/php-7.4-CVE-2026-7262.patch: backport upstream commit 79551ab8b1 in ext/soap/php_encoding.c — fix typo'd null check in to_zval_map() (was checking xmlKey, should check xmlValue). - CVE-2026-7262 * SECURITY UPDATE: php-fpm status endpoint XSS via unescaped request_uri - debian/patches/php-7.4-CVE-2026-6735.patch: backport upstream commit 99a5ad7441 in sapi/fpm/fpm/fpm_status.c — escape proc.request_uri with php_escape_html_entities_ex() and fix the broken "ENT_HTML_IGNORE_ERRORS & ENT_COMPAT" flag (bitwise-AND of two flag constants evaluates to 0). Adapted to 7.x layout (struct access "proc.X", single encode flag, older 6-arg php_escape_html_entities_ex signature). - CVE-2026-6735 * SECURITY UPDATE: soap SoapServer use-after-free after header parsing failure when SOAP_PERSISTENCE_SESSION is set - debian/patches/php-7.4-CVE-2026-7261.patch: backport upstream commit db2a7f9348 in ext/soap/soap.c — guard both zval_ptr_dtor(soap_obj) call sites in PHP_METHOD(SoapServer, handle) with "if (service->soap_class.persistence != SOAP_PERSISTENCE_SESSION)". - CVE-2026-7261 * SECURITY UPDATE: metaphone() signed integer overflow on >INT_MAX input - debian/patches/php-7.4-CVE-2026-7568.patch: backport upstream commit 47def8ce1d in ext/standard/metaphone.c — retype w_idx and Lookahead's how_far/idx from int to size_t to avoid signed overflow while walking strings larger than 2 GB on 64-bit builds. - CVE-2026-7568
Updated packages:
  • alt-php74_7.4.33-55_amd64.deb
    sha:a366dd82802c5d904f0cf6f343d926deded8d04c
  • alt-php74-bcmath_7.4.33-55_amd64.deb
    sha:55f8f496bde7bf352846965f53a7797d16bc3312
  • alt-php74-cli_7.4.33-55_amd64.deb
    sha:c578d3e144c641b2627c75a6458efb7df1654725
  • alt-php74-common_7.4.33-55_amd64.deb
    sha:b4d3f6a4b35372fa82dcd3edcd8a23ce2a450e57
  • alt-php74-dba_7.4.33-55_amd64.deb
    sha:8b43d665eae0b781a0a23c5aa40a3336a272af33
  • alt-php74-dev_7.4.33-55_amd64.deb
    sha:b44cb36bf6eccc650aefd02a68f0b4588eb542b1
  • alt-php74-enchant_7.4.33-55_amd64.deb
    sha:6a481cbc105f914ff56e7a1322cac0456dea1c9e
  • alt-php74-firebird_7.4.33-55_amd64.deb
    sha:59d10103af763f79fa8bc04d349153955337fb93
  • alt-php74-fpm_7.4.33-55_amd64.deb
    sha:6aec5013b6d56bff013c6768f0089cf23216ea52
  • alt-php74-gd_7.4.33-55_amd64.deb
    sha:c3d6ed3f28058e456cd03002b35774f6de679dbd
  • alt-php74-imap_7.4.33-55_amd64.deb
    sha:5d1e09962737dc321b191f58be80763c4f9e9ba4
  • alt-php74-intl_7.4.33-55_amd64.deb
    sha:765cc4c15f80049528404c941d7808f26e8342b1
  • alt-php74-ldap_7.4.33-55_amd64.deb
    sha:5d5f85c2b2628e9b0d26ed5435da3e2a6afbfedf
  • alt-php74-mbstring_7.4.33-55_amd64.deb
    sha:0d7f02fafb6d58136c1ad3ab269f35fb80f24262
  • alt-php74-mysqlnd_7.4.33-55_amd64.deb
    sha:c59061ffc2233b63a4b89b2a453ac94f1d282f1a
  • alt-php74-odbc_7.4.33-55_amd64.deb
    sha:5eb5b75d68d8f15c354feac1f1c562f90ef02901
  • alt-php74-opcache_7.4.33-55_amd64.deb
    sha:a06fced9e86f400911e61cbf2a4fd087fd877eeb
  • alt-php74-pdo_7.4.33-55_amd64.deb
    sha:d234153dea67f5703c12be880817bf09c761858d
  • alt-php74-pgsql_7.4.33-55_amd64.deb
    sha:cc56c721f5fad294e58ade3bf998cb2efb1e950c
  • alt-php74-process_7.4.33-55_amd64.deb
    sha:c939cd509bb3e5f8f93c7558c5aebbd930b7ca1b
  • alt-php74-pspell_7.4.33-55_amd64.deb
    sha:f1f2f7f9e26038f18424682c7f8d0e0fdd49d8f9
  • alt-php74-snmp_7.4.33-55_amd64.deb
    sha:d59edb43addb161c6f722718491bdaa9ee44be9b
  • alt-php74-soap_7.4.33-55_amd64.deb
    sha:9687a6b619503e29d423a4d0e505009400474a12
  • alt-php74-sodium_7.4.33-55_amd64.deb
    sha:bee040b286cab6d7eaaad657706da300973d7eb2
  • alt-php74-tidy_7.4.33-55_amd64.deb
    sha:8ae56c2cf52724d4eae4beaac05942676034d644
  • alt-php74-xml_7.4.33-55_amd64.deb
    sha:38dafa6949af47fb73b5dc4d058615f1d58e9def
  • alt-php74-xmlrpc_7.4.33-55_amd64.deb
    sha:f5f7e89e9e2982194c246da64d00eee0e7e8919d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.