[CLSA-2026:1790931672] Fix CVE(s): CVE-2025-14181, CVE-2026-6103, CVE-2026-91765, CVE-2026-92842
Type:
security
Severity:
Important
Release date:
2026-10-02 09:01:41 UTC
Description:
* SECURITY UPDATE: heap buffer over-read in the convert.* stream filters when line-break-chars contains a NUL - debian/patches/php-5.6-CVE-2026-92842.patch: backport upstream commit b4e3397ec8f4 (GHSA-88hq-2827-7pg6) in ext/standard/filters.c. php_conv_base64_encode_ctor(), php_conv_qprint_encode_ctor() and php_conv_qprint_decode_ctor() duplicated the option with the strlen-based pestrdup() while keeping lbchars_len, which the option reader sets from Z_STRLEN, so a "line-break-chars" of "\0X" allocated one byte and the filters then copied two bytes out of it on every line break. The three calls become pestrndup(lbchars, lbchars_len, persistent). - Note: byte-identical to upstream, only the hunk line numbers differ. Upstream's .phpt is carried, rewritten for the 5.6 runner as ext/standard/tests/filters/ghsa-88hq-2827-7pg6.phpt. The suite is not run during the build, so it ships for manual and downstream runs. - CVE-2026-92842 * SECURITY UPDATE: integer overflow in the SOAP client's chunked response reader - debian/patches/php-5.6-CVE-2025-14181.patch: backport upstream commit b11bd1d9390b (GHSA-cj93-vc83-wgqv) in ext/soap/php_http.c. get_http_body() accumulated the body length in a signed int and guarded growth with "http_buf_size + buf_size + 1 < 0", which is signed overflow - undefined behaviour a modern compiler folds away - so a hostile endpoint answering with two 0x7fffffff-sized chunks made the second erealloc() request wrap to a small allocation that php_stream_read() then overflowed. The accumulator becomes unsigned, each growth step is bounded before it is performed, and the overflow test is a subtraction from the bound rather than a wrapping addition. - Note: PHP 5.x has no zend_string in this path, so the bound is INT_MAX - the representable maximum of the int *out_size this function reports the body length through - in place of upstream's ZSTR_MAX_LEN, and erealloc() stands in for zend_string_safe_realloc(). The Content-Length guard upstream retargets in the same commit is already present here. Upstream's regression test is not carried: tripping the overflow needs a response body past INT_MAX, i.e. more than 4 GB live in the test process, which a build or QA host cannot be assumed to have. - CVE-2025-14181 * SECURITY UPDATE: phar tar entry injection - debian/patches/php-5.6-CVE-2026-6103.patch: backport upstream commit 0994e2e887cd (GHSA-j3wh-g957-2m85) in ext/phar/tar.c and ext/phar/phar_internal.h. phar_tar_number() parsed the 512-byte header's size field with an unchecked octal accumulator over a php_uint32 and ignored trailing garbage and GNU base-256 encoding, and phar_parse_tarfile() skipped the data blocks of only the '\0' and TAR_FILE entry types. Either way the stream was left inside an entry's payload, which was then read as the next tar header, so one archive shows one set of entries to phar and another to every conforming tar reader. A new phar_tar_size() rejects sizes that cannot be parsed or represented, a new phar_tar_type_has_data() decides the skip for every type, GNU long link records are refused outright, and the bug-61065 guard now bounds the long file name by the archive size. - Note: adapted to C89 (the two new helpers return int rather than bool), to phar_destroy_phar_data()'s TSRMLS_CC, and to the pemalloc'd long-name buffer, which the new bail-outs release with pefree(). The three upstream .phpt files are carried, rewritten for the 5.6 runner and 5.6's PharData exception text, as ext/phar/tests/tar/ghsa-j3wh-g957-2m85-{size,typeflag,longlink}.phpt. - CVE-2026-6103 * SECURITY UPDATE: unbounded recursion in ext/soap XML parsing and decoding - debian/patches/php-5.6-CVE-2026-91765.patch: backport upstream commit 3655b79c7bfa (GHSA-rgrp-mwpx-f6rm) in ext/soap/php_xml.c, ext/soap/php_encoding.c, ext/soap/php_soap.h and ext/soap/soap.c. cleanup_xml_node() and get_node_with_attribute_recursive_ex() recursed once per XML nesting level and master_to_zval_int() once per decoded node and per href hop, with no cap; both SOAP parsers set XML_PARSE_HUGE, which turns off libxml2's own depth limit, so a deep envelope or WSDL - or a long href chain in a shallow one - exhausts the C stack. Both walkers become iterative, a 2048-level document cap is enforced after parsing where libxml2 is older than 2.13, and the decoder takes a depth counter bailing out at twice that. - Note: the counter is added to this version's soap globals struct rather than importing upstream's globals plumbing, and is reset in php_soap_init_globals(), encode_reset_ns() and encode_finish(), since soap_error0(E_ERROR) bails out past the matching decrement. Upstream's three .phpt files are carried as ext/soap/tests/GHSA-rgrp-mwpx-f6rm{,-href-chain,-href-cycle}.phpt, with the scalar type hints dropped for 5.6 and, in the href-chain test, the reference marker php-5.6-CVE-2026-6722.patch's added Z_ADDREF_PP() makes var_dump() print here. - CVE-2026-91765
Updated packages:
  • alt-php56_5.6.40-145_amd64.deb
    sha:59e7ada9b37fb4a6e4f2830ff83ec8892b63764a
  • alt-php56-bcmath_5.6.40-145_amd64.deb
    sha:8e4a99b59318c4d82e42e06dda790350f866eba8
  • alt-php56-cli_5.6.40-145_amd64.deb
    sha:0cc84ea6ef1540c47e4624bf9008b395e1141a58
  • alt-php56-common_5.6.40-145_amd64.deb
    sha:26939506e077096689d0965d21dc1e8973243a78
  • alt-php56-dba_5.6.40-145_amd64.deb
    sha:2464d18ce6506fc8571eb5699c3d1f027dcba103
  • alt-php56-dbx_5.6.40-145_amd64.deb
    sha:9a2a5fe9e29a1eced6b01406cd7af863e88861a8
  • alt-php56-dev_5.6.40-145_amd64.deb
    sha:3a2ead1a02d71ebfd420d6447ede20153c38be0b
  • alt-php56-enchant_5.6.40-145_amd64.deb
    sha:486eac01b3baf24ead0c676569f3e4c01e89dcbf
  • alt-php56-firebird_5.6.40-145_amd64.deb
    sha:f7f383af016a026617793067e099132709756c1e
  • alt-php56-gd_5.6.40-145_amd64.deb
    sha:3713eb09d1a8b217c9b319ec291c7a9eaf65c8ea
  • alt-php56-imap_5.6.40-145_amd64.deb
    sha:d59052cd92d4e0fccd35478d08d075215bf00f6c
  • alt-php56-intl_5.6.40-145_amd64.deb
    sha:4588e157991864cb4fddc699470748735191235f
  • alt-php56-ldap_5.6.40-145_amd64.deb
    sha:38a15d7f691f032729a3eac9cc2674f75fabbefa
  • alt-php56-mbstring_5.6.40-145_amd64.deb
    sha:c0df7bd63b31b58c5211f87a08c4d0ba7014c1da
  • alt-php56-mcrypt_5.6.40-145_amd64.deb
    sha:0b79e2a01762c9c962e369f45cb8c100589ee92f
  • alt-php56-mysqlnd_5.6.40-145_amd64.deb
    sha:3c60b5dd9381e1aebc0fab4735549170a23be215
  • alt-php56-odbc_5.6.40-145_amd64.deb
    sha:e4fd1e3533b7c45a0b8835cc8f8d40e89f61a7b1
  • alt-php56-opcache_5.6.40-145_amd64.deb
    sha:2616fcddfd5e30c64d8004f32531a79a0e52aa6c
  • alt-php56-pdo_5.6.40-145_amd64.deb
    sha:1a0321d0b7abae34a45c3616cc890dea68e6e01a
  • alt-php56-pgsql_5.6.40-145_amd64.deb
    sha:2e1dd5b160c08daf8fc87884ec9a283dd347462d
  • alt-php56-php-fpm_5.6.40-145_amd64.deb
    sha:8d99be208a3e0f64c7670b048655ddd9ff18ff9b
  • alt-php56-process_5.6.40-145_amd64.deb
    sha:22d38680bd17c8f0fbaa42d7ab23e266acc95b98
  • alt-php56-pspell_5.6.40-145_amd64.deb
    sha:a2d2fc638a92ebf8fd94a5fbba32d381e67e172c
  • alt-php56-recode_5.6.40-145_amd64.deb
    sha:aaaeaf7f9d7a323ff32c181280901c658f23f37a
  • alt-php56-snmp_5.6.40-145_amd64.deb
    sha:47cf222ef65782d75c2a3bda6dc18236f63194a6
  • alt-php56-soap_5.6.40-145_amd64.deb
    sha:b423eecf9724d55679b5b645ac47dc62ac22b291
  • alt-php56-sybase_5.6.40-145_amd64.deb
    sha:7fabb7b3b2b7640028486a432b64c56c9e78dc6c
  • alt-php56-tidy_5.6.40-145_amd64.deb
    sha:027a42688f127fb05eee5c5477601156f43c1e73
  • alt-php56-xml_5.6.40-145_amd64.deb
    sha:a40deaaa3fac94119625fe5c2d9d266f7b416592
  • alt-php56-xmlrpc_5.6.40-145_amd64.deb
    sha:2cd858becf7d902bc31f13acc0cfcd9626963dc6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.