Release date:
2026-10-02 09:01:41 UTC
Description:
* SECURITY UPDATE: heap buffer over-read in the convert.* stream filters
when line-break-chars contains a NUL
- debian/patches/php-5.6-CVE-2026-92842.patch: backport upstream commit
b4e3397ec8f4 (GHSA-88hq-2827-7pg6) in ext/standard/filters.c.
php_conv_base64_encode_ctor(), php_conv_qprint_encode_ctor() and
php_conv_qprint_decode_ctor() duplicated the option with the
strlen-based pestrdup() while keeping lbchars_len, which the option
reader sets from Z_STRLEN, so a "line-break-chars" of "\0X" allocated
one byte and the filters then copied two bytes out of it on every line
break. The three calls become pestrndup(lbchars, lbchars_len,
persistent).
- Note: byte-identical to upstream, only the hunk line numbers differ.
Upstream's .phpt is carried, rewritten for the 5.6 runner as
ext/standard/tests/filters/ghsa-88hq-2827-7pg6.phpt. The suite is not
run during the build, so it ships for manual and downstream runs.
- CVE-2026-92842
* SECURITY UPDATE: integer overflow in the SOAP client's chunked response
reader
- debian/patches/php-5.6-CVE-2025-14181.patch: backport upstream commit
b11bd1d9390b (GHSA-cj93-vc83-wgqv) in ext/soap/php_http.c.
get_http_body() accumulated the body length in a signed int and guarded
growth with "http_buf_size + buf_size + 1 < 0", which is signed overflow
- undefined behaviour a modern compiler folds away - so a hostile
endpoint answering with two 0x7fffffff-sized chunks made the second
erealloc() request wrap to a small allocation that php_stream_read()
then overflowed. The accumulator becomes unsigned, each growth step is
bounded before it is performed, and the overflow test is a subtraction
from the bound rather than a wrapping addition.
- Note: PHP 5.x has no zend_string in this path, so the bound is INT_MAX -
the representable maximum of the int *out_size this function reports the
body length through - in place of upstream's ZSTR_MAX_LEN, and
erealloc() stands in for zend_string_safe_realloc(). The Content-Length
guard upstream retargets in the same commit is already present here.
Upstream's regression test is not carried: tripping the overflow needs
a response body past INT_MAX, i.e. more than 4 GB live in the test
process, which a build or QA host cannot be assumed to have.
- CVE-2025-14181
* SECURITY UPDATE: phar tar entry injection
- debian/patches/php-5.6-CVE-2026-6103.patch: backport upstream commit
0994e2e887cd (GHSA-j3wh-g957-2m85) in ext/phar/tar.c and
ext/phar/phar_internal.h. phar_tar_number() parsed the 512-byte header's
size field with an unchecked octal accumulator over a php_uint32 and
ignored trailing garbage and GNU base-256 encoding, and
phar_parse_tarfile() skipped the data blocks of only the '\0' and
TAR_FILE entry types. Either way the stream was left inside an entry's
payload, which was then read as the next tar header, so one archive
shows one set of entries to phar and another to every conforming tar
reader. A new phar_tar_size() rejects sizes that cannot be parsed or
represented, a new phar_tar_type_has_data() decides the skip for every
type, GNU long link records are refused outright, and the bug-61065
guard now bounds the long file name by the archive size.
- Note: adapted to C89 (the two new helpers return int rather than bool),
to phar_destroy_phar_data()'s TSRMLS_CC, and to the pemalloc'd
long-name buffer, which the new bail-outs release with pefree(). The
three upstream .phpt files are carried, rewritten for the 5.6 runner
and 5.6's PharData exception text, as
ext/phar/tests/tar/ghsa-j3wh-g957-2m85-{size,typeflag,longlink}.phpt.
- CVE-2026-6103
* SECURITY UPDATE: unbounded recursion in ext/soap XML parsing and decoding
- debian/patches/php-5.6-CVE-2026-91765.patch: backport upstream commit
3655b79c7bfa (GHSA-rgrp-mwpx-f6rm) in ext/soap/php_xml.c,
ext/soap/php_encoding.c, ext/soap/php_soap.h and ext/soap/soap.c.
cleanup_xml_node() and get_node_with_attribute_recursive_ex() recursed
once per XML nesting level and master_to_zval_int() once per decoded
node and per href hop, with no cap; both SOAP parsers set
XML_PARSE_HUGE, which turns off libxml2's own depth limit, so a deep
envelope or WSDL - or a long href chain in a shallow one - exhausts the
C stack. Both walkers become iterative, a 2048-level document cap is
enforced after parsing where libxml2 is older than 2.13, and the decoder
takes a depth counter bailing out at twice that.
- Note: the counter is added to this version's soap globals struct rather
than importing upstream's globals plumbing, and is reset in
php_soap_init_globals(), encode_reset_ns() and encode_finish(), since
soap_error0(E_ERROR) bails out past the matching decrement. Upstream's
three .phpt files are carried as
ext/soap/tests/GHSA-rgrp-mwpx-f6rm{,-href-chain,-href-cycle}.phpt, with
the scalar type hints dropped for 5.6 and, in the href-chain test, the
reference marker php-5.6-CVE-2026-6722.patch's added Z_ADDREF_PP() makes
var_dump() print here.
- CVE-2026-91765
Updated packages:
-
alt-php56_5.6.40-145_amd64.deb
sha:59e7ada9b37fb4a6e4f2830ff83ec8892b63764a
-
alt-php56-bcmath_5.6.40-145_amd64.deb
sha:8e4a99b59318c4d82e42e06dda790350f866eba8
-
alt-php56-cli_5.6.40-145_amd64.deb
sha:0cc84ea6ef1540c47e4624bf9008b395e1141a58
-
alt-php56-common_5.6.40-145_amd64.deb
sha:26939506e077096689d0965d21dc1e8973243a78
-
alt-php56-dba_5.6.40-145_amd64.deb
sha:2464d18ce6506fc8571eb5699c3d1f027dcba103
-
alt-php56-dbx_5.6.40-145_amd64.deb
sha:9a2a5fe9e29a1eced6b01406cd7af863e88861a8
-
alt-php56-dev_5.6.40-145_amd64.deb
sha:3a2ead1a02d71ebfd420d6447ede20153c38be0b
-
alt-php56-enchant_5.6.40-145_amd64.deb
sha:486eac01b3baf24ead0c676569f3e4c01e89dcbf
-
alt-php56-firebird_5.6.40-145_amd64.deb
sha:f7f383af016a026617793067e099132709756c1e
-
alt-php56-gd_5.6.40-145_amd64.deb
sha:3713eb09d1a8b217c9b319ec291c7a9eaf65c8ea
-
alt-php56-imap_5.6.40-145_amd64.deb
sha:d59052cd92d4e0fccd35478d08d075215bf00f6c
-
alt-php56-intl_5.6.40-145_amd64.deb
sha:4588e157991864cb4fddc699470748735191235f
-
alt-php56-ldap_5.6.40-145_amd64.deb
sha:38a15d7f691f032729a3eac9cc2674f75fabbefa
-
alt-php56-mbstring_5.6.40-145_amd64.deb
sha:c0df7bd63b31b58c5211f87a08c4d0ba7014c1da
-
alt-php56-mcrypt_5.6.40-145_amd64.deb
sha:0b79e2a01762c9c962e369f45cb8c100589ee92f
-
alt-php56-mysqlnd_5.6.40-145_amd64.deb
sha:3c60b5dd9381e1aebc0fab4735549170a23be215
-
alt-php56-odbc_5.6.40-145_amd64.deb
sha:e4fd1e3533b7c45a0b8835cc8f8d40e89f61a7b1
-
alt-php56-opcache_5.6.40-145_amd64.deb
sha:2616fcddfd5e30c64d8004f32531a79a0e52aa6c
-
alt-php56-pdo_5.6.40-145_amd64.deb
sha:1a0321d0b7abae34a45c3616cc890dea68e6e01a
-
alt-php56-pgsql_5.6.40-145_amd64.deb
sha:2e1dd5b160c08daf8fc87884ec9a283dd347462d
-
alt-php56-php-fpm_5.6.40-145_amd64.deb
sha:8d99be208a3e0f64c7670b048655ddd9ff18ff9b
-
alt-php56-process_5.6.40-145_amd64.deb
sha:22d38680bd17c8f0fbaa42d7ab23e266acc95b98
-
alt-php56-pspell_5.6.40-145_amd64.deb
sha:a2d2fc638a92ebf8fd94a5fbba32d381e67e172c
-
alt-php56-recode_5.6.40-145_amd64.deb
sha:aaaeaf7f9d7a323ff32c181280901c658f23f37a
-
alt-php56-snmp_5.6.40-145_amd64.deb
sha:47cf222ef65782d75c2a3bda6dc18236f63194a6
-
alt-php56-soap_5.6.40-145_amd64.deb
sha:b423eecf9724d55679b5b645ac47dc62ac22b291
-
alt-php56-sybase_5.6.40-145_amd64.deb
sha:7fabb7b3b2b7640028486a432b64c56c9e78dc6c
-
alt-php56-tidy_5.6.40-145_amd64.deb
sha:027a42688f127fb05eee5c5477601156f43c1e73
-
alt-php56-xml_5.6.40-145_amd64.deb
sha:a40deaaa3fac94119625fe5c2d9d266f7b416592
-
alt-php56-xmlrpc_5.6.40-145_amd64.deb
sha:2cd858becf7d902bc31f13acc0cfcd9626963dc6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.