Release date:
2026-10-02 17:54:33 UTC
Description:
* SECURITY UPDATE: heap over-read in the convert stream filters when
line-break-chars contains a NUL byte
- debian/patches/php-7.0-CVE-2026-92842.patch:
the base64-encode, quoted-printable-encode and quoted-printable-decode
filter constructors duplicated the user-supplied line-break-chars option
with pestrdup(), which stops at the first NUL, while keeping the option's
real length in inst->lbchars_len. Every memcpy() of lbchars_len bytes in
the filter body then read past the end of the allocation. They now
duplicate with pestrndup() so the allocation matches the recorded length.
Adds the upstream regression test
- CVE-2026-92842
* SECURITY UPDATE: buffer overflow in the SOAP client when reading a chunked
HTTP response
- debian/patches/php-7.0-CVE-2025-14181.patch:
get_http_body() tracked the accumulated body length in a signed int and
guarded each growth step with "http_buf_size + buf_size + 1 < 0" - signed
overflow, which is undefined and cannot describe an overflow of the
size_t the allocator receives. A hostile SOAP endpoint answering with
Transfer-Encoding: chunked could drive the total past INT_MAX, wrap the
reallocation length and make the following read write out of bounds. The
accumulator is now a size_t, every growth step is bounded against
ZSTR_MAX_LEN before it happens, and the chunked path reallocates through
zend_string_safe_realloc(). The redirect-path allocation in the same
upstream commit goes through safe_emalloc()
- CVE-2025-14181
* SECURITY UPDATE: tar entry injection in ext/phar
- debian/patches/php-7.0-CVE-2026-6103.patch:
phar_parse_tarfile() read an entry's size with phar_tar_number(), which
overflows a 32-bit accumulator without a check and silently stops at the
first non-octal byte, and it skipped an entry's data blocks only for
typeflag '\0' and TAR_FILE. A size field that overflows, uses GNU
base-256 encoding or carries trailing garbage - or an entry type that
carries data but was not skipped - left the stream on attacker-controlled
payload that was then parsed as the next tar header, so PHP saw a
different archive from every other tar implementation. Sizes that cannot
be parsed or represented are now rejected, the unsupported GNU long link
record is refused instead of being registered as an entry, the
"././@LongLink" name is bounded by the size of the archive, and the data
blocks of every entry type that carries data are skipped. Adds the three
upstream regression tests
- CVE-2026-6103
* SECURITY UPDATE: stack exhaustion in ext/soap on deeply nested XML
- debian/patches/php-7.0-CVE-2026-91765.patch:
cleanup_xml_node() and get_node_with_attribute_recursive_ex() walked
parsed documents with self-recursive C functions and master_to_zval_int()
re-entered itself for every nested element and every hop of an href
chain, none of them bounded - and ext/soap sets XML_PARSE_HUGE, which
removes the depth limit libxml2 would otherwise apply. A SOAP request or
WSDL a few thousand levels deep, an href chain, or an array element
referencing its own array exhausted the C stack and crashed the process.
Both tree walks are now iterative, documents nested deeper than
SOAP_MAX_XML_DEPTH are rejected on libxml2 versions that enforce no limit
of their own, and the decoder is capped by a per-request depth counter
reset at the start and end of every encode/decode cycle. Adds the three
upstream regression tests
- CVE-2026-91765
Updated packages:
-
alt-php70_7.0.33-146_amd64.deb
sha:f0aa500b06eadd8b47b50dfe65a72566561c5722
-
alt-php70-bcmath_7.0.33-146_amd64.deb
sha:cfd7b9a65ed002571e37a409de3d81293a63df61
-
alt-php70-cli_7.0.33-146_amd64.deb
sha:4c7642037f0eb2f5bbb1a891a7208ee5b30f3963
-
alt-php70-common_7.0.33-146_amd64.deb
sha:b14feb92a04aa466fed9c31fd36590385f080bda
-
alt-php70-dba_7.0.33-146_amd64.deb
sha:769350fc3154090c7305224c96309a6cfbff5fac
-
alt-php70-dev_7.0.33-146_amd64.deb
sha:d4a77ca9eae51cbfa7ee8375a8703be10c371b79
-
alt-php70-enchant_7.0.33-146_amd64.deb
sha:dfbc4b021d9102d08173973a0db0ae7d2f75cc91
-
alt-php70-firebird_7.0.33-146_amd64.deb
sha:1c56393ff25ed8d8e2482412987594428c4621dc
-
alt-php70-gd_7.0.33-146_amd64.deb
sha:bfd88132cfc49baccf2bed72f87dac61276d00c4
-
alt-php70-imap_7.0.33-146_amd64.deb
sha:4fb905e977a9eeaf999642dec27b42ef470da434
-
alt-php70-intl_7.0.33-146_amd64.deb
sha:ee5e4d0baab805b2c5801fe72bf0fab3b47bd1cf
-
alt-php70-ldap_7.0.33-146_amd64.deb
sha:10714305ce0e91ab9e255f2cd45a98a5fdb980d5
-
alt-php70-mbstring_7.0.33-146_amd64.deb
sha:4f755b2cf9765f1c1b8e3346ed1d893861b05379
-
alt-php70-mcrypt_7.0.33-146_amd64.deb
sha:6a9e1b777d551cd3e89ff994b79b769553751488
-
alt-php70-mysqlnd_7.0.33-146_amd64.deb
sha:759fb908d59627c4f52f81018dfd035ed88051c1
-
alt-php70-odbc_7.0.33-146_amd64.deb
sha:509785c93dc6eeb51fa0c063cd5144adf04faf8e
-
alt-php70-opcache_7.0.33-146_amd64.deb
sha:7c45af050f0a9a8ed871b3a7200399f423f0c708
-
alt-php70-pdo_7.0.33-146_amd64.deb
sha:11897d1de9794006881c7ebeafa9aba8ff167abe
-
alt-php70-pgsql_7.0.33-146_amd64.deb
sha:5ca485407cea4c1b733a750866ff7ef0f6af5df0
-
alt-php70-php-fpm_7.0.33-146_amd64.deb
sha:7621020ec796379432c4639ed78f232f188a4c92
-
alt-php70-process_7.0.33-146_amd64.deb
sha:4e19108f3ee1258245540a523d0007fd181a1853
-
alt-php70-pspell_7.0.33-146_amd64.deb
sha:2ccf74b398bb86274ac9b54679d5b2f515b4a164
-
alt-php70-recode_7.0.33-146_amd64.deb
sha:e3d0ef44c64f9ec70ced775444b5c20d4f6cc92a
-
alt-php70-snmp_7.0.33-146_amd64.deb
sha:d00966fff360fbfeea8e2eaab1d4cd39c401fcb1
-
alt-php70-soap_7.0.33-146_amd64.deb
sha:1d3cf4998dcaba703b843f9c3c2935604e085e87
-
alt-php70-tidy_7.0.33-146_amd64.deb
sha:d32425e0a33b30cb6d84f7ee79fce587e19c40da
-
alt-php70-xml_7.0.33-146_amd64.deb
sha:5d7a656480e5e4291b68f599bab4c8510cc28420
-
alt-php70-xmlrpc_7.0.33-146_amd64.deb
sha:3e8eb99efa0ca5b082d8d5537180b50cb6eeaeac
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.