[CLSA-2026:1790941215] Fix CVE(s): CVE-2025-14181, CVE-2026-6103, CVE-2026-91765, CVE-2026-92842
Type:
security
Severity:
Important
Release date:
2026-10-02 17:54:33 UTC
Description:
* SECURITY UPDATE: heap over-read in the convert stream filters when line-break-chars contains a NUL byte - debian/patches/php-7.0-CVE-2026-92842.patch: the base64-encode, quoted-printable-encode and quoted-printable-decode filter constructors duplicated the user-supplied line-break-chars option with pestrdup(), which stops at the first NUL, while keeping the option's real length in inst->lbchars_len. Every memcpy() of lbchars_len bytes in the filter body then read past the end of the allocation. They now duplicate with pestrndup() so the allocation matches the recorded length. Adds the upstream regression test - CVE-2026-92842 * SECURITY UPDATE: buffer overflow in the SOAP client when reading a chunked HTTP response - debian/patches/php-7.0-CVE-2025-14181.patch: get_http_body() tracked the accumulated body length in a signed int and guarded each growth step with "http_buf_size + buf_size + 1 < 0" - signed overflow, which is undefined and cannot describe an overflow of the size_t the allocator receives. A hostile SOAP endpoint answering with Transfer-Encoding: chunked could drive the total past INT_MAX, wrap the reallocation length and make the following read write out of bounds. The accumulator is now a size_t, every growth step is bounded against ZSTR_MAX_LEN before it happens, and the chunked path reallocates through zend_string_safe_realloc(). The redirect-path allocation in the same upstream commit goes through safe_emalloc() - CVE-2025-14181 * SECURITY UPDATE: tar entry injection in ext/phar - debian/patches/php-7.0-CVE-2026-6103.patch: phar_parse_tarfile() read an entry's size with phar_tar_number(), which overflows a 32-bit accumulator without a check and silently stops at the first non-octal byte, and it skipped an entry's data blocks only for typeflag '\0' and TAR_FILE. A size field that overflows, uses GNU base-256 encoding or carries trailing garbage - or an entry type that carries data but was not skipped - left the stream on attacker-controlled payload that was then parsed as the next tar header, so PHP saw a different archive from every other tar implementation. Sizes that cannot be parsed or represented are now rejected, the unsupported GNU long link record is refused instead of being registered as an entry, the "././@LongLink" name is bounded by the size of the archive, and the data blocks of every entry type that carries data are skipped. Adds the three upstream regression tests - CVE-2026-6103 * SECURITY UPDATE: stack exhaustion in ext/soap on deeply nested XML - debian/patches/php-7.0-CVE-2026-91765.patch: cleanup_xml_node() and get_node_with_attribute_recursive_ex() walked parsed documents with self-recursive C functions and master_to_zval_int() re-entered itself for every nested element and every hop of an href chain, none of them bounded - and ext/soap sets XML_PARSE_HUGE, which removes the depth limit libxml2 would otherwise apply. A SOAP request or WSDL a few thousand levels deep, an href chain, or an array element referencing its own array exhausted the C stack and crashed the process. Both tree walks are now iterative, documents nested deeper than SOAP_MAX_XML_DEPTH are rejected on libxml2 versions that enforce no limit of their own, and the decoder is capped by a per-request depth counter reset at the start and end of every encode/decode cycle. Adds the three upstream regression tests - CVE-2026-91765
Updated packages:
  • alt-php70_7.0.33-146_amd64.deb
    sha:f0aa500b06eadd8b47b50dfe65a72566561c5722
  • alt-php70-bcmath_7.0.33-146_amd64.deb
    sha:cfd7b9a65ed002571e37a409de3d81293a63df61
  • alt-php70-cli_7.0.33-146_amd64.deb
    sha:4c7642037f0eb2f5bbb1a891a7208ee5b30f3963
  • alt-php70-common_7.0.33-146_amd64.deb
    sha:b14feb92a04aa466fed9c31fd36590385f080bda
  • alt-php70-dba_7.0.33-146_amd64.deb
    sha:769350fc3154090c7305224c96309a6cfbff5fac
  • alt-php70-dev_7.0.33-146_amd64.deb
    sha:d4a77ca9eae51cbfa7ee8375a8703be10c371b79
  • alt-php70-enchant_7.0.33-146_amd64.deb
    sha:dfbc4b021d9102d08173973a0db0ae7d2f75cc91
  • alt-php70-firebird_7.0.33-146_amd64.deb
    sha:1c56393ff25ed8d8e2482412987594428c4621dc
  • alt-php70-gd_7.0.33-146_amd64.deb
    sha:bfd88132cfc49baccf2bed72f87dac61276d00c4
  • alt-php70-imap_7.0.33-146_amd64.deb
    sha:4fb905e977a9eeaf999642dec27b42ef470da434
  • alt-php70-intl_7.0.33-146_amd64.deb
    sha:ee5e4d0baab805b2c5801fe72bf0fab3b47bd1cf
  • alt-php70-ldap_7.0.33-146_amd64.deb
    sha:10714305ce0e91ab9e255f2cd45a98a5fdb980d5
  • alt-php70-mbstring_7.0.33-146_amd64.deb
    sha:4f755b2cf9765f1c1b8e3346ed1d893861b05379
  • alt-php70-mcrypt_7.0.33-146_amd64.deb
    sha:6a9e1b777d551cd3e89ff994b79b769553751488
  • alt-php70-mysqlnd_7.0.33-146_amd64.deb
    sha:759fb908d59627c4f52f81018dfd035ed88051c1
  • alt-php70-odbc_7.0.33-146_amd64.deb
    sha:509785c93dc6eeb51fa0c063cd5144adf04faf8e
  • alt-php70-opcache_7.0.33-146_amd64.deb
    sha:7c45af050f0a9a8ed871b3a7200399f423f0c708
  • alt-php70-pdo_7.0.33-146_amd64.deb
    sha:11897d1de9794006881c7ebeafa9aba8ff167abe
  • alt-php70-pgsql_7.0.33-146_amd64.deb
    sha:5ca485407cea4c1b733a750866ff7ef0f6af5df0
  • alt-php70-php-fpm_7.0.33-146_amd64.deb
    sha:7621020ec796379432c4639ed78f232f188a4c92
  • alt-php70-process_7.0.33-146_amd64.deb
    sha:4e19108f3ee1258245540a523d0007fd181a1853
  • alt-php70-pspell_7.0.33-146_amd64.deb
    sha:2ccf74b398bb86274ac9b54679d5b2f515b4a164
  • alt-php70-recode_7.0.33-146_amd64.deb
    sha:e3d0ef44c64f9ec70ced775444b5c20d4f6cc92a
  • alt-php70-snmp_7.0.33-146_amd64.deb
    sha:d00966fff360fbfeea8e2eaab1d4cd39c401fcb1
  • alt-php70-soap_7.0.33-146_amd64.deb
    sha:1d3cf4998dcaba703b843f9c3c2935604e085e87
  • alt-php70-tidy_7.0.33-146_amd64.deb
    sha:d32425e0a33b30cb6d84f7ee79fce587e19c40da
  • alt-php70-xml_7.0.33-146_amd64.deb
    sha:5d7a656480e5e4291b68f599bab4c8510cc28420
  • alt-php70-xmlrpc_7.0.33-146_amd64.deb
    sha:3e8eb99efa0ca5b082d8d5537180b50cb6eeaeac
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.