Release date:
2026-10-02 15:46:46 UTC
Description:
* SECURITY UPDATE: heap over-read in convert.* stream filters
- debian/patches/php-7.2-CVE-2026-92842.patch: duplicate
line-break-chars with pestrndup() so an embedded NUL byte no longer
truncates the copy while the full length is kept, in
ext/standard/filters.c (GHSA-88hq-2827-7pg6).
- CVE-2026-92842
* SECURITY UPDATE: heap overflow in SOAP chunked HTTP response handling
- debian/patches/php-7.2-CVE-2025-14181.patch: accumulate the body
size in size_t, bound each growth step by ZSTR_MAX_LEN and use
checked reallocation in get_http_body(), ext/soap/php_http.c
(GHSA-cj93-vc83-wgqv).
- CVE-2025-14181
* SECURITY UPDATE: phar tar entry injection
- debian/patches/php-7.2-CVE-2026-6103.patch: reject unparsable or
overflowing tar entry sizes and GNU long-link records, bound
././@LongLink names by the archive size and skip the data of every
entry type that carries data, in ext/phar/tar.c and
ext/phar/phar_internal.h (GHSA-j3wh-g957-2m85).
- CVE-2026-6103
* SECURITY UPDATE: unbounded recursion in ext/soap XML handling
- debian/patches/php-7.2-CVE-2026-91765.patch: make XML cleanup and
href lookup iterative, reject over-deep documents on libxml2 < 2.13
and cap the decoder nesting depth, in ext/soap/php_xml.c,
php_encoding.c, php_soap.h and soap.c (GHSA-rgrp-mwpx-f6rm).
- CVE-2026-91765
Updated packages:
-
alt-php72_7.2.34-95_amd64.deb
sha:f439ba0a8dbf195f9d5b3ef08376be0118f22fac
-
alt-php72-bcmath_7.2.34-95_amd64.deb
sha:5a33444192df235eb403b34d333cc9a0ffe4ea63
-
alt-php72-cli_7.2.34-95_amd64.deb
sha:420c9dcfa0a793e5f5d2eb736b5e49ef56cd9629
-
alt-php72-common_7.2.34-95_amd64.deb
sha:83412149182acac081b3f5718d58fdda5d6497d1
-
alt-php72-dba_7.2.34-95_amd64.deb
sha:1d020f9e1a10a59136ec78ccb57b8c3a753dc8d0
-
alt-php72-dev_7.2.34-95_amd64.deb
sha:80aaa304329c83cc2d5b44e25bbb4f0ec8a77ee1
-
alt-php72-enchant_7.2.34-95_amd64.deb
sha:5973f7ea1fe2e0d37df491ff6d5c4fae45decb52
-
alt-php72-firebird_7.2.34-95_amd64.deb
sha:dd4dde34a1a3280c328e8d10b7ea599911ff897a
-
alt-php72-gd_7.2.34-95_amd64.deb
sha:664d0ec4c312db04881bfc57eec417c83e22e7eb
-
alt-php72-imap_7.2.34-95_amd64.deb
sha:9dc6220142c9fd395d0ae7fb1d5e13eb25521b45
-
alt-php72-intl_7.2.34-95_amd64.deb
sha:49c1e94838252c392ee020247906f3aad2e77386
-
alt-php72-ldap_7.2.34-95_amd64.deb
sha:36ddb984514b8347e810901d62d5883d96963149
-
alt-php72-mbstring_7.2.34-95_amd64.deb
sha:b6a3fc3413574b42eb847cbe3f6e33d5c8e72f3e
-
alt-php72-mysqlnd_7.2.34-95_amd64.deb
sha:3750f057d3e49134809f74e2d962344d7ea61601
-
alt-php72-odbc_7.2.34-95_amd64.deb
sha:d9b8651d182a7ae6e92e68901af5162d81254e1a
-
alt-php72-opcache_7.2.34-95_amd64.deb
sha:ebdf3a7cc83c27d140786375314f6ee52184e553
-
alt-php72-pdo_7.2.34-95_amd64.deb
sha:d3d462bb357866198926ae06ddcbe0138628a813
-
alt-php72-pgsql_7.2.34-95_amd64.deb
sha:c8b3d44b0a3b1abfcb4237ffc46f7bdd84d02a4d
-
alt-php72-php-fpm_7.2.34-95_amd64.deb
sha:16fbec8160ba435dd80a509c34bf9b7860e3a55c
-
alt-php72-process_7.2.34-95_amd64.deb
sha:0f7179213f97bc94d24178d20b67b2b65f8c7a2d
-
alt-php72-pspell_7.2.34-95_amd64.deb
sha:394a694e425bec513d88e8c86858d0da29c3acc2
-
alt-php72-recode_7.2.34-95_amd64.deb
sha:219d5b594e8557f6d846318334cb28d9f9fb53b5
-
alt-php72-snmp_7.2.34-95_amd64.deb
sha:667399636e64cbf432cb8c746dfe896cc179e050
-
alt-php72-soap_7.2.34-95_amd64.deb
sha:afdd224116f13795668612ffbbfa5d8102a1b73e
-
alt-php72-sodium_7.2.34-95_amd64.deb
sha:2e106095cb517cab68dcb130a3b8587617d6f347
-
alt-php72-tidy_7.2.34-95_amd64.deb
sha:27df5d051f1eee2e09ac899e3bbce85c0c86b0a9
-
alt-php72-xml_7.2.34-95_amd64.deb
sha:1dfac2b9a8538a6801e3497244316ffc456fbfb6
-
alt-php72-xmlrpc_7.2.34-95_amd64.deb
sha:7fb804a6c7a18b2b1a5ee20a1495bd9cb3be0f54
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.