[CLSA-2026:1790985564] Fix CVE(s): CVE-2025-14181, CVE-2026-6103, CVE-2026-91765, CVE-2026-92842
Type:
security
Severity:
Important
Release date:
2026-10-02 23:59:37 UTC
Description:
* SECURITY UPDATE: heap over-read in convert.* stream filters - debian/patches/php-8.1-CVE-2026-92842.patch: duplicate line-break-chars with pestrndup() so an embedded NUL byte no longer truncates the copy while lbchars_len keeps the full length in ext/standard/filters.c. - CVE-2026-92842 * SECURITY UPDATE: heap overflow reading chunked SOAP HTTP responses - debian/patches/php-8.1-CVE-2025-14181.patch: use a size_t accumulator and unsigned chunk size, bound every growth step against ZSTR_MAX_LEN and use checked allocations in get_http_body(), and use a checked allocation when building the relative redirect path in make_http_soap_request() in ext/soap/php_http.c. - CVE-2025-14181 * SECURITY UPDATE: phar tar entry injection - debian/patches/php-8.1-CVE-2026-6103.patch: reject tar entry sizes that cannot be parsed or represented, refuse GNU long link records and skip the data blocks of every entry type that carries data in ext/phar/tar.c and ext/phar/phar_internal.h. - CVE-2026-6103 * SECURITY UPDATE: unbounded recursion in SOAP XML parsing and decoding - debian/patches/php-8.1-CVE-2026-91765.patch: make node cleanup and attribute lookup iterative, reject over-deep documents and cap the decoder nesting depth in ext/soap/php_xml.c, ext/soap/php_encoding.c, ext/soap/php_soap.h and ext/soap/soap.c. - CVE-2026-91765
Updated packages:
  • alt-php81_8.1.34-33_amd64.deb
    sha:851127e7fdefdb5d3e0d7818347fa48691a52444
  • alt-php81-bcmath_8.1.34-33_amd64.deb
    sha:497064fe455bf887fbd7cde429bbeb1a145676ad
  • alt-php81-cli_8.1.34-33_amd64.deb
    sha:05f05f763ac64ae4e955245c34498da2fbb74119
  • alt-php81-common_8.1.34-33_amd64.deb
    sha:6365fecb337508f130c823abb7d7dc1125d80c61
  • alt-php81-dba_8.1.34-33_amd64.deb
    sha:06873327bea23d4072bb30f9ca3a7d556d0d43bc
  • alt-php81-dev_8.1.34-33_amd64.deb
    sha:1b774b51e1d63d242ea56300d0e9a3eabe0313d6
  • alt-php81-enchant_8.1.34-33_amd64.deb
    sha:af5099d14ec9415a03953c329d930ef4fcde30c0
  • alt-php81-firebird_8.1.34-33_amd64.deb
    sha:42f620ee88343e7cc33b3e3de19045e1e3c06292
  • alt-php81-gd_8.1.34-33_amd64.deb
    sha:7e97f666b4d2faab069d58eb8bdfde9956d457a0
  • alt-php81-imap_8.1.34-33_amd64.deb
    sha:a70dc53d3bfb36028ff208368163568ceaf3e3bc
  • alt-php81-intl_8.1.34-33_amd64.deb
    sha:64ecb0d3149b778f4acf96ab8c58c41afca22902
  • alt-php81-ldap_8.1.34-33_amd64.deb
    sha:ae93ffa3033a686a08afd8f15c4a560d9f418153
  • alt-php81-mbstring_8.1.34-33_amd64.deb
    sha:d4f3f0f970e171a9b816e5ac22fba4835be92df2
  • alt-php81-mysqlnd_8.1.34-33_amd64.deb
    sha:11712785c16b86ccccbdd78bc416f24a36a5e986
  • alt-php81-odbc_8.1.34-33_amd64.deb
    sha:1105e65017b7a8676e02db31c8bc90e8e4dc8610
  • alt-php81-opcache_8.1.34-33_amd64.deb
    sha:17021861436c29be78804a09a06420600132a0d5
  • alt-php81-pdo_8.1.34-33_amd64.deb
    sha:59892b50ba70a04867bd55a33b707daa9ecfb009
  • alt-php81-pgsql_8.1.34-33_amd64.deb
    sha:50affbff2917b6f8d8248154c6ada1c36515c1b9
  • alt-php81-php-fpm_8.1.34-33_amd64.deb
    sha:b05bc5e487caeb01db320bc521cc34da0bdb2ad7
  • alt-php81-process_8.1.34-33_amd64.deb
    sha:ae9bbd625fb873a4a8ced6215e0d10d1388c37a8
  • alt-php81-pspell_8.1.34-33_amd64.deb
    sha:1f53858d58ff0c523119d9a57542d71e8d08730d
  • alt-php81-snmp_8.1.34-33_amd64.deb
    sha:47163a64eaa0a32107a8dc4ac916e4abbd8c3d53
  • alt-php81-soap_8.1.34-33_amd64.deb
    sha:4ba19626bcf87997c23c93098056a4198628468e
  • alt-php81-sodium_8.1.34-33_amd64.deb
    sha:0babcb7f71b9ab70b26a575563c9ed90b0232d5b
  • alt-php81-tidy_8.1.34-33_amd64.deb
    sha:bf1745e1a9d0c9612c9b75483a6dc9cb3e8e9fc0
  • alt-php81-xml_8.1.34-33_amd64.deb
    sha:6adbc465cff3248ac850144fad0d9e25a083ef88
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.