[CLSA-2026:1790946728] Fix CVE(s): CVE-2025-14181, CVE-2026-6103, CVE-2026-91765, CVE-2026-92842
Type:
security
Severity:
Important
Release date:
2026-10-02 13:12:31 UTC
Description:
* SECURITY UPDATE: heap buffer over-read in the convert.* stream filters - debian/patches/php-7.1-CVE-2026-92842.patch: backport upstream commit b4e3397ec8 in ext/standard/filters.c. The base64-encode, quoted-printable-encode and quoted-printable-decode constructors copied line-break-chars with the strlen()-based pestrdup() but kept the caller's length, so a value containing a NUL byte was truncated and the filter later read lbchars_len bytes past the end of the shorter copy. They now use pestrndup() with the real length. Adds the upstream regression test. - CVE-2026-92842 * SECURITY UPDATE: integer overflow in the SOAP client HTTP body reader - debian/patches/php-7.1-CVE-2025-14181.patch: backport upstream commit b11bd1d939 in ext/soap/php_http.c. get_http_body() accumulated chunked body sizes in a signed int and guarded growth with "http_buf_size + buf_size + 1 < 0", which overflow makes undefined and which a compiler may drop, so a server sending large chunk sizes could shrink the reallocation and make the following read overflow the heap buffer. The accumulator is now size_t, the chunk size is unsigned, each growth step is bounded by ZSTR_MAX_LEN and done with zend_string_safe_realloc(), the Connection: close reader is bounded the same way, and the relative redirect path is built with safe_emalloc(). Adds the upstream regression test, adapted to stream its 2 GiB response instead of building it in memory. - CVE-2025-14181 * SECURITY UPDATE: phar tar entry injection - debian/patches/php-7.1-CVE-2026-6103.patch: backport upstream commit 0994e2e887 in ext/phar/tar.c and ext/phar/phar_internal.h. Entry sizes were parsed with an unchecked octal accumulator that silently wrapped, stopped at the first non-octal byte and ignored GNU base-256 sizes, and only regular files had their data blocks skipped, so attacker controlled data could be parsed as the next tar header and inject an entry other tar readers never see. Sizes that cannot be parsed or represented are now rejected, every entry type that carries data has it skipped, GNU long link records are refused, and a ././@LongLink name longer than the archive is rejected. Adds the three upstream regression tests. - CVE-2026-6103 * SECURITY UPDATE: unbounded recursion in ext/soap XML parsing and decoding - debian/patches/php-7.1-CVE-2026-91765.patch: backport upstream commit 3655b79c7b in ext/soap/php_xml.c, php_encoding.c, php_soap.h and soap.c. A deeply nested SOAP request or WSDL, or a long chain or cycle of href references, recursed without limit in cleanup_xml_node(), get_node_with_attribute_recursive_ex() and the decoder, and crashed the process on stack exhaustion. The two tree walkers are now iterative, documents deeper than 2048 levels are rejected on libxml2 older than 2.13 (newer libxml2 enforces this itself), and decoding fails with "Encoding: Nesting level too deep" past 4096 nested values. Adds the three upstream regression tests. - CVE-2026-91765
Updated packages:
  • alt-php71_7.1.33-111_amd64.deb
    sha:4616b854ae5f08b1cc69b1b00536a376e0331273
  • alt-php71-bcmath_7.1.33-111_amd64.deb
    sha:6b3dfb037da22d0158fb90ef5004d2adf55a28a0
  • alt-php71-cli_7.1.33-111_amd64.deb
    sha:acfda118fa584c43c65f6a8525e1021a95ae5c05
  • alt-php71-common_7.1.33-111_amd64.deb
    sha:9e8bc14aebf048cde3ca09b655556381e14dec24
  • alt-php71-dba_7.1.33-111_amd64.deb
    sha:a0434fc053c7a0116d7d250a4f1aa4b405b0bf8c
  • alt-php71-dev_7.1.33-111_amd64.deb
    sha:011a1e4a73b9741f367512888d94e3459adbf143
  • alt-php71-enchant_7.1.33-111_amd64.deb
    sha:d6bd4a656d493a0b46a63928134bb34426bf600f
  • alt-php71-firebird_7.1.33-111_amd64.deb
    sha:a8dcd5f741d7d6a71446daa213db6378b6d083fc
  • alt-php71-gd_7.1.33-111_amd64.deb
    sha:9de5c793b5ae19338a8e37b807d17a1a68241bf7
  • alt-php71-imap_7.1.33-111_amd64.deb
    sha:d2ee11613708b0f0019a5ba434dba80fadcdfb8b
  • alt-php71-intl_7.1.33-111_amd64.deb
    sha:9535d3cf353122d6a887e0790030627d892a4b1a
  • alt-php71-ldap_7.1.33-111_amd64.deb
    sha:2f09de61900bd3692f5013a7da0ebae03424c09e
  • alt-php71-mbstring_7.1.33-111_amd64.deb
    sha:6bd57fec054b8a9f217561bbc999eeebda8869b2
  • alt-php71-mcrypt_7.1.33-111_amd64.deb
    sha:d72f6edd19c21297f38410ac80ac79530802cacb
  • alt-php71-mysqlnd_7.1.33-111_amd64.deb
    sha:45aa2a405e774c8405403aae9874c6d6253c15d0
  • alt-php71-odbc_7.1.33-111_amd64.deb
    sha:7209382c053aab6e0e8be0feade36db4048cd543
  • alt-php71-opcache_7.1.33-111_amd64.deb
    sha:148d115680214755597021870ed0482f0eb7e5a1
  • alt-php71-pdo_7.1.33-111_amd64.deb
    sha:5de540fb9142325981aa86546f705e7c0e7f1580
  • alt-php71-pgsql_7.1.33-111_amd64.deb
    sha:6e04bdc4b9cea7466562b98c96c00f54f6e646e3
  • alt-php71-php-fpm_7.1.33-111_amd64.deb
    sha:1a578d82c9de1185af686d8023d751a831aa64d7
  • alt-php71-process_7.1.33-111_amd64.deb
    sha:87b3f134c42cf225cf5f058862722fb3043ef57a
  • alt-php71-pspell_7.1.33-111_amd64.deb
    sha:c50e27855c59fd39b0e35b9dae79fa750aeba3ae
  • alt-php71-recode_7.1.33-111_amd64.deb
    sha:b1c69877fc0c99887207b271f1fd7aa855a281b7
  • alt-php71-snmp_7.1.33-111_amd64.deb
    sha:959e9bbad40a0996ea734bf006a7c29423cd7ccd
  • alt-php71-soap_7.1.33-111_amd64.deb
    sha:8862585fb11c2f4ceb3d01499aa2edf5995a25cd
  • alt-php71-tidy_7.1.33-111_amd64.deb
    sha:b2965284b94fae962cff08da8c5144e2ef084ad6
  • alt-php71-xml_7.1.33-111_amd64.deb
    sha:be4c88fb0cf06cf1fc30d2923f1e4fced091119c
  • alt-php71-xmlrpc_7.1.33-111_amd64.deb
    sha:93aa224b059644a23446a2d0095eac43309817a7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.