Release date:
2026-10-02 13:12:31 UTC
Description:
* SECURITY UPDATE: heap buffer over-read in the convert.* stream filters
- debian/patches/php-7.1-CVE-2026-92842.patch: backport upstream commit
b4e3397ec8 in ext/standard/filters.c. The base64-encode,
quoted-printable-encode and quoted-printable-decode constructors
copied line-break-chars with the strlen()-based pestrdup() but kept
the caller's length, so a value containing a NUL byte was truncated
and the filter later read lbchars_len bytes past the end of the
shorter copy. They now use pestrndup() with the real length.
Adds the upstream regression test.
- CVE-2026-92842
* SECURITY UPDATE: integer overflow in the SOAP client HTTP body reader
- debian/patches/php-7.1-CVE-2025-14181.patch: backport upstream commit
b11bd1d939 in ext/soap/php_http.c. get_http_body() accumulated chunked
body sizes in a signed int and guarded growth with
"http_buf_size + buf_size + 1 < 0", which overflow makes undefined
and which a compiler may drop, so a server sending large chunk sizes
could shrink the reallocation and make the following read overflow
the heap buffer. The accumulator is now size_t, the chunk size is
unsigned, each growth step is bounded by ZSTR_MAX_LEN and done with
zend_string_safe_realloc(), the Connection: close reader is bounded
the same way, and the relative redirect path is built with
safe_emalloc(). Adds the upstream regression test, adapted to stream
its 2 GiB response instead of building it in memory.
- CVE-2025-14181
* SECURITY UPDATE: phar tar entry injection
- debian/patches/php-7.1-CVE-2026-6103.patch: backport upstream commit
0994e2e887 in ext/phar/tar.c and ext/phar/phar_internal.h. Entry sizes
were parsed with an unchecked octal accumulator that silently wrapped,
stopped at the first non-octal byte and ignored GNU base-256 sizes,
and only regular files had their data blocks skipped, so attacker
controlled data could be parsed as the next tar header and inject an
entry other tar readers never see. Sizes that cannot be parsed or
represented are now rejected, every entry type that carries data has
it skipped, GNU long link records are refused, and a ././@LongLink
name longer than the archive is rejected. Adds the three upstream
regression tests.
- CVE-2026-6103
* SECURITY UPDATE: unbounded recursion in ext/soap XML parsing and decoding
- debian/patches/php-7.1-CVE-2026-91765.patch: backport upstream commit
3655b79c7b in ext/soap/php_xml.c, php_encoding.c, php_soap.h and
soap.c. A deeply nested SOAP request or WSDL, or a long chain or
cycle of href references, recursed without limit in
cleanup_xml_node(), get_node_with_attribute_recursive_ex() and the
decoder, and crashed the process on stack exhaustion. The two tree
walkers are now iterative, documents deeper than 2048 levels are
rejected on libxml2 older than 2.13 (newer libxml2 enforces this
itself), and decoding fails with "Encoding: Nesting level too deep"
past 4096 nested values. Adds the three upstream regression tests.
- CVE-2026-91765
Updated packages:
-
alt-php71_7.1.33-111_amd64.deb
sha:4616b854ae5f08b1cc69b1b00536a376e0331273
-
alt-php71-bcmath_7.1.33-111_amd64.deb
sha:6b3dfb037da22d0158fb90ef5004d2adf55a28a0
-
alt-php71-cli_7.1.33-111_amd64.deb
sha:acfda118fa584c43c65f6a8525e1021a95ae5c05
-
alt-php71-common_7.1.33-111_amd64.deb
sha:9e8bc14aebf048cde3ca09b655556381e14dec24
-
alt-php71-dba_7.1.33-111_amd64.deb
sha:a0434fc053c7a0116d7d250a4f1aa4b405b0bf8c
-
alt-php71-dev_7.1.33-111_amd64.deb
sha:011a1e4a73b9741f367512888d94e3459adbf143
-
alt-php71-enchant_7.1.33-111_amd64.deb
sha:d6bd4a656d493a0b46a63928134bb34426bf600f
-
alt-php71-firebird_7.1.33-111_amd64.deb
sha:a8dcd5f741d7d6a71446daa213db6378b6d083fc
-
alt-php71-gd_7.1.33-111_amd64.deb
sha:9de5c793b5ae19338a8e37b807d17a1a68241bf7
-
alt-php71-imap_7.1.33-111_amd64.deb
sha:d2ee11613708b0f0019a5ba434dba80fadcdfb8b
-
alt-php71-intl_7.1.33-111_amd64.deb
sha:9535d3cf353122d6a887e0790030627d892a4b1a
-
alt-php71-ldap_7.1.33-111_amd64.deb
sha:2f09de61900bd3692f5013a7da0ebae03424c09e
-
alt-php71-mbstring_7.1.33-111_amd64.deb
sha:6bd57fec054b8a9f217561bbc999eeebda8869b2
-
alt-php71-mcrypt_7.1.33-111_amd64.deb
sha:d72f6edd19c21297f38410ac80ac79530802cacb
-
alt-php71-mysqlnd_7.1.33-111_amd64.deb
sha:45aa2a405e774c8405403aae9874c6d6253c15d0
-
alt-php71-odbc_7.1.33-111_amd64.deb
sha:7209382c053aab6e0e8be0feade36db4048cd543
-
alt-php71-opcache_7.1.33-111_amd64.deb
sha:148d115680214755597021870ed0482f0eb7e5a1
-
alt-php71-pdo_7.1.33-111_amd64.deb
sha:5de540fb9142325981aa86546f705e7c0e7f1580
-
alt-php71-pgsql_7.1.33-111_amd64.deb
sha:6e04bdc4b9cea7466562b98c96c00f54f6e646e3
-
alt-php71-php-fpm_7.1.33-111_amd64.deb
sha:1a578d82c9de1185af686d8023d751a831aa64d7
-
alt-php71-process_7.1.33-111_amd64.deb
sha:87b3f134c42cf225cf5f058862722fb3043ef57a
-
alt-php71-pspell_7.1.33-111_amd64.deb
sha:c50e27855c59fd39b0e35b9dae79fa750aeba3ae
-
alt-php71-recode_7.1.33-111_amd64.deb
sha:b1c69877fc0c99887207b271f1fd7aa855a281b7
-
alt-php71-snmp_7.1.33-111_amd64.deb
sha:959e9bbad40a0996ea734bf006a7c29423cd7ccd
-
alt-php71-soap_7.1.33-111_amd64.deb
sha:8862585fb11c2f4ceb3d01499aa2edf5995a25cd
-
alt-php71-tidy_7.1.33-111_amd64.deb
sha:b2965284b94fae962cff08da8c5144e2ef084ad6
-
alt-php71-xml_7.1.33-111_amd64.deb
sha:be4c88fb0cf06cf1fc30d2923f1e4fced091119c
-
alt-php71-xmlrpc_7.1.33-111_amd64.deb
sha:93aa224b059644a23446a2d0095eac43309817a7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.