[CLSA-2026:1790998143] Fix CVE(s): CVE-2025-14181, CVE-2026-6103, CVE-2026-91765, CVE-2026-92842
Type:
security
Severity:
Important
Release date:
2026-10-03 03:29:18 UTC
Description:
* SECURITY UPDATE: heap over-read in convert.* stream filters - debian/patches/php-8.1-CVE-2026-92842.patch: duplicate line-break-chars with pestrndup() so an embedded NUL byte no longer truncates the copy while lbchars_len keeps the full length in ext/standard/filters.c. - CVE-2026-92842 * SECURITY UPDATE: heap overflow reading chunked SOAP HTTP responses - debian/patches/php-8.1-CVE-2025-14181.patch: use a size_t accumulator and unsigned chunk size, bound every growth step against ZSTR_MAX_LEN and use checked allocations in get_http_body(), and use a checked allocation when building the relative redirect path in make_http_soap_request() in ext/soap/php_http.c. - CVE-2025-14181 * SECURITY UPDATE: phar tar entry injection - debian/patches/php-8.1-CVE-2026-6103.patch: reject tar entry sizes that cannot be parsed or represented, refuse GNU long link records and skip the data blocks of every entry type that carries data in ext/phar/tar.c and ext/phar/phar_internal.h. - CVE-2026-6103 * SECURITY UPDATE: unbounded recursion in SOAP XML parsing and decoding - debian/patches/php-8.1-CVE-2026-91765.patch: make node cleanup and attribute lookup iterative, reject over-deep documents and cap the decoder nesting depth in ext/soap/php_xml.c, ext/soap/php_encoding.c, ext/soap/php_soap.h and ext/soap/soap.c. - CVE-2026-91765
Updated packages:
  • alt-php81_8.1.34-33_amd64.deb
    sha:851127e7fdefdb5d3e0d7818347fa48691a52444
  • alt-php81-bcmath_8.1.34-33_amd64.deb
    sha:b2bfc8cd4e599eecc81afb68803ec213643dde2d
  • alt-php81-cli_8.1.34-33_amd64.deb
    sha:b8ae60671c1c7907cb02eadda7dd86f5813535a4
  • alt-php81-common_8.1.34-33_amd64.deb
    sha:422f329546034d503ff347dd490e71a1c2e0736f
  • alt-php81-dba_8.1.34-33_amd64.deb
    sha:9df36505aa97511c26fbaffcc6fc3ad92e74d1f5
  • alt-php81-dev_8.1.34-33_amd64.deb
    sha:7f2e63a1e8a9eed56f6e5e09e55ab1372fb95258
  • alt-php81-enchant_8.1.34-33_amd64.deb
    sha:919c1a1cdef6b8d2f0048324b7b568ba0ad26568
  • alt-php81-firebird_8.1.34-33_amd64.deb
    sha:b5dd748084f875d40aaac87b78c629c9d6a40ec8
  • alt-php81-gd_8.1.34-33_amd64.deb
    sha:0a1d50c1e145f8855cf6809e0c87529f71517b94
  • alt-php81-imap_8.1.34-33_amd64.deb
    sha:6a17f88295f6b4c0f410609607a11b1ce04040cb
  • alt-php81-intl_8.1.34-33_amd64.deb
    sha:8defba583f6356a97b017b959810b84153c929e6
  • alt-php81-ldap_8.1.34-33_amd64.deb
    sha:9212f7f42e53a9488688ca3823cb5101c05c2d26
  • alt-php81-mbstring_8.1.34-33_amd64.deb
    sha:6f785651c5b9e935ef1e6435739af826be2a5e00
  • alt-php81-mysqlnd_8.1.34-33_amd64.deb
    sha:22745c95ee5e74aab2382c08178d73d36259b42e
  • alt-php81-odbc_8.1.34-33_amd64.deb
    sha:3b387a36e45c1ae19c5eae18ab97cb9a505f1140
  • alt-php81-opcache_8.1.34-33_amd64.deb
    sha:0cd41b2af809d9a997104cd07c5811a0431b58ae
  • alt-php81-pdo_8.1.34-33_amd64.deb
    sha:071674b054d8a1cf8ce09f475bb8ce168d8c07d0
  • alt-php81-pgsql_8.1.34-33_amd64.deb
    sha:550ad5c961c125b29a92ec63f8ca7d1f536eb8a8
  • alt-php81-php-fpm_8.1.34-33_amd64.deb
    sha:c96dccf1a95903556efb2bc6f8d7af6ac99fec36
  • alt-php81-process_8.1.34-33_amd64.deb
    sha:d14e1ac2aa3d920d3f59322976b30ea9e86239f2
  • alt-php81-pspell_8.1.34-33_amd64.deb
    sha:585e89d0081c2c02133ce1bc35ad7e9e02a157f4
  • alt-php81-snmp_8.1.34-33_amd64.deb
    sha:14117d4990b2cc230f8c8c258a29609753ed46cb
  • alt-php81-soap_8.1.34-33_amd64.deb
    sha:9bec9d8e01ae091934ce6de48c9d33c4180b443f
  • alt-php81-sodium_8.1.34-33_amd64.deb
    sha:ad80712a7c270f07b724206b9bb35ba255060dae
  • alt-php81-tidy_8.1.34-33_amd64.deb
    sha:1894529f96b3499aa62d6cb901880430cef61212
  • alt-php81-xml_8.1.34-33_amd64.deb
    sha:a97e1cb9a01bf7d230aaead88e699cc61437d924
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.