Release date:
2026-10-02 11:22:54 UTC
Description:
* SECURITY UPDATE: heap out-of-bounds read in the convert.* stream filters
when the "line-break-chars" parameter contains a NUL byte
(GHSA-88hq-2827-7pg6)
- debian/patches/php-5.3-CVE-2026-92842.patch: the base64-encode,
quoted-printable-encode and quoted-printable-decode constructors in
ext/standard/filters.c duplicated lbchars with the strlen-based
pestrdup(), which truncates at the first NUL, while inst->lbchars_len
kept the original length, so every later use copied lbchars_len bytes
out of the shorter allocation; duplicate with pestrndup(lbchars,
lbchars_len, persistent) instead
- CVE-2026-92842
* SECURITY UPDATE: ext/soap heap buffer overflow when a SOAP peer sends a
chunked response (GHSA-cj93-vc83-wgqv)
- debian/patches/php-5.3-CVE-2025-14181.patch: get_http_body() in
ext/soap/php_http.c accumulated the body length in an int and guarded
the growth with "http_buf_size + buf_size + 1 < 0", which relies on
signed integer overflow, so the buffer could be reallocated smaller
than the data subsequently read into it; make the accumulator size_t
and the chunk length unsigned, bound every growth step against a new
SOAP_HTTP_BODY_MAX_LEN before the addition, add the same checked add to
the unbounded "Connection: close" branch and use safe_emalloc() for the
redirect path's allocation size
- CVE-2025-14181
* SECURITY UPDATE: phar tar entry injection - a crafted tar archive could
make the parser read attacker-controlled payload bytes as a tar header
(GHSA-j3wh-g957-2m85)
- debian/patches/php-5.3-CVE-2026-6103.patch: phar_parse_tarfile() in
ext/phar/tar.c sized entries with phar_tar_number(), which wraps on
octal overflow, ignores trailing garbage and reads a GNU base-256 field
as 0, and it only skipped the data blocks of typeflag '\0' and
TAR_FILE; parse the size with a new checked phar_tar_size(), refuse GNU
long link records, bound the ././@LongLink name by the archive size,
and skip the data of every type that carries data via a new
phar_tar_type_has_data()
- CVE-2026-6103
* SECURITY UPDATE: ext/soap stack exhaustion (unbounded recursion) on
deeply nested XML or on a chain of href references (GHSA-rgrp-mwpx-f6rm)
- debian/patches/php-5.3-CVE-2026-91765.patch: cleanup_xml_node() and
get_node_with_attribute_recursive_ex() in ext/soap/php_xml.c recursed
once per level of nesting and master_to_zval_int() in
ext/soap/php_encoding.c re-entered itself through href resolution, with
no depth limit in any of them and XML_PARSE_HUGE disabling libxml2's
own; make both tree walks iterative, reject documents deeper than
SOAP_MAX_XML_DEPTH in soap_xmlParseFile()/soap_xmlParseMemory(), and
cap the decoder with a decode_depth counter added to the soap module
globals, checked in master_to_zval_int() and cleared by
encode_reset_ns()/encode_finish()
- CVE-2026-91765
Updated packages:
-
alt-php53_5.3.29-215_amd64.deb
sha:9162790fdce7424253d037916df92b8c6b9c2683
-
alt-php53-bcmath_5.3.29-215_amd64.deb
sha:c97c5f697f41fbd9ac30c9ca7eb138c6d18d8aec
-
alt-php53-cli_5.3.29-215_amd64.deb
sha:8132cd126ee8e211a2fa1bf0f0084f22cf37d955
-
alt-php53-common_5.3.29-215_amd64.deb
sha:c8744a0970f4ddee547e462ab662080b7cf82d27
-
alt-php53-dba_5.3.29-215_amd64.deb
sha:1446414a7c15af848b5d7303fbd0d21b9a04d5f5
-
alt-php53-dbx_5.3.29-215_amd64.deb
sha:7f99c6747ba95d1d9cbe092a501c67c4b785dd12
-
alt-php53-dev_5.3.29-215_amd64.deb
sha:6c3710a1a44a15407cbaf738e500695101d572d4
-
alt-php53-enchant_5.3.29-215_amd64.deb
sha:7b2439235ea3a44b8e13c4360a5fbaed4403ce65
-
alt-php53-firebird_5.3.29-215_amd64.deb
sha:dc846b231cd877b6512b04011966e73537c2f9e4
-
alt-php53-gd_5.3.29-215_amd64.deb
sha:b72bebf6007863977c29c2e54ae95765f583332f
-
alt-php53-imap_5.3.29-215_amd64.deb
sha:9e8895f349b7dd417c595da07cdfe3d13182b6b3
-
alt-php53-intl_5.3.29-215_amd64.deb
sha:75c0b5fb431679af797fc2e54d1e1b4dd4848c65
-
alt-php53-ldap_5.3.29-215_amd64.deb
sha:001831bfcdf697fe0684d61ad693dc1935a7ab9e
-
alt-php53-mbstring_5.3.29-215_amd64.deb
sha:fa81e03c91b40e59ddd45617802b33ddc86617f9
-
alt-php53-mcrypt_5.3.29-215_amd64.deb
sha:1341074408c23653540fad351e304a82a1f8a8dc
-
alt-php53-mssql_5.3.29-215_amd64.deb
sha:cda98d3d3b82bd2f530fb0bd8aa2438d2b1b7692
-
alt-php53-mysqlnd_5.3.29-215_amd64.deb
sha:845419bad8c83c79f570a5e149a05038947d4645
-
alt-php53-odbc_5.3.29-215_amd64.deb
sha:05c5b720468508b2bf61e8d790bb6fc7481ed254
-
alt-php53-pdo_5.3.29-215_amd64.deb
sha:3c456161a14672c26b042a09aa09553e8d226eb1
-
alt-php53-pgsql_5.3.29-215_amd64.deb
sha:c750f93d31c06787f0d71aafbf1cb6aa04de9cbc
-
alt-php53-php-fpm_5.3.29-215_amd64.deb
sha:7d7c522b0af56fab5970ca35e0bef66518cab0bf
-
alt-php53-process_5.3.29-215_amd64.deb
sha:618ad2e5a763a3472aa71b3db3cce472fafbbb58
-
alt-php53-pspell_5.3.29-215_amd64.deb
sha:8581240a06e4b3852dfa39e6382d302e6376b0d9
-
alt-php53-recode_5.3.29-215_amd64.deb
sha:72215a4d0af1a8825d1c1495112b3f566b54bdde
-
alt-php53-snmp_5.3.29-215_amd64.deb
sha:3dc8be225b5c77de066773534e75473720df15f0
-
alt-php53-soap_5.3.29-215_amd64.deb
sha:560f65b030ba9a2b94a284e036628ec0f3e4cdd1
-
alt-php53-sybase_5.3.29-215_amd64.deb
sha:20c0e47948d6dfaabb7d9b49ac6c97c6b3195c13
-
alt-php53-tidy_5.3.29-215_amd64.deb
sha:d98a1921898bd65c36cb65b354d9ccb4f4a6f9fd
-
alt-php53-xml_5.3.29-215_amd64.deb
sha:ed1ca658159513917f13621260edbce02981e84a
-
alt-php53-xmlrpc_5.3.29-215_amd64.deb
sha:2ca6eb6f745888881e43007c59d3c51e86047057
-
alt-php53_5.3.29-215_arm64.deb
sha:2e4828fb64a33ed27903f091c3ca7ad126f93fcc
-
alt-php53-bcmath_5.3.29-215_arm64.deb
sha:22c603e22d08749b14fa6c5db109091076781e0a
-
alt-php53-cli_5.3.29-215_arm64.deb
sha:e327b7e085987ad00fc3106dec501a9b5f6c8a1f
-
alt-php53-common_5.3.29-215_arm64.deb
sha:885d3ab9dbf8dbf1a3e282f21b4d597f73e8874c
-
alt-php53-dba_5.3.29-215_arm64.deb
sha:1774a67ba8d434d58e14fe337d30a59b097936d8
-
alt-php53-dbx_5.3.29-215_arm64.deb
sha:db1f3b759d93d29b11fdc96fe46ec688b23b12c5
-
alt-php53-dev_5.3.29-215_arm64.deb
sha:62820cb1fccd915f9c3417246fbb9a0d81f33251
-
alt-php53-enchant_5.3.29-215_arm64.deb
sha:7edc28ea800de57dbb3de92ff7269d6cab18fcd2
-
alt-php53-firebird_5.3.29-215_arm64.deb
sha:fd6b4ed8317c1278e1ff0924dbe54e6dedb903e3
-
alt-php53-gd_5.3.29-215_arm64.deb
sha:01de8e6281f0b8d0e3fd961e99ebdec3ada9674e
-
alt-php53-imap_5.3.29-215_arm64.deb
sha:d3ed5cb430cbb12427559bdae8fe7a5c13d44525
-
alt-php53-intl_5.3.29-215_arm64.deb
sha:ae44a0dc2df9035cfd47587694df2bf2ec5d84c1
-
alt-php53-ldap_5.3.29-215_arm64.deb
sha:bc70ca70343394a266f5d9a8a78aab4e98d52645
-
alt-php53-mbstring_5.3.29-215_arm64.deb
sha:96e25b63895d522b4e0adab7f2e7239c4e15717a
-
alt-php53-mcrypt_5.3.29-215_arm64.deb
sha:e90e21d9b401a9938c94a4043fe228e9d64cc43f
-
alt-php53-mssql_5.3.29-215_arm64.deb
sha:254e6dc283471f0e3924b210bdc1c4daa487bc9a
-
alt-php53-mysqlnd_5.3.29-215_arm64.deb
sha:71644ce7764e1e3280ca833a5040fe346114a57c
-
alt-php53-odbc_5.3.29-215_arm64.deb
sha:2a3e776f87acf1afe13fb15a8923c385b451f6fd
-
alt-php53-pdo_5.3.29-215_arm64.deb
sha:e27798edc30c4456623b4882540ba81e7a5e7b09
-
alt-php53-pgsql_5.3.29-215_arm64.deb
sha:60a8a6dc5627f0d9502b73bd59a45c40c073af3b
-
alt-php53-php-fpm_5.3.29-215_arm64.deb
sha:6d3bf0464a74fe7b5bd12b50963000582fa585fb
-
alt-php53-process_5.3.29-215_arm64.deb
sha:575b35451e1c9d8ad712a31e1c365273ad2b7ac5
-
alt-php53-pspell_5.3.29-215_arm64.deb
sha:efc6c4da4fbd0093cdb23b6b07b37e4ee190d142
-
alt-php53-recode_5.3.29-215_arm64.deb
sha:3ff47a304dfb0b88b0f4717456ee481635ee1bd0
-
alt-php53-snmp_5.3.29-215_arm64.deb
sha:8acad7ff468a406099a830d6a7ebe122b5451354
-
alt-php53-soap_5.3.29-215_arm64.deb
sha:5e3b9e55499050101c202eaeb25b4aa1ad7d3d78
-
alt-php53-sybase_5.3.29-215_arm64.deb
sha:204ffd0a8955c0f029d835924460b451498f3019
-
alt-php53-tidy_5.3.29-215_arm64.deb
sha:57e4cdadd28a9187303a8a2e672fea3b8c830e87
-
alt-php53-xml_5.3.29-215_arm64.deb
sha:32f50af0363a0baeeac63525482d23bb7f192d1b
-
alt-php53-xmlrpc_5.3.29-215_arm64.deb
sha:2e720c8b1fe9a14aae1a1a57374df7683eb85cd6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.