[CLSA-2026:1791061271] alt-php56: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-03 21:01:26 UTC
Description:
- CVE-2026-92842: heap buffer over-read in the convert.* stream filters when "line-break-chars" contains a NUL (ext/standard/filters.c, GHSA-88hq-2827-7pg6). php_conv_base64_encode_ctor(), php_conv_qprint_encode_ctor() and php_conv_qprint_decode_ctor() duplicated the option with the strlen-based pestrdup() while keeping lbchars_len, which the option reader sets from Z_STRLEN, so "\0X" allocated one byte and the filters then copied two out of it on every line break. Backport of upstream commit b4e3397ec8f4; the three calls become pestrndup(lbchars, lbchars_len, persistent). Byte-identical to upstream, only the hunk line numbers differ. Upstream's regression test is carried, rewritten for the 5.6 runner as ext/standard/tests/filters/ghsa-88hq-2827-7pg6.phpt. - CVE-2025-14181: integer overflow in the SOAP client's chunked response reader (ext/soap/php_http.c, GHSA-cj93-vc83-wgqv). get_http_body() accumulated the body length in a signed int and guarded growth with "http_buf_size + buf_size + 1 < 0", which is signed overflow - undefined behaviour a modern compiler folds away - so a hostile endpoint answering with two 0x7fffffff-sized chunks made the second erealloc() request wrap to a small allocation that php_stream_read() then overflowed. Backport of upstream commit b11bd1d9390b: the accumulator becomes unsigned, each growth step is bounded before it is performed and the overflow test is a subtraction from the bound rather than a wrapping addition. 5.6 has no zend_string in this path, so the bound is INT_MAX - the representable maximum of the int *out_size this function reports the body length through - in place of upstream's ZSTR_MAX_LEN, and erealloc() stands in for zend_string_safe_realloc(). - CVE-2026-6103: phar tar entry injection (ext/phar/tar.c, ext/phar/phar_internal.h, GHSA-j3wh-g957-2m85). phar_tar_number() parsed the 512-byte header's size field with an unchecked octal accumulator over a php_uint32 and ignored trailing garbage and GNU base-256 encoding, and phar_parse_tarfile() skipped the data blocks of only the '\0' and TAR_FILE entry types. Either way the stream was left inside an entry's payload, which was then read as the next tar header - so an archive shows one set of entries to phar and another to every conforming tar reader. Backport of upstream commit 0994e2e887cd: a new phar_tar_size() rejects sizes that cannot be parsed or represented, a new phar_tar_type_has_data() decides the skip for every type, GNU long link records are refused outright, and the bug-61065 guard now bounds the long file name by the archive size. Adapted to C89 (int-returning helpers), to phar_destroy_phar_data()'s TSRMLS_CC and to the pemalloc'd long-name buffer. Upstream's three regression tests are carried, rewritten for the 5.6 runner and 5.6's exception text as ext/phar/tests/tar/ghsa-j3wh-g957-2m85-{size,typeflag,longlink}.phpt. - CVE-2026-91765: unbounded recursion in ext/soap XML parsing and decoding (ext/soap/php_xml.c, php_encoding.c, php_soap.h, soap.c, GHSA-rgrp-mwpx-f6rm). cleanup_xml_node() and get_node_with_attribute_recursive_ex() recursed once per XML nesting level and master_to_zval_int() once per decoded node and per href hop, with no cap; both SOAP parsers set XML_PARSE_HUGE, which turns off libxml2's own depth limit, so a deep envelope or WSDL - or a long href chain in a shallow one - exhausts the C stack. Backport of upstream commit 3655b79c7bfa: both walkers become iterative, a 2048-level document cap is enforced after parsing where libxml2 is older than 2.13, and the decoder takes a depth counter bailing out at twice that. The counter is added to this version's soap globals struct and reset in php_soap_init_globals(), encode_reset_ns() and encode_finish(), since soap_error0(E_ERROR) bails out past the matching decrement. Upstream's three regression tests are carried as ext/soap/tests/GHSA-rgrp-mwpx-f6rm{,-href-chain,-href-cycle}.phpt, with the scalar type hints dropped for 5.6 and, in the href-chain test, the reference marker php-5.6-CVE-2026-6722.patch's added Z_ADDREF_PP() makes var_dump() print here.
Updated packages:
  • alt-php56-5.6.40-142.el10.x86_64.rpm
    sha:7899f1ff79d6a715cf55652e7fc405087ff47f928e38e226ec52f79737861dd3
  • alt-php56-bcmath-5.6.40-142.el10.x86_64.rpm
    sha:1c88d14ee703c58411f2b72ac011e98e965b52a830dc1633c5614fbe460ebcc7
  • alt-php56-cli-5.6.40-142.el10.x86_64.rpm
    sha:5345637083f2c8fbe7306a09ff9e9612292040877c674b2c584a8527123b1103
  • alt-php56-common-5.6.40-142.el10.x86_64.rpm
    sha:50b83939ac24f09d64b385625e09a0ce3191be2274a936613f913ea18c78e865
  • alt-php56-dba-5.6.40-142.el10.x86_64.rpm
    sha:43e593b48de7cba7ddb4228186efa48849543bf4d5b29b6a85e974aba24c3c1e
  • alt-php56-dbx-5.6.40-142.el10.x86_64.rpm
    sha:8febf9b51d36b2c982a34032c4a1a4930100c0b905d1fe01366dddd9842b393a
  • alt-php56-devel-5.6.40-142.el10.x86_64.rpm
    sha:3a776442d7a48626f922f0399f17b6d5a2d5625ab5db50999fc498f828a1f9ec
  • alt-php56-enchant-5.6.40-142.el10.x86_64.rpm
    sha:aaee5fe5c1b1e0c955a3668198283ae8a147fcbf29ef81a1ef3886d039f2d2f6
  • alt-php56-firebird-5.6.40-142.el10.x86_64.rpm
    sha:4f34e68947ffe3b16923a5c9eadd1b4e1934a5f94766841aed94cd77a47d4361
  • alt-php56-gd-5.6.40-142.el10.x86_64.rpm
    sha:db300260e0d807e0d271c10765c0945589cbcd797bdb40551f4409b1aed9878b
  • alt-php56-imap-5.6.40-142.el10.x86_64.rpm
    sha:84982ea419c59cf4d4d91639798a83da004bc9ecaae7bf4c1abcdc11f6af04cb
  • alt-php56-intl-5.6.40-142.el10.x86_64.rpm
    sha:43c19979d0fcbd0727afafc70b87effd57a455072573813dd4036db7da369e08
  • alt-php56-ldap-5.6.40-142.el10.x86_64.rpm
    sha:ebf527314a9b6b3c789acb1f030bb201f4a38f5f5ed8b522f96ecb44aeea6bf1
  • alt-php56-mbstring-5.6.40-142.el10.x86_64.rpm
    sha:24dd3e71143554714d68aa10087e54fa51a7c7d839ea6295e05c8c41bf4b39ae
  • alt-php56-mcrypt-5.6.40-142.el10.x86_64.rpm
    sha:7000b8ba8d089ba81d501901e42b9638b067622373c5d55f1ef354ebbc4a2689
  • alt-php56-mssql-5.6.40-142.el10.x86_64.rpm
    sha:2b73674598ab61d3b7ca3cec125fd1f4eca371afd100c32180a77fb6c934eca5
  • alt-php56-mysqlnd-5.6.40-142.el10.x86_64.rpm
    sha:57d71bce27398d6bdb829043a3db6bcb661a5b13936dd2a53b53c71ffaca7541
  • alt-php56-odbc-5.6.40-142.el10.x86_64.rpm
    sha:4589d4b67582740a568052e6c4488e2e577759fa02de0c2ca6ae6e9b94b6ef8b
  • alt-php56-opcache-5.6.40-142.el10.x86_64.rpm
    sha:b7295ec005de2fe09fe67bb6c2cffb60d47f96daca47b6b262901e528473a2b5
  • alt-php56-pdo-5.6.40-142.el10.x86_64.rpm
    sha:d0c4d6fbb309427e69d884e2c7992e4535191c9077c52ac1c5d83ec63d0c218d
  • alt-php56-pgsql-5.6.40-142.el10.x86_64.rpm
    sha:16deb03017b26672f874c9f150c6e77ebb4ca4ae55f999be487f43eef76a0840
  • alt-php56-php-fpm-5.6.40-142.el10.x86_64.rpm
    sha:8c7c8a3f1d32010b48d0aa0dec43bcc73c83ebb24c8581c2d401a8f0c0f04c4e
  • alt-php56-process-5.6.40-142.el10.x86_64.rpm
    sha:19ea85543f4aab68e4865fd8d667875115f32e0886b9584abbd683c0c9fe50e4
  • alt-php56-pspell-5.6.40-142.el10.x86_64.rpm
    sha:827820daf28b514927e1d0979edccac7d7fcb6ac53b37b4eee15f3f1323f1041
  • alt-php56-recode-5.6.40-142.el10.x86_64.rpm
    sha:ec6da5497173ec2969f157344725ec26a91c382a1b1e3e3d072a8bd41a9e1ccd
  • alt-php56-snmp-5.6.40-142.el10.x86_64.rpm
    sha:1f435c619395722c1856a799d8b6ca877153b262a5e3cf2a30a03f37e76db061
  • alt-php56-soap-5.6.40-142.el10.x86_64.rpm
    sha:64209d0a5dae78ac22d8833a27aad421143348b691cf417304fff36ed90f4cf8
  • alt-php56-sybase-5.6.40-142.el10.x86_64.rpm
    sha:ff4135eed1f828c65e51651c6eee81c7f207588767d56e47a0a1b7e0c2353bc8
  • alt-php56-tidy-5.6.40-142.el10.x86_64.rpm
    sha:5eafb85939a3be1608af556cc3d6d5684173505bbb47780ebfa6934edc7a60bd
  • alt-php56-xml-5.6.40-142.el10.x86_64.rpm
    sha:8124e834c09bcdf10a738221da02f68bea93d39b3266fa34acf7d542113500bb
  • alt-php56-xmlrpc-5.6.40-142.el10.x86_64.rpm
    sha:7a60bc0af046fa127672bc73f645da3c605dc08cd06525cae4ad6b3911babb83
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.