Release date:
2026-10-03 21:06:46 UTC
Description:
- CVE-2026-92842: heap buffer overflow in the convert.* stream filters when
line-break-chars contains a NUL byte (GHSA-88hq-2827-7pg6). The base64-encode,
quoted-printable-encode and quoted-printable-decode filter constructors
duplicated lbchars with the strlen-based pestrdup(), which truncates at the
first NUL, while lbchars_len kept the caller's original length; the filter
then copied lbchars_len bytes out of the shorter allocation. Duplicate with
pestrndup(lbchars, lbchars_len, persistent) instead
- CVE-2025-14181: integer overflow in ext/soap get_http_body() leading to a heap
buffer overflow (GHSA-cj93-vc83-wgqv). The chunked-transfer accumulator was a
signed int guarded by "http_buf_size + buf_size + 1 < 0", which is
signed-overflow UB that the compiler removes, so an attacker-controlled chunk
size could wrap the erealloc() size and the body was then written past the
allocation. Make the accumulator size_t, bound every growth step against
SOAP_HTTP_MAX_BODY_LEN ((size_t) INT_MAX - 1, the local stand-in for
upstream's ZSTR_MAX_LEN) before the add is performed, read the chunk size into
an unsigned int as %x requires, apply the same bound to the Content-Length and
connection-close paths, and allocate the redirect path with safe_emalloc()
- CVE-2026-6103: phar tar entry injection (GHSA-j3wh-g957-2m85). phar_tar_number()
wrapped silently on an oversized octal size field and ignored trailing garbage
and GNU base-256 sizes, and only entries of type '\0' and '0' had their data
blocks skipped, so a crafted archive could leave the stream positioned on
attacker data that was then parsed as a tar header - making PharData show
entries no conforming tar reader sees. Parse the size with a strict
phar_tar_size() that rejects anything it cannot represent, skip the data of
every type that carries data via phar_tar_type_has_data(), refuse unsupported
GNU long link ('K') records, and bound a ././@LongLink name by the archive size
- CVE-2026-91765: unbounded recursion in ext/soap XML parsing and decoding
(GHSA-rgrp-mwpx-f6rm). cleanup_xml_node() and
get_node_with_attribute_recursive_ex() recursed once per document level, and
master_to_zval_int() recursed once per href hop, so a deeply nested or
href-chained SOAP message exhausted the stack and crashed the process. Both
traversals become iterative, documents deeper than SOAP_MAX_XML_DEPTH (2048)
are rejected at parse time on libxml2 below 2.13, and the decoder carries a
decode_depth counter in the soap globals that is capped at
SOAP_MAX_DECODE_DEPTH and reset by encode_reset_ns()/encode_finish()
Updated packages:
-
alt-php54-5.4.45-198.el10.x86_64.rpm
sha:c7edf6d489dce59008045f09326a62b22d92031ad42febb1888dfa79f2b9b31f
-
alt-php54-bcmath-5.4.45-198.el10.x86_64.rpm
sha:b0f1bebd6ae1f66f30cd8f5bc3e2a2a96666355e6f9ed7c54d3646610d93d923
-
alt-php54-cli-5.4.45-198.el10.x86_64.rpm
sha:4b2488a0cabe67ea2d100f16c9fa2abe7977fd08a991e0b763810e5855ea9361
-
alt-php54-common-5.4.45-198.el10.x86_64.rpm
sha:b5db4a7e1fee5996a4827e73432b3b1ac8a69515379a53e5b7aad62765931bd3
-
alt-php54-dba-5.4.45-198.el10.x86_64.rpm
sha:526ef998bbb95c723a41a58e2c317def9f4084143ff373eca1a0e60d3dd93594
-
alt-php54-dbx-5.4.45-198.el10.x86_64.rpm
sha:fce16f501bf3a8aa34b9f1179bc622608524991a3c9e226c455622f0d1f73d49
-
alt-php54-devel-5.4.45-198.el10.x86_64.rpm
sha:00d29aef5c3d7c1592eb7a401204507a2a67f610860094cb87076b6dbb973b4b
-
alt-php54-enchant-5.4.45-198.el10.x86_64.rpm
sha:436136f16195a2b6affa2fb8b3b4e65575d8d1742379de10f4a594d0e667864e
-
alt-php54-firebird-5.4.45-198.el10.x86_64.rpm
sha:2ba4cfcc10d34140cc23d6ffbf66df9e1df76da00d5a635dd991131e79b5d37f
-
alt-php54-gd-5.4.45-198.el10.x86_64.rpm
sha:887ed1340d972fdde820c283b4c4f731fc50a94090c181a458c0885b86c407b3
-
alt-php54-imap-5.4.45-198.el10.x86_64.rpm
sha:62963f5cccf70f067f7dd8de397cb8589dbf13e4dc65d9c2c95d27a6ae3da81e
-
alt-php54-intl-5.4.45-198.el10.x86_64.rpm
sha:b8e2ebac24b3f39f2bb440f872daf51693b751549534cec87e17917b8864d21f
-
alt-php54-ldap-5.4.45-198.el10.x86_64.rpm
sha:4af5e00d77c402b3e51d703aad6a19ee39a47ca5a4bc444c9432e5bb0592f3e0
-
alt-php54-mbstring-5.4.45-198.el10.x86_64.rpm
sha:d01e5f8b67595ffc80a46761b146a64b656e5da61a977159a4eb11f83cbac06a
-
alt-php54-mcrypt-5.4.45-198.el10.x86_64.rpm
sha:de4d90ed0250900118fc1ad0b4163535f8abf2627d317f63ead418d330fd39d0
-
alt-php54-mssql-5.4.45-198.el10.x86_64.rpm
sha:e024b034d3e85d0ad61b2d1a2dcc5482f26741b664e9abe4995247319bcdf289
-
alt-php54-mysqlnd-5.4.45-198.el10.x86_64.rpm
sha:9a6b0bc62829b1ba32daada0e93e853d58facbec5d926b4a6a379dc3ae6c8164
-
alt-php54-odbc-5.4.45-198.el10.x86_64.rpm
sha:063d729aa8cbbe149fe3a88c4066678eee3b0a86bee16b6b74aa8c971f2d8f41
-
alt-php54-pdo-5.4.45-198.el10.x86_64.rpm
sha:4c6182835c3c53ceee4b0d77fe519c58d8c5551975a93f07c886852d3d6e8d7f
-
alt-php54-pgsql-5.4.45-198.el10.x86_64.rpm
sha:e85bb02256e184da2aeba260b03d05fa4f20a608cfcda753a2a1ea0db3115ec7
-
alt-php54-php-fpm-5.4.45-198.el10.x86_64.rpm
sha:d7e42e0e5df82e0ea5bfcadc366f64d09f1c3beaeba80bb972fc034b3eb81a9e
-
alt-php54-process-5.4.45-198.el10.x86_64.rpm
sha:8484273e62b244d98857a4e00ebdfb252fe1817fad388fcc7a0b1c7f13a7c68e
-
alt-php54-pspell-5.4.45-198.el10.x86_64.rpm
sha:b34d74178a19dd57cd2d4b8d8ba0f3dc85ca62369299476a1db870249167774d
-
alt-php54-recode-5.4.45-198.el10.x86_64.rpm
sha:c760c9c8d41799ee6760346107a98f40b1e3d9f86b11814a53db67bb484de512
-
alt-php54-snmp-5.4.45-198.el10.x86_64.rpm
sha:7bedf4fd09d34ddd9fe29657609199014dcdb522fe3ca6ff933ffbeaed74e449
-
alt-php54-soap-5.4.45-198.el10.x86_64.rpm
sha:ccdab6dc49113710a850f511f087d7efd488d5bafdf6d90a541fc5e706df5ac6
-
alt-php54-sybase-5.4.45-198.el10.x86_64.rpm
sha:e19ed06217027e5871f584504ddf7c78bdb53c246019fd856d030be7154fcbf9
-
alt-php54-tidy-5.4.45-198.el10.x86_64.rpm
sha:7766f02a50049b66e653e6ec3a996ad46df106776dae9968df9e8d2029889bba
-
alt-php54-xml-5.4.45-198.el10.x86_64.rpm
sha:6f401a15db47322052ca661a7b813939511ee0690740e8c8ef6add6f44cb611b
-
alt-php54-xmlrpc-5.4.45-198.el10.x86_64.rpm
sha:e3fbeeb913b64a399fc7ec344220894052634ce5dd91553b1d76e9f3bca77aea
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.