[CLSA-2026:1790947549] alt-php56: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-02 13:26:11 UTC
Description:
- CVE-2026-92842: heap buffer over-read in the convert.* stream filters when "line-break-chars" contains a NUL (ext/standard/filters.c, GHSA-88hq-2827-7pg6). php_conv_base64_encode_ctor(), php_conv_qprint_encode_ctor() and php_conv_qprint_decode_ctor() duplicated the option with the strlen-based pestrdup() while keeping lbchars_len, which the option reader sets from Z_STRLEN, so "\0X" allocated one byte and the filters then copied two out of it on every line break. Backport of upstream commit b4e3397ec8f4; the three calls become pestrndup(lbchars, lbchars_len, persistent). Byte-identical to upstream, only the hunk line numbers differ. Upstream's regression test is carried, rewritten for the 5.6 runner as ext/standard/tests/filters/ghsa-88hq-2827-7pg6.phpt. - CVE-2025-14181: integer overflow in the SOAP client's chunked response reader (ext/soap/php_http.c, GHSA-cj93-vc83-wgqv). get_http_body() accumulated the body length in a signed int and guarded growth with "http_buf_size + buf_size + 1 < 0", which is signed overflow - undefined behaviour a modern compiler folds away - so a hostile endpoint answering with two 0x7fffffff-sized chunks made the second erealloc() request wrap to a small allocation that php_stream_read() then overflowed. Backport of upstream commit b11bd1d9390b: the accumulator becomes unsigned, each growth step is bounded before it is performed and the overflow test is a subtraction from the bound rather than a wrapping addition. 5.6 has no zend_string in this path, so the bound is INT_MAX - the representable maximum of the int *out_size this function reports the body length through - in place of upstream's ZSTR_MAX_LEN, and erealloc() stands in for zend_string_safe_realloc(). - CVE-2026-6103: phar tar entry injection (ext/phar/tar.c, ext/phar/phar_internal.h, GHSA-j3wh-g957-2m85). phar_tar_number() parsed the 512-byte header's size field with an unchecked octal accumulator over a php_uint32 and ignored trailing garbage and GNU base-256 encoding, and phar_parse_tarfile() skipped the data blocks of only the '\0' and TAR_FILE entry types. Either way the stream was left inside an entry's payload, which was then read as the next tar header - so an archive shows one set of entries to phar and another to every conforming tar reader. Backport of upstream commit 0994e2e887cd: a new phar_tar_size() rejects sizes that cannot be parsed or represented, a new phar_tar_type_has_data() decides the skip for every type, GNU long link records are refused outright, and the bug-61065 guard now bounds the long file name by the archive size. Adapted to C89 (int-returning helpers), to phar_destroy_phar_data()'s TSRMLS_CC and to the pemalloc'd long-name buffer. Upstream's three regression tests are carried, rewritten for the 5.6 runner and 5.6's exception text as ext/phar/tests/tar/ghsa-j3wh-g957-2m85-{size,typeflag,longlink}.phpt. - CVE-2026-91765: unbounded recursion in ext/soap XML parsing and decoding (ext/soap/php_xml.c, php_encoding.c, php_soap.h, soap.c, GHSA-rgrp-mwpx-f6rm). cleanup_xml_node() and get_node_with_attribute_recursive_ex() recursed once per XML nesting level and master_to_zval_int() once per decoded node and per href hop, with no cap; both SOAP parsers set XML_PARSE_HUGE, which turns off libxml2's own depth limit, so a deep envelope or WSDL - or a long href chain in a shallow one - exhausts the C stack. Backport of upstream commit 3655b79c7bfa: both walkers become iterative, a 2048-level document cap is enforced after parsing where libxml2 is older than 2.13, and the decoder takes a depth counter bailing out at twice that. The counter is added to this version's soap globals struct and reset in php_soap_init_globals(), encode_reset_ns() and encode_finish(), since soap_error0(E_ERROR) bails out past the matching decrement. Upstream's three regression tests are carried as ext/soap/tests/GHSA-rgrp-mwpx-f6rm{,-href-chain,-href-cycle}.phpt, with the scalar type hints dropped for 5.6 and, in the href-chain test, the reference marker php-5.6-CVE-2026-6722.patch's added Z_ADDREF_PP() makes var_dump() print here.
Updated packages:
  • alt-php56-5.6.40-142.el6.x86_64.rpm
    sha:5eb44f1d06fd8b250766a7d8ece71183430a5c5ec1f7282764c5cd7135541483
  • alt-php56-bcmath-5.6.40-142.el6.x86_64.rpm
    sha:db2771d97f4b44d75f29b63e80f1b8ec87eb2e55948d867a17d711959b8b02f5
  • alt-php56-cli-5.6.40-142.el6.x86_64.rpm
    sha:66bdfced2da38076d9f3c8f84bc16d4e97a40f4fd64d019efb75f3d7d0d61927
  • alt-php56-common-5.6.40-142.el6.x86_64.rpm
    sha:8a210cd2d65b59a1bab5cbddbf2e0d914db95cd1c19e6896baffa309fd132b0d
  • alt-php56-dba-5.6.40-142.el6.x86_64.rpm
    sha:b600a749e48a9e993be668767bff2749f6af584d6ace9ee8e15a45dd4452a687
  • alt-php56-dbx-5.6.40-142.el6.x86_64.rpm
    sha:43d7b972738ae9808d253b3e2360900cc6032f2a84743a14b56f901288d2f104
  • alt-php56-devel-5.6.40-142.el6.x86_64.rpm
    sha:d07307750bd728b1dda0ed37815f5ec83ed48a7d6da5355f4455139134de3f64
  • alt-php56-enchant-5.6.40-142.el6.x86_64.rpm
    sha:67c7d8483caedeaee11fa555802cde95b06254f706e3cd5bd83aa96f7b76937b
  • alt-php56-firebird-5.6.40-142.el6.x86_64.rpm
    sha:f0a24c3ded2b2d370d7753f2a7af369a03cb2f455818b10cc721dae092471bdb
  • alt-php56-gd-5.6.40-142.el6.x86_64.rpm
    sha:cbdf6366e78dd5efa5831a9f3c8c853e503194a3efbe3710b7619d8c585d73e3
  • alt-php56-imap-5.6.40-142.el6.x86_64.rpm
    sha:59656a2cc93fb8b373d9298b8ff9fa9b43cc32ea5445b90c4c5b656dbf086903
  • alt-php56-intl-5.6.40-142.el6.x86_64.rpm
    sha:846762dc0e38a1a0b4245849fb0f1fd550cb91228301cd23522c5cf3edfe291c
  • alt-php56-ldap-5.6.40-142.el6.x86_64.rpm
    sha:a0b4a90c64184fbc99251ffeb7711de0864bed6644b04e9232ff5f0b5b9ea043
  • alt-php56-mbstring-5.6.40-142.el6.x86_64.rpm
    sha:9e69374028784a9628c0d2e3ae3e0a46085fe1ea9764ef03b3afdd3b9550e43b
  • alt-php56-mcrypt-5.6.40-142.el6.x86_64.rpm
    sha:70be3e59fe080d0cb2a8428f8f50ca8baa8b98c8ec226b7fc9056ab73d62d14e
  • alt-php56-mssql-5.6.40-142.el6.x86_64.rpm
    sha:decbe766d5264716cbcf0eb7757a17e1a444f6e51955d95a917abd2307517870
  • alt-php56-mysqlnd-5.6.40-142.el6.x86_64.rpm
    sha:a2cc7ece55e0911ecc7ff4e88432e155c59d17b42b105bca7288e3cf5e7cd194
  • alt-php56-odbc-5.6.40-142.el6.x86_64.rpm
    sha:a8876dc28e969dcd1a7a6249fb9934211ff8dce7dfa50ef0323cf788f71183b7
  • alt-php56-opcache-5.6.40-142.el6.x86_64.rpm
    sha:25cc7ad5c9e75dc6082f9554a95b5e7fe8e58790e86ace9aed2cd1492ac534f7
  • alt-php56-pdo-5.6.40-142.el6.x86_64.rpm
    sha:bc1b079467acd92fc83e0322865e38b385b0ea2d1dc0649afbce000fd55429c3
  • alt-php56-pgsql-5.6.40-142.el6.x86_64.rpm
    sha:22af29702633e4e0930d33275d3620cb75be74562267ab42c57086cf64e30700
  • alt-php56-php-fpm-5.6.40-142.el6.x86_64.rpm
    sha:9560ff05c6e39770e50213206bfc746a73cb55e40eee11a16a1e96e542663305
  • alt-php56-process-5.6.40-142.el6.x86_64.rpm
    sha:980f6a776bfec4dc804e36d12f45c1a28b19a607a7ec0190a8900a23ca59e3b1
  • alt-php56-pspell-5.6.40-142.el6.x86_64.rpm
    sha:f04f2852334067ce831a68194fb6317f31fb54a6dd2640b6174f4245aff23e37
  • alt-php56-recode-5.6.40-142.el6.x86_64.rpm
    sha:33ca9e304c2040f4260a79f4c5786aa88605b3ce26f9205aa88fa890c5e2fb16
  • alt-php56-snmp-5.6.40-142.el6.x86_64.rpm
    sha:f4f4c7e8923d7438467098f2346e835e1234af025660fa3cf422136da915f636
  • alt-php56-soap-5.6.40-142.el6.x86_64.rpm
    sha:613fb05cdca15b97abc644a695b451168aead02926cb6c4e72f6417306f9884d
  • alt-php56-sybase-5.6.40-142.el6.x86_64.rpm
    sha:080e8964b46239cfc318a8cd256fbc21a21b3c88642234a6c9ba4cf9825a5245
  • alt-php56-tidy-5.6.40-142.el6.x86_64.rpm
    sha:6d90cddeae9048ef684e0ba1d9dacca667a984207a7ec4d44dc041ea6c048b31
  • alt-php56-xml-5.6.40-142.el6.x86_64.rpm
    sha:c7456a1ab79e9c651ec233b5d0cad19f09b313c3a5217b06221a80b455cc1d5f
  • alt-php56-xmlrpc-5.6.40-142.el6.x86_64.rpm
    sha:bfdc5e6f8035094adf561839f5c53b2c68119719ea8bba34688a84b0fb46a2e8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.