[CLSA-2026:1790947994] alt-php54: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-02 13:33:35 UTC
Description:
- CVE-2026-92842: heap buffer overflow in the convert.* stream filters when line-break-chars contains a NUL byte (GHSA-88hq-2827-7pg6). The base64-encode, quoted-printable-encode and quoted-printable-decode filter constructors duplicated lbchars with the strlen-based pestrdup(), which truncates at the first NUL, while lbchars_len kept the caller's original length; the filter then copied lbchars_len bytes out of the shorter allocation. Duplicate with pestrndup(lbchars, lbchars_len, persistent) instead - CVE-2025-14181: integer overflow in ext/soap get_http_body() leading to a heap buffer overflow (GHSA-cj93-vc83-wgqv). The chunked-transfer accumulator was a signed int guarded by "http_buf_size + buf_size + 1 < 0", which is signed-overflow UB that the compiler removes, so an attacker-controlled chunk size could wrap the erealloc() size and the body was then written past the allocation. Make the accumulator size_t, bound every growth step against SOAP_HTTP_MAX_BODY_LEN ((size_t) INT_MAX - 1, the local stand-in for upstream's ZSTR_MAX_LEN) before the add is performed, read the chunk size into an unsigned int as %x requires, apply the same bound to the Content-Length and connection-close paths, and allocate the redirect path with safe_emalloc() - CVE-2026-6103: phar tar entry injection (GHSA-j3wh-g957-2m85). phar_tar_number() wrapped silently on an oversized octal size field and ignored trailing garbage and GNU base-256 sizes, and only entries of type '\0' and '0' had their data blocks skipped, so a crafted archive could leave the stream positioned on attacker data that was then parsed as a tar header - making PharData show entries no conforming tar reader sees. Parse the size with a strict phar_tar_size() that rejects anything it cannot represent, skip the data of every type that carries data via phar_tar_type_has_data(), refuse unsupported GNU long link ('K') records, and bound a ././@LongLink name by the archive size - CVE-2026-91765: unbounded recursion in ext/soap XML parsing and decoding (GHSA-rgrp-mwpx-f6rm). cleanup_xml_node() and get_node_with_attribute_recursive_ex() recursed once per document level, and master_to_zval_int() recursed once per href hop, so a deeply nested or href-chained SOAP message exhausted the stack and crashed the process. Both traversals become iterative, documents deeper than SOAP_MAX_XML_DEPTH (2048) are rejected at parse time on libxml2 below 2.13, and the decoder carries a decode_depth counter in the soap globals that is capped at SOAP_MAX_DECODE_DEPTH and reset by encode_reset_ns()/encode_finish()
Updated packages:
  • alt-php54-5.4.45-198.el6.x86_64.rpm
    sha:bcd3f937e53a79c0bbbc42cc7aabc01f66107f4e913e038af7f288104ced4cc6
  • alt-php54-bcmath-5.4.45-198.el6.x86_64.rpm
    sha:d50652468e232dda16715cb0f998cda4c3b07bb17a07b77515822ee0b6cd3dfd
  • alt-php54-cli-5.4.45-198.el6.x86_64.rpm
    sha:31d8346828f059615eeb71f143f60a3f8e00c14c7c3decd82acd2cdff58c1f2b
  • alt-php54-common-5.4.45-198.el6.x86_64.rpm
    sha:f6702d0c21a32e1a3fcd77fb676097405b8cf0adc01b1cf45ac1ea26344d5f53
  • alt-php54-dba-5.4.45-198.el6.x86_64.rpm
    sha:85fe4254828df53a026cddb80d0d8ba7e5f45f5c522b5a6a63920fb7436c2807
  • alt-php54-dbx-5.4.45-198.el6.x86_64.rpm
    sha:cb361576b7530c26e4a789fded90b74d734a9de9b59dd91a986b5fd9589e1569
  • alt-php54-devel-5.4.45-198.el6.x86_64.rpm
    sha:d89defe1d51745136bd03b904440785e53d17f04749c9babaa7cf13b8d59685d
  • alt-php54-enchant-5.4.45-198.el6.x86_64.rpm
    sha:5bf4d1b2070dc2ac33936cefd36aa0dc3af11a70d6fff4a19383ca1f3a25236f
  • alt-php54-firebird-5.4.45-198.el6.x86_64.rpm
    sha:ac2a28ef4c24c3aa720d7c40d9ece2820b29f23ae36bf894063144cb5b5bfcdb
  • alt-php54-gd-5.4.45-198.el6.x86_64.rpm
    sha:69be9b7a9f1713422b68e309175297f7fb97f77a79390ebeade72c0f1417bb11
  • alt-php54-imap-5.4.45-198.el6.x86_64.rpm
    sha:498da684d15b9ea857479bfcb879d9b73d9d56c8f74a70c07ba96980a72304ff
  • alt-php54-intl-5.4.45-198.el6.x86_64.rpm
    sha:776c924e223d8d73a3df3531a6b937e9fb1961114c29ba189f27dcd1d3a5272d
  • alt-php54-ldap-5.4.45-198.el6.x86_64.rpm
    sha:0764246787f73d1b515f0c5dc102b6386db455e316adcc5ff7eb52ba22a9b3e2
  • alt-php54-mbstring-5.4.45-198.el6.x86_64.rpm
    sha:cb96657ace7c4742662595bc348f2a801a0229f72886dc0dc16fc2a1062aac2c
  • alt-php54-mcrypt-5.4.45-198.el6.x86_64.rpm
    sha:06a4a90ac3e97eb9bb279f61edf4221f5a3443a29c9ba5387c991c1a133f1371
  • alt-php54-mssql-5.4.45-198.el6.x86_64.rpm
    sha:bbe33bad3eae09135354b8b2ddb234242bfe90ebf1a8cc458aae4faf566af8ce
  • alt-php54-mysqlnd-5.4.45-198.el6.x86_64.rpm
    sha:e7174c6d42226e5358ed1c5a4ee6db2a96a02814201f6d4a11f708df61cff332
  • alt-php54-odbc-5.4.45-198.el6.x86_64.rpm
    sha:0709814381ee9dff781f170888a53c29d078c45ca703b8bfd5604a872914734a
  • alt-php54-pdo-5.4.45-198.el6.x86_64.rpm
    sha:520485f1488ad81a75e20fbc25276ed6949210d07ea23d892292ce15bb1dcae5
  • alt-php54-pgsql-5.4.45-198.el6.x86_64.rpm
    sha:3c8efd4646724d2562da2fb970d2f169f3ace85f0e9caa45e81302229889d08b
  • alt-php54-php-fpm-5.4.45-198.el6.x86_64.rpm
    sha:b26b9d1954b5cd9ce65e8887221029b9286a5d4212a9e1bf5e03e0bea2afbd87
  • alt-php54-process-5.4.45-198.el6.x86_64.rpm
    sha:8ec240cca4e84369bd883c55fcaa4ee24030a702c1c6edf3c34ecce37ff5c0a4
  • alt-php54-pspell-5.4.45-198.el6.x86_64.rpm
    sha:2b574d1767f04dba3921184c903974d3fc633858925346859b825248992c7126
  • alt-php54-recode-5.4.45-198.el6.x86_64.rpm
    sha:ea2fa0c818f3759a494b15cf3e5e652c9b4528b83464ebcf5b727bb5f5138898
  • alt-php54-snmp-5.4.45-198.el6.x86_64.rpm
    sha:0b26605241abe1ef2ab31eda23c59d5448bcff7da257e6d17035aa0511ee5f8e
  • alt-php54-soap-5.4.45-198.el6.x86_64.rpm
    sha:e94834e320c158f57bbf981d1f5456f01d6e772742e04525f9255983dff790a9
  • alt-php54-sybase-5.4.45-198.el6.x86_64.rpm
    sha:0cb535cf22e5fc0c2a6225dcfc0f43ced525edcd49a71a80e999f0a32075e1c4
  • alt-php54-tidy-5.4.45-198.el6.x86_64.rpm
    sha:134046408cd2e908ca6ec90b3811ee4eb4fc5d7781a615fe6b8ce33aad8cfd59
  • alt-php54-xml-5.4.45-198.el6.x86_64.rpm
    sha:778e47b72e61d6b13191fac15cc3dcad723484479c31cbdd8fc85ce8cfb8e40b
  • alt-php54-xmlrpc-5.4.45-198.el6.x86_64.rpm
    sha:f8479a7d7c651d67d0a2890956cb8f5dcc392f06aedd43bbd4f5ac2e86afb6a1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.