[CLSA-2026:1790983577] alt-php56: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-02 23:26:35 UTC
Description:
- CVE-2026-92842: heap buffer over-read in the convert.* stream filters when "line-break-chars" contains a NUL (ext/standard/filters.c, GHSA-88hq-2827-7pg6). php_conv_base64_encode_ctor(), php_conv_qprint_encode_ctor() and php_conv_qprint_decode_ctor() duplicated the option with the strlen-based pestrdup() while keeping lbchars_len, which the option reader sets from Z_STRLEN, so "\0X" allocated one byte and the filters then copied two out of it on every line break. Backport of upstream commit b4e3397ec8f4; the three calls become pestrndup(lbchars, lbchars_len, persistent). Byte-identical to upstream, only the hunk line numbers differ. Upstream's regression test is carried, rewritten for the 5.6 runner as ext/standard/tests/filters/ghsa-88hq-2827-7pg6.phpt. - CVE-2025-14181: integer overflow in the SOAP client's chunked response reader (ext/soap/php_http.c, GHSA-cj93-vc83-wgqv). get_http_body() accumulated the body length in a signed int and guarded growth with "http_buf_size + buf_size + 1 < 0", which is signed overflow - undefined behaviour a modern compiler folds away - so a hostile endpoint answering with two 0x7fffffff-sized chunks made the second erealloc() request wrap to a small allocation that php_stream_read() then overflowed. Backport of upstream commit b11bd1d9390b: the accumulator becomes unsigned, each growth step is bounded before it is performed and the overflow test is a subtraction from the bound rather than a wrapping addition. 5.6 has no zend_string in this path, so the bound is INT_MAX - the representable maximum of the int *out_size this function reports the body length through - in place of upstream's ZSTR_MAX_LEN, and erealloc() stands in for zend_string_safe_realloc(). - CVE-2026-6103: phar tar entry injection (ext/phar/tar.c, ext/phar/phar_internal.h, GHSA-j3wh-g957-2m85). phar_tar_number() parsed the 512-byte header's size field with an unchecked octal accumulator over a php_uint32 and ignored trailing garbage and GNU base-256 encoding, and phar_parse_tarfile() skipped the data blocks of only the '\0' and TAR_FILE entry types. Either way the stream was left inside an entry's payload, which was then read as the next tar header - so an archive shows one set of entries to phar and another to every conforming tar reader. Backport of upstream commit 0994e2e887cd: a new phar_tar_size() rejects sizes that cannot be parsed or represented, a new phar_tar_type_has_data() decides the skip for every type, GNU long link records are refused outright, and the bug-61065 guard now bounds the long file name by the archive size. Adapted to C89 (int-returning helpers), to phar_destroy_phar_data()'s TSRMLS_CC and to the pemalloc'd long-name buffer. Upstream's three regression tests are carried, rewritten for the 5.6 runner and 5.6's exception text as ext/phar/tests/tar/ghsa-j3wh-g957-2m85-{size,typeflag,longlink}.phpt. - CVE-2026-91765: unbounded recursion in ext/soap XML parsing and decoding (ext/soap/php_xml.c, php_encoding.c, php_soap.h, soap.c, GHSA-rgrp-mwpx-f6rm). cleanup_xml_node() and get_node_with_attribute_recursive_ex() recursed once per XML nesting level and master_to_zval_int() once per decoded node and per href hop, with no cap; both SOAP parsers set XML_PARSE_HUGE, which turns off libxml2's own depth limit, so a deep envelope or WSDL - or a long href chain in a shallow one - exhausts the C stack. Backport of upstream commit 3655b79c7bfa: both walkers become iterative, a 2048-level document cap is enforced after parsing where libxml2 is older than 2.13, and the decoder takes a depth counter bailing out at twice that. The counter is added to this version's soap globals struct and reset in php_soap_init_globals(), encode_reset_ns() and encode_finish(), since soap_error0(E_ERROR) bails out past the matching decrement. Upstream's three regression tests are carried as ext/soap/tests/GHSA-rgrp-mwpx-f6rm{,-href-chain,-href-cycle}.phpt, with the scalar type hints dropped for 5.6 and, in the href-chain test, the reference marker php-5.6-CVE-2026-6722.patch's added Z_ADDREF_PP() makes var_dump() print here.
Updated packages:
  • alt-php56-5.6.40-142.el7.x86_64.rpm
    sha:3349f409560b4fa566e01c8dcd1414e3b108235d761e64352b7107e93f08405d
  • alt-php56-bcmath-5.6.40-142.el7.x86_64.rpm
    sha:eea53d36bc6573dc217ea503c97df2c77009c877a5ac72ca17b55155d7b654b4
  • alt-php56-cli-5.6.40-142.el7.x86_64.rpm
    sha:912f42a5916df20f8b5139ab5dd1664ef6f68aefc1e4c602ad4ff15920a85a36
  • alt-php56-common-5.6.40-142.el7.x86_64.rpm
    sha:2950b42e7f6604d1637228e17161a349dcf45aecb982dbe703706c6f22ece058
  • alt-php56-dba-5.6.40-142.el7.x86_64.rpm
    sha:d3760c0c03d383f8bc831eb2aef97df46d486a877949e45c9bc48591ba6c68ef
  • alt-php56-dbx-5.6.40-142.el7.x86_64.rpm
    sha:30b151ffbabe6c4778b495fb05096df15d9231559f1c492d289c8f2da5617e5f
  • alt-php56-devel-5.6.40-142.el7.x86_64.rpm
    sha:0b83a733ce5a34f2ab7674a617abc287831c1a9a5d1789d76d18940af0f8dff3
  • alt-php56-enchant-5.6.40-142.el7.x86_64.rpm
    sha:1c253c96f107e3645e2a5aec2e53c2e4bfcc637bf2fa8a7506febf57ec5c1108
  • alt-php56-firebird-5.6.40-142.el7.x86_64.rpm
    sha:701febfe734b3d5ad57b1b39ec1d6375784ba8ff228af2f1632af19043de8417
  • alt-php56-gd-5.6.40-142.el7.x86_64.rpm
    sha:9271a4eb319fd5388b2d346e0d8ab489aa274110685d88b8fddd61a57740f4e3
  • alt-php56-imap-5.6.40-142.el7.x86_64.rpm
    sha:1e630dfd8109a033825ccaf5ef9c495ff103d6c0f4a298295310c54d3040a146
  • alt-php56-intl-5.6.40-142.el7.x86_64.rpm
    sha:719c018332b89c3b3e7efa5fe90f48d9d37195bb5c65876ab92fbb1b4b728329
  • alt-php56-ldap-5.6.40-142.el7.x86_64.rpm
    sha:bda4132d8f0d1aa8f6ed2d120223f5eeb2404655ea74401ab16ed1271282b245
  • alt-php56-mbstring-5.6.40-142.el7.x86_64.rpm
    sha:4b52a01f178d7a6a1b186d8ed0d5359c6e13ff291348a4bd189e3bdf415acdb4
  • alt-php56-mcrypt-5.6.40-142.el7.x86_64.rpm
    sha:1c60274e72003264414a92b76ac0b749281341c5c2ca1bf54aac310ce29f5caa
  • alt-php56-mssql-5.6.40-142.el7.x86_64.rpm
    sha:c64705e2a3c25fa74c4a496aabee6e8d807f92950016717e2c80b33e7ed707e9
  • alt-php56-mysqlnd-5.6.40-142.el7.x86_64.rpm
    sha:ae11ce119225b1a2ab87494ccf6d3b7155a89a842e35647e6604182870570ffd
  • alt-php56-odbc-5.6.40-142.el7.x86_64.rpm
    sha:b00f67a431ba7eed107da8d9f616cd62ae351e1f2bd66d6105630225edc99c50
  • alt-php56-opcache-5.6.40-142.el7.x86_64.rpm
    sha:331aec164f27642e3ec8c98780777811f92cd38e31567f63c74f4d2385f67e44
  • alt-php56-pdo-5.6.40-142.el7.x86_64.rpm
    sha:1f6430b5907bf03f76eab4bef594dcbc60cf6dc0fcac5ee950aae9bcbe7efc20
  • alt-php56-pgsql-5.6.40-142.el7.x86_64.rpm
    sha:b7baff19762c6e4b71b692fa7c5885ecb2a7efd1b0ffdcae85aa595021d1ecb0
  • alt-php56-php-fpm-5.6.40-142.el7.x86_64.rpm
    sha:f60ee3ab545d8b322708654f5f305532b2e6b57ab83eb03676a2e350a403e49c
  • alt-php56-process-5.6.40-142.el7.x86_64.rpm
    sha:acbc0bac8438084b8bf6f6251705b45f472fab2f80e9292db8b628faf293d486
  • alt-php56-pspell-5.6.40-142.el7.x86_64.rpm
    sha:444098482529113f26c8cdf44724be2d317f3fe871beb34c67a366aa46cec02b
  • alt-php56-recode-5.6.40-142.el7.x86_64.rpm
    sha:82a4b3259b49c0757c7dd715be1d3865664c30296c5f6616511c3a982372f0f9
  • alt-php56-snmp-5.6.40-142.el7.x86_64.rpm
    sha:b6e025552a69bf6e471dd85e8ee176ab82d0986abdac8cf10d544053a5881181
  • alt-php56-soap-5.6.40-142.el7.x86_64.rpm
    sha:c5bf3e46bac3bfbfaae96b2d10866b0717c9d9686d141c179c3226f9bb36aa48
  • alt-php56-sybase-5.6.40-142.el7.x86_64.rpm
    sha:7b228cdadce2dbdc428602a0c4fa4bfee53f33bd43d7edba2a7b608902499d8d
  • alt-php56-tidy-5.6.40-142.el7.x86_64.rpm
    sha:4c3f3e26d85dc76560947f406c24125d92229dff8e29c6ac051f51d083fd2291
  • alt-php56-xml-5.6.40-142.el7.x86_64.rpm
    sha:8f1c1fc6f9a8e0a3d2c9b8a65e912f4b62acb04a64cd54e60dd109e2f5e44ad2
  • alt-php56-xmlrpc-5.6.40-142.el7.x86_64.rpm
    sha:cd9ce283089409403565475694d431cf81349e204db9e3325c4d2af6c73675a2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.