[CLSA-2026:1791013716] alt-php54: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-03 07:48:50 UTC
Description:
- CVE-2026-92842: heap buffer overflow in the convert.* stream filters when line-break-chars contains a NUL byte (GHSA-88hq-2827-7pg6). The base64-encode, quoted-printable-encode and quoted-printable-decode filter constructors duplicated lbchars with the strlen-based pestrdup(), which truncates at the first NUL, while lbchars_len kept the caller's original length; the filter then copied lbchars_len bytes out of the shorter allocation. Duplicate with pestrndup(lbchars, lbchars_len, persistent) instead - CVE-2025-14181: integer overflow in ext/soap get_http_body() leading to a heap buffer overflow (GHSA-cj93-vc83-wgqv). The chunked-transfer accumulator was a signed int guarded by "http_buf_size + buf_size + 1 < 0", which is signed-overflow UB that the compiler removes, so an attacker-controlled chunk size could wrap the erealloc() size and the body was then written past the allocation. Make the accumulator size_t, bound every growth step against SOAP_HTTP_MAX_BODY_LEN ((size_t) INT_MAX - 1, the local stand-in for upstream's ZSTR_MAX_LEN) before the add is performed, read the chunk size into an unsigned int as %x requires, apply the same bound to the Content-Length and connection-close paths, and allocate the redirect path with safe_emalloc() - CVE-2026-6103: phar tar entry injection (GHSA-j3wh-g957-2m85). phar_tar_number() wrapped silently on an oversized octal size field and ignored trailing garbage and GNU base-256 sizes, and only entries of type '\0' and '0' had their data blocks skipped, so a crafted archive could leave the stream positioned on attacker data that was then parsed as a tar header - making PharData show entries no conforming tar reader sees. Parse the size with a strict phar_tar_size() that rejects anything it cannot represent, skip the data of every type that carries data via phar_tar_type_has_data(), refuse unsupported GNU long link ('K') records, and bound a ././@LongLink name by the archive size - CVE-2026-91765: unbounded recursion in ext/soap XML parsing and decoding (GHSA-rgrp-mwpx-f6rm). cleanup_xml_node() and get_node_with_attribute_recursive_ex() recursed once per document level, and master_to_zval_int() recursed once per href hop, so a deeply nested or href-chained SOAP message exhausted the stack and crashed the process. Both traversals become iterative, documents deeper than SOAP_MAX_XML_DEPTH (2048) are rejected at parse time on libxml2 below 2.13, and the decoder carries a decode_depth counter in the soap globals that is capped at SOAP_MAX_DECODE_DEPTH and reset by encode_reset_ns()/encode_finish()
Updated packages:
  • alt-php54-5.4.45-198.el7.x86_64.rpm
    sha:a406685ceb7092b896b36c067058a0284d043998d20149be5eaf7476a37217ce
  • alt-php54-bcmath-5.4.45-198.el7.x86_64.rpm
    sha:12dc55ace433b78853a3398bef9db4acbe5bc50be3812eea4c8782fdc2bea9f7
  • alt-php54-cli-5.4.45-198.el7.x86_64.rpm
    sha:1862985af83e0eb052b1c29ce91bec78f66efb698f109bf6cb5f2c6a789a8a64
  • alt-php54-common-5.4.45-198.el7.x86_64.rpm
    sha:40bff7022b063283182511aea5c9ec9d8459d12b3c7ae560fd506f2d78b9957f
  • alt-php54-dba-5.4.45-198.el7.x86_64.rpm
    sha:40c9f94014af15af4e8fd94cbec9492d528a707db62f3652d6c5cd542ffba4b9
  • alt-php54-dbx-5.4.45-198.el7.x86_64.rpm
    sha:fd724d6d1a4d49163a763a91a5488b58551e004ce06b15e43e297bc9dfdd867a
  • alt-php54-devel-5.4.45-198.el7.x86_64.rpm
    sha:1b583c3861097343c4a574976e905f0ee28f13e2b89e3c58777a6100039b03bc
  • alt-php54-enchant-5.4.45-198.el7.x86_64.rpm
    sha:896be8ade4bd03102f21c39958316142ccbb80d8e3dddcceef27aaede8f2285d
  • alt-php54-firebird-5.4.45-198.el7.x86_64.rpm
    sha:e6e75d17ce3e3a4fc50ea4e9f98f8383b81f84d9456772684483d46486f66819
  • alt-php54-gd-5.4.45-198.el7.x86_64.rpm
    sha:2b8732e11560b33a5305206819e035bb681204c4d61fdface03514c7aca03565
  • alt-php54-imap-5.4.45-198.el7.x86_64.rpm
    sha:cb328980b1e33b3facdf99b1747e7b2b0fa05948b74786f1f8a1517d657c602c
  • alt-php54-intl-5.4.45-198.el7.x86_64.rpm
    sha:18aa8f8dced70a5386f8ed31e0d87571587b87fdfd4dee5a63ebb2701eb5732a
  • alt-php54-ldap-5.4.45-198.el7.x86_64.rpm
    sha:3829ece793ba7add6ac7b67370ea31b9170047f331683647c425cbde70334b44
  • alt-php54-mbstring-5.4.45-198.el7.x86_64.rpm
    sha:6b0b76dc882f0084e7983326f5bd3b5cb2c566f678a012686ebb6e199b394a15
  • alt-php54-mcrypt-5.4.45-198.el7.x86_64.rpm
    sha:579c46d22e17e324a7c396ade3fcfe1997ae8be3b6a64e39d9798c3ef3e3278a
  • alt-php54-mssql-5.4.45-198.el7.x86_64.rpm
    sha:1452b05bf04daacb15ea32d38f841ab955f838c215c95596e74da022731a7987
  • alt-php54-mysqlnd-5.4.45-198.el7.x86_64.rpm
    sha:f98fbb580025e85490f6d8aa7825c53456a162df48813bf01f28871dc8d6e49f
  • alt-php54-odbc-5.4.45-198.el7.x86_64.rpm
    sha:afaed92d4f98585003211e9521271d4703c0f22e83ee20bf67c8d2ec5b755ab2
  • alt-php54-pdo-5.4.45-198.el7.x86_64.rpm
    sha:c809a9cebd236ebb953ef21d2962d368729b3fe319caeaf3ed41d7644f622d24
  • alt-php54-pgsql-5.4.45-198.el7.x86_64.rpm
    sha:48a098b10694993a65fdb2938c041b1303710315966a56c56444dd1006618f70
  • alt-php54-php-fpm-5.4.45-198.el7.x86_64.rpm
    sha:31347553c9c7455192f29d2264b1d3e092dc4bac72c11abfb65150aa5ee8dc2f
  • alt-php54-process-5.4.45-198.el7.x86_64.rpm
    sha:1ce7e1e7441c3ad4e4c733321bf8abbafda968f05d158122fdc33b10266a5719
  • alt-php54-pspell-5.4.45-198.el7.x86_64.rpm
    sha:edcc669e0812d663c1a180e936e953927e71eb5afa1858b97ec9295c4623363d
  • alt-php54-recode-5.4.45-198.el7.x86_64.rpm
    sha:f87b344c5f3516577c7119c0aff68defddb400b1f52922b9bbb6dbfbf127c051
  • alt-php54-snmp-5.4.45-198.el7.x86_64.rpm
    sha:695c89e92d7162ba3072bea4fdb42bc90dcfe751b75e6dbcdbf19b5e296233a8
  • alt-php54-soap-5.4.45-198.el7.x86_64.rpm
    sha:724141e8b912167862175be99eaaa9af96703c763fb65995387a16f5287e7669
  • alt-php54-sybase-5.4.45-198.el7.x86_64.rpm
    sha:3b35e601fe5a6b39fdcecf1db00567469f90bda1fe7d03450efd87e9bb1254d4
  • alt-php54-tidy-5.4.45-198.el7.x86_64.rpm
    sha:4f96e95b64759c842811dbfbdf8c15eafb56cfd30878b385e97af9c0c0beb791
  • alt-php54-xml-5.4.45-198.el7.x86_64.rpm
    sha:d023b095a22c9d6e1819112a4a7a1a8c5c8faae5fee18280c74367a5352c7b58
  • alt-php54-xmlrpc-5.4.45-198.el7.x86_64.rpm
    sha:e06f92b1a22c7ee0f4be4921117a1af680710575ae58a2cdd6e45e3e76265e31
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.