[CLSA-2026:1791007454] alt-php56: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-03 06:04:28 UTC
Description:
- CVE-2026-92842: heap buffer over-read in the convert.* stream filters when "line-break-chars" contains a NUL (ext/standard/filters.c, GHSA-88hq-2827-7pg6). php_conv_base64_encode_ctor(), php_conv_qprint_encode_ctor() and php_conv_qprint_decode_ctor() duplicated the option with the strlen-based pestrdup() while keeping lbchars_len, which the option reader sets from Z_STRLEN, so "\0X" allocated one byte and the filters then copied two out of it on every line break. Backport of upstream commit b4e3397ec8f4; the three calls become pestrndup(lbchars, lbchars_len, persistent). Byte-identical to upstream, only the hunk line numbers differ. Upstream's regression test is carried, rewritten for the 5.6 runner as ext/standard/tests/filters/ghsa-88hq-2827-7pg6.phpt. - CVE-2025-14181: integer overflow in the SOAP client's chunked response reader (ext/soap/php_http.c, GHSA-cj93-vc83-wgqv). get_http_body() accumulated the body length in a signed int and guarded growth with "http_buf_size + buf_size + 1 < 0", which is signed overflow - undefined behaviour a modern compiler folds away - so a hostile endpoint answering with two 0x7fffffff-sized chunks made the second erealloc() request wrap to a small allocation that php_stream_read() then overflowed. Backport of upstream commit b11bd1d9390b: the accumulator becomes unsigned, each growth step is bounded before it is performed and the overflow test is a subtraction from the bound rather than a wrapping addition. 5.6 has no zend_string in this path, so the bound is INT_MAX - the representable maximum of the int *out_size this function reports the body length through - in place of upstream's ZSTR_MAX_LEN, and erealloc() stands in for zend_string_safe_realloc(). - CVE-2026-6103: phar tar entry injection (ext/phar/tar.c, ext/phar/phar_internal.h, GHSA-j3wh-g957-2m85). phar_tar_number() parsed the 512-byte header's size field with an unchecked octal accumulator over a php_uint32 and ignored trailing garbage and GNU base-256 encoding, and phar_parse_tarfile() skipped the data blocks of only the '\0' and TAR_FILE entry types. Either way the stream was left inside an entry's payload, which was then read as the next tar header - so an archive shows one set of entries to phar and another to every conforming tar reader. Backport of upstream commit 0994e2e887cd: a new phar_tar_size() rejects sizes that cannot be parsed or represented, a new phar_tar_type_has_data() decides the skip for every type, GNU long link records are refused outright, and the bug-61065 guard now bounds the long file name by the archive size. Adapted to C89 (int-returning helpers), to phar_destroy_phar_data()'s TSRMLS_CC and to the pemalloc'd long-name buffer. Upstream's three regression tests are carried, rewritten for the 5.6 runner and 5.6's exception text as ext/phar/tests/tar/ghsa-j3wh-g957-2m85-{size,typeflag,longlink}.phpt. - CVE-2026-91765: unbounded recursion in ext/soap XML parsing and decoding (ext/soap/php_xml.c, php_encoding.c, php_soap.h, soap.c, GHSA-rgrp-mwpx-f6rm). cleanup_xml_node() and get_node_with_attribute_recursive_ex() recursed once per XML nesting level and master_to_zval_int() once per decoded node and per href hop, with no cap; both SOAP parsers set XML_PARSE_HUGE, which turns off libxml2's own depth limit, so a deep envelope or WSDL - or a long href chain in a shallow one - exhausts the C stack. Backport of upstream commit 3655b79c7bfa: both walkers become iterative, a 2048-level document cap is enforced after parsing where libxml2 is older than 2.13, and the decoder takes a depth counter bailing out at twice that. The counter is added to this version's soap globals struct and reset in php_soap_init_globals(), encode_reset_ns() and encode_finish(), since soap_error0(E_ERROR) bails out past the matching decrement. Upstream's three regression tests are carried as ext/soap/tests/GHSA-rgrp-mwpx-f6rm{,-href-chain,-href-cycle}.phpt, with the scalar type hints dropped for 5.6 and, in the href-chain test, the reference marker php-5.6-CVE-2026-6722.patch's added Z_ADDREF_PP() makes var_dump() print here.
Updated packages:
  • alt-php56-5.6.40-142.el8.x86_64.rpm
    sha:214d64eaf55202cdc4c7d395436060e69db7aab0c6908070e7228522e4f265e8
  • alt-php56-bcmath-5.6.40-142.el8.x86_64.rpm
    sha:33a03acef913932380f8200ff48a0513710bbcbbc7c2477e5d132ccf6c686444
  • alt-php56-cli-5.6.40-142.el8.x86_64.rpm
    sha:d2c44c40344bc7f2fa96f6f4c5ec5ec56684bd36c9ea47b7fe85e298f2e9e14b
  • alt-php56-common-5.6.40-142.el8.x86_64.rpm
    sha:8812951404cbfb94abccbb0c1b073b5cf678fae081ac90b920734c0dc9ed7243
  • alt-php56-dba-5.6.40-142.el8.x86_64.rpm
    sha:f8e786b22ef8668378d7291dc79785364f7903c5c027bb0784725a0a39711f16
  • alt-php56-dbx-5.6.40-142.el8.x86_64.rpm
    sha:f409fad82aaac7118b2357b52f449da5c5a07dc2798e1c0c7e9b639a1af07171
  • alt-php56-devel-5.6.40-142.el8.x86_64.rpm
    sha:af771d90aa19787fb58df2f642c468a88fc0239d03ed9deb43b0e5d26d2dce7d
  • alt-php56-enchant-5.6.40-142.el8.x86_64.rpm
    sha:e18a42c950d75774c58dc0d1b222eb76bf713b3aa2ec99abdbc4e856667f0695
  • alt-php56-firebird-5.6.40-142.el8.x86_64.rpm
    sha:9e06df1e112afb2b42ff67bf12c1b814635a01ca1aa6834dff2d536ad4694203
  • alt-php56-gd-5.6.40-142.el8.x86_64.rpm
    sha:a7720d3c878fb093ea23b3e1369b5b1eb3ccb7ca6365f0b7ddda2fa1b14772fb
  • alt-php56-imap-5.6.40-142.el8.x86_64.rpm
    sha:265530452c77954de47cb46bf504a66c4f290068568e8cc2c900a830b276c0d4
  • alt-php56-intl-5.6.40-142.el8.x86_64.rpm
    sha:174fee95e36470c10f6dcf66cfd20b6066baf192cb96697ed6e410b4402b23c6
  • alt-php56-ldap-5.6.40-142.el8.x86_64.rpm
    sha:8a6bce04de45d53a3d36cec1be735c33912040112b400dd132bf51174ee91a43
  • alt-php56-mbstring-5.6.40-142.el8.x86_64.rpm
    sha:f8d9878b292b821ff900f31322727f4dff4340df2825189c9c8525bb6515ade6
  • alt-php56-mcrypt-5.6.40-142.el8.x86_64.rpm
    sha:c4e80a49af3a232103e474591d1e475d9d72cab7e2a1c2681dd639f9d199933b
  • alt-php56-mssql-5.6.40-142.el8.x86_64.rpm
    sha:ce4d368ed67ece540b0ecd97e105b2a67e1f7b38abc0721b88a4493c50ef877b
  • alt-php56-mysqlnd-5.6.40-142.el8.x86_64.rpm
    sha:eacda8a6d8203c548830be2c53c209c0d74bf2938bca0063ce3a5c6259074306
  • alt-php56-odbc-5.6.40-142.el8.x86_64.rpm
    sha:e061999a0afac98fd896ab1a377632aad10e8b260216b1f200d4902267d9a66b
  • alt-php56-opcache-5.6.40-142.el8.x86_64.rpm
    sha:3810c245f053f05f2680af98bdd665a4d735eb2fa45796e374a84dc508c2e6b7
  • alt-php56-pdo-5.6.40-142.el8.x86_64.rpm
    sha:de50ae38bc76acbb1bda2792c87317d0e7d16030fe64d4371c1319042bb50ece
  • alt-php56-pgsql-5.6.40-142.el8.x86_64.rpm
    sha:44de8ca13987db3e25f2be5c634953ec49edfa876675d0a365fd703a44e957c6
  • alt-php56-php-fpm-5.6.40-142.el8.x86_64.rpm
    sha:538dceddd86d48a4007432e94b7b0c78ea1ebbc165b0f8353909b6086713f3c7
  • alt-php56-process-5.6.40-142.el8.x86_64.rpm
    sha:c2256943d46caf9fc62b1cc555a29962e99c71ae7078e0cae8b2dd928bf4a212
  • alt-php56-pspell-5.6.40-142.el8.x86_64.rpm
    sha:0e0163ff2bfde38165d4ad09db0ecd73341704c97f7ba7bf5ea5d6297b69fff7
  • alt-php56-recode-5.6.40-142.el8.x86_64.rpm
    sha:f9ceb05aee6f1b1fcd5536aca68fd93a3f06555ee50ec4972fbaa12590f35db4
  • alt-php56-snmp-5.6.40-142.el8.x86_64.rpm
    sha:a85bebc1ad0603d358a76f92f0a243ab57c553412482f6bb0236988d23e6ae33
  • alt-php56-soap-5.6.40-142.el8.x86_64.rpm
    sha:8051c8a93ad3baa099338d2da5f2413e64de0eeacfccb04b39026293979831e7
  • alt-php56-sybase-5.6.40-142.el8.x86_64.rpm
    sha:3887491fe714f53124e56dad0652c38b159dbc6d9cb6637c9e9661a9b6ede203
  • alt-php56-tidy-5.6.40-142.el8.x86_64.rpm
    sha:7c4a76fc6e81864a2c4281169ac2ce8f1008e715754d7c8d1816992b5b66f697
  • alt-php56-xml-5.6.40-142.el8.x86_64.rpm
    sha:e68755145270f6f2abbbc2bb27e77a6a4f6d699618870cd468b260fe3c8529b9
  • alt-php56-xmlrpc-5.6.40-142.el8.x86_64.rpm
    sha:136f716b4b82f7b194e319fbda5831450dd9df510800d9a66d603727b42ef9c2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.