[CLSA-2026:1790984287] alt-php54: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-02 23:38:19 UTC
Description:
- CVE-2026-92842: heap buffer overflow in the convert.* stream filters when line-break-chars contains a NUL byte (GHSA-88hq-2827-7pg6). The base64-encode, quoted-printable-encode and quoted-printable-decode filter constructors duplicated lbchars with the strlen-based pestrdup(), which truncates at the first NUL, while lbchars_len kept the caller's original length; the filter then copied lbchars_len bytes out of the shorter allocation. Duplicate with pestrndup(lbchars, lbchars_len, persistent) instead - CVE-2025-14181: integer overflow in ext/soap get_http_body() leading to a heap buffer overflow (GHSA-cj93-vc83-wgqv). The chunked-transfer accumulator was a signed int guarded by "http_buf_size + buf_size + 1 < 0", which is signed-overflow UB that the compiler removes, so an attacker-controlled chunk size could wrap the erealloc() size and the body was then written past the allocation. Make the accumulator size_t, bound every growth step against SOAP_HTTP_MAX_BODY_LEN ((size_t) INT_MAX - 1, the local stand-in for upstream's ZSTR_MAX_LEN) before the add is performed, read the chunk size into an unsigned int as %x requires, apply the same bound to the Content-Length and connection-close paths, and allocate the redirect path with safe_emalloc() - CVE-2026-6103: phar tar entry injection (GHSA-j3wh-g957-2m85). phar_tar_number() wrapped silently on an oversized octal size field and ignored trailing garbage and GNU base-256 sizes, and only entries of type '\0' and '0' had their data blocks skipped, so a crafted archive could leave the stream positioned on attacker data that was then parsed as a tar header - making PharData show entries no conforming tar reader sees. Parse the size with a strict phar_tar_size() that rejects anything it cannot represent, skip the data of every type that carries data via phar_tar_type_has_data(), refuse unsupported GNU long link ('K') records, and bound a ././@LongLink name by the archive size - CVE-2026-91765: unbounded recursion in ext/soap XML parsing and decoding (GHSA-rgrp-mwpx-f6rm). cleanup_xml_node() and get_node_with_attribute_recursive_ex() recursed once per document level, and master_to_zval_int() recursed once per href hop, so a deeply nested or href-chained SOAP message exhausted the stack and crashed the process. Both traversals become iterative, documents deeper than SOAP_MAX_XML_DEPTH (2048) are rejected at parse time on libxml2 below 2.13, and the decoder carries a decode_depth counter in the soap globals that is capped at SOAP_MAX_DECODE_DEPTH and reset by encode_reset_ns()/encode_finish()
Updated packages:
  • alt-php54-5.4.45-198.el9.x86_64.rpm
    sha:0063a03393d378984894c30c7131adb546318976ea1fbb7db3a844defd414ac0
  • alt-php54-bcmath-5.4.45-198.el9.x86_64.rpm
    sha:301be80bf50b4e2eaa5e10231227f6e2ac56455df0ffa80f64e1e8339ce280cc
  • alt-php54-cli-5.4.45-198.el9.x86_64.rpm
    sha:388b841136c1634b238faec0a085246209b3524ba0adb5857986e50cefb3e7af
  • alt-php54-common-5.4.45-198.el9.x86_64.rpm
    sha:2e188290c4b633c74891590399e717a1899b732129aea93f103e847c30404e74
  • alt-php54-dba-5.4.45-198.el9.x86_64.rpm
    sha:1b20d58bfc4f3803e471bccfad2fc859de8524afa44c5f5989f2e8975b9602b1
  • alt-php54-dbx-5.4.45-198.el9.x86_64.rpm
    sha:3a2c887b75f51fa563d50766c3ef605139f1b9c0248e1305865255efda6b5e62
  • alt-php54-devel-5.4.45-198.el9.x86_64.rpm
    sha:521de30942ed55303a266ced6e1081bdc5ca4323e26798c310e4c9e786eedc6f
  • alt-php54-enchant-5.4.45-198.el9.x86_64.rpm
    sha:6071951b3dc37e4c0da9933d7a5c37c6fceee967b62d267f3ce798baefcdec51
  • alt-php54-firebird-5.4.45-198.el9.x86_64.rpm
    sha:a9720b3e485cd70b13f9d86820090b4e5756ffe151bf33a3a3c426d4f26c71e4
  • alt-php54-gd-5.4.45-198.el9.x86_64.rpm
    sha:c626daf08fb980e7a6ca2e3fac4ee4610ec46f9ccc305313c9a199d67cadf934
  • alt-php54-imap-5.4.45-198.el9.x86_64.rpm
    sha:f44e36bafceb27e87fc2ccadf527336a51bc34db54ded441c0f8594aa5d3c15c
  • alt-php54-intl-5.4.45-198.el9.x86_64.rpm
    sha:368249e3c0340c945ca0eca0d22069eb2928d1f791594265a5d7f35953aacdb7
  • alt-php54-ldap-5.4.45-198.el9.x86_64.rpm
    sha:f37f55d4340be8b30e235439f67e92148596d54c1d8a331ffeb9001ee21657b2
  • alt-php54-mbstring-5.4.45-198.el9.x86_64.rpm
    sha:69a0cf02a10ab6f34353c7eca8a55042506b4657b7bcf62b9e85330ef81fe67e
  • alt-php54-mcrypt-5.4.45-198.el9.x86_64.rpm
    sha:079aa72b8707e7934e78844cdbed96ce30a38bbadeb629ca549323ca6a737ca9
  • alt-php54-mssql-5.4.45-198.el9.x86_64.rpm
    sha:e6dde01ba9e7b20360c22dc0b76e988d2b60b74cc44d5f94d3e34fdcddf5e07a
  • alt-php54-mysqlnd-5.4.45-198.el9.x86_64.rpm
    sha:ded5d7e6132ad1dee8cdd7f1c5bbeaadf248a401c68785bb46eb21b2ccdb5c96
  • alt-php54-odbc-5.4.45-198.el9.x86_64.rpm
    sha:755219167ca336a74f91e08d3c996693346c372b75c8d78a7112a79a27319ee2
  • alt-php54-pdo-5.4.45-198.el9.x86_64.rpm
    sha:863b37b96e52d4a606e6a43838bbd5ef097c0abef7725fd6fb178aaf26b5522b
  • alt-php54-pgsql-5.4.45-198.el9.x86_64.rpm
    sha:a725ee14eb0007150a829bea1c552a5f7104d6d553cf1cdc8d86f4204f885028
  • alt-php54-php-fpm-5.4.45-198.el9.x86_64.rpm
    sha:81bd80833b652bb408f6ed645fa898346c0c44ace29155dd26c3e55f517b5b7b
  • alt-php54-process-5.4.45-198.el9.x86_64.rpm
    sha:ed2b06a2bce7bf2f43f9c3bb81578c2c8852ac56c990ae0cbb81cfedede26735
  • alt-php54-pspell-5.4.45-198.el9.x86_64.rpm
    sha:11771170b5110ca1a0e423ab688e24c79838de1e0046b110d92d7b1f208d3625
  • alt-php54-recode-5.4.45-198.el9.x86_64.rpm
    sha:f0f3f72b1465d90d91701f61af508c3d2cca155e4780f01252920744fa5acd65
  • alt-php54-snmp-5.4.45-198.el9.x86_64.rpm
    sha:5ec12ebd16713bea7f26cf7991b64a79288776cd95a2ff7cc0fd03c8b1c219f7
  • alt-php54-soap-5.4.45-198.el9.x86_64.rpm
    sha:38021e56b19e712e4ba5ec57834294ae74c191fe9052ff227f6a666cd5c69432
  • alt-php54-sybase-5.4.45-198.el9.x86_64.rpm
    sha:963657b5628b668b3bab4bcc29d2d0bf6577efe414eb3593e5b2707c5228996b
  • alt-php54-tidy-5.4.45-198.el9.x86_64.rpm
    sha:8c743c58fb3f68e4efd779210118fccc106d2618203097e529c6087a7db7a89e
  • alt-php54-xml-5.4.45-198.el9.x86_64.rpm
    sha:d047d2a0facc0b7d4b85861255db4f7f6231a7205f6b1f833c62ea47903b3d87
  • alt-php54-xmlrpc-5.4.45-198.el9.x86_64.rpm
    sha:db59c88293983a5c94f5e243adbf260c1a8f2cb0fa38b1a5e210ffbf2b0e815e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.