[CLSA-2026:1791003404] alt-php56: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-03 04:56:57 UTC
Description:
- CVE-2026-92842: heap buffer over-read in the convert.* stream filters when "line-break-chars" contains a NUL (ext/standard/filters.c, GHSA-88hq-2827-7pg6). php_conv_base64_encode_ctor(), php_conv_qprint_encode_ctor() and php_conv_qprint_decode_ctor() duplicated the option with the strlen-based pestrdup() while keeping lbchars_len, which the option reader sets from Z_STRLEN, so "\0X" allocated one byte and the filters then copied two out of it on every line break. Backport of upstream commit b4e3397ec8f4; the three calls become pestrndup(lbchars, lbchars_len, persistent). Byte-identical to upstream, only the hunk line numbers differ. Upstream's regression test is carried, rewritten for the 5.6 runner as ext/standard/tests/filters/ghsa-88hq-2827-7pg6.phpt. - CVE-2025-14181: integer overflow in the SOAP client's chunked response reader (ext/soap/php_http.c, GHSA-cj93-vc83-wgqv). get_http_body() accumulated the body length in a signed int and guarded growth with "http_buf_size + buf_size + 1 < 0", which is signed overflow - undefined behaviour a modern compiler folds away - so a hostile endpoint answering with two 0x7fffffff-sized chunks made the second erealloc() request wrap to a small allocation that php_stream_read() then overflowed. Backport of upstream commit b11bd1d9390b: the accumulator becomes unsigned, each growth step is bounded before it is performed and the overflow test is a subtraction from the bound rather than a wrapping addition. 5.6 has no zend_string in this path, so the bound is INT_MAX - the representable maximum of the int *out_size this function reports the body length through - in place of upstream's ZSTR_MAX_LEN, and erealloc() stands in for zend_string_safe_realloc(). - CVE-2026-6103: phar tar entry injection (ext/phar/tar.c, ext/phar/phar_internal.h, GHSA-j3wh-g957-2m85). phar_tar_number() parsed the 512-byte header's size field with an unchecked octal accumulator over a php_uint32 and ignored trailing garbage and GNU base-256 encoding, and phar_parse_tarfile() skipped the data blocks of only the '\0' and TAR_FILE entry types. Either way the stream was left inside an entry's payload, which was then read as the next tar header - so an archive shows one set of entries to phar and another to every conforming tar reader. Backport of upstream commit 0994e2e887cd: a new phar_tar_size() rejects sizes that cannot be parsed or represented, a new phar_tar_type_has_data() decides the skip for every type, GNU long link records are refused outright, and the bug-61065 guard now bounds the long file name by the archive size. Adapted to C89 (int-returning helpers), to phar_destroy_phar_data()'s TSRMLS_CC and to the pemalloc'd long-name buffer. Upstream's three regression tests are carried, rewritten for the 5.6 runner and 5.6's exception text as ext/phar/tests/tar/ghsa-j3wh-g957-2m85-{size,typeflag,longlink}.phpt. - CVE-2026-91765: unbounded recursion in ext/soap XML parsing and decoding (ext/soap/php_xml.c, php_encoding.c, php_soap.h, soap.c, GHSA-rgrp-mwpx-f6rm). cleanup_xml_node() and get_node_with_attribute_recursive_ex() recursed once per XML nesting level and master_to_zval_int() once per decoded node and per href hop, with no cap; both SOAP parsers set XML_PARSE_HUGE, which turns off libxml2's own depth limit, so a deep envelope or WSDL - or a long href chain in a shallow one - exhausts the C stack. Backport of upstream commit 3655b79c7bfa: both walkers become iterative, a 2048-level document cap is enforced after parsing where libxml2 is older than 2.13, and the decoder takes a depth counter bailing out at twice that. The counter is added to this version's soap globals struct and reset in php_soap_init_globals(), encode_reset_ns() and encode_finish(), since soap_error0(E_ERROR) bails out past the matching decrement. Upstream's three regression tests are carried as ext/soap/tests/GHSA-rgrp-mwpx-f6rm{,-href-chain,-href-cycle}.phpt, with the scalar type hints dropped for 5.6 and, in the href-chain test, the reference marker php-5.6-CVE-2026-6722.patch's added Z_ADDREF_PP() makes var_dump() print here.
Updated packages:
  • alt-php56-5.6.40-142.el9.x86_64.rpm
    sha:8e2218bca43eaac531ac01ae8aead278df20d4e474f3cbb761e1f700b313c001
  • alt-php56-bcmath-5.6.40-142.el9.x86_64.rpm
    sha:01574486efd87cd0b5fdae0e052a45bddf04b125763bae9109ab7c45577bf9be
  • alt-php56-cli-5.6.40-142.el9.x86_64.rpm
    sha:a8eae2e83282923a8ca2b8ddd22b0893f3ada186e7c28c6715f303519e4e6ee1
  • alt-php56-common-5.6.40-142.el9.x86_64.rpm
    sha:b1ae372229a4034abd8cdd5d0012b1326a9eceb9d1390e370d2a99a340f5e479
  • alt-php56-dba-5.6.40-142.el9.x86_64.rpm
    sha:723a00eb8035d60c05fc6516dffa0577bef3c8425181318e2775ae5590dcda26
  • alt-php56-dbx-5.6.40-142.el9.x86_64.rpm
    sha:e86fddd44f8dafa05e97831fc1c906f213c5d0cc809593739b451cac4aaf588f
  • alt-php56-devel-5.6.40-142.el9.x86_64.rpm
    sha:1dd1bde64953cc837c41fc8e02e2900bac6a5405cf10afa699e70ac652caaf9c
  • alt-php56-enchant-5.6.40-142.el9.x86_64.rpm
    sha:2a5b4266442fa175d31008debeb3ac163fc7a6bef9f9df23fb56af2f66223a3f
  • alt-php56-firebird-5.6.40-142.el9.x86_64.rpm
    sha:b911785f513435734d746fec94b698a21aaa0f2cb470030231760de5aa2979ab
  • alt-php56-gd-5.6.40-142.el9.x86_64.rpm
    sha:b65b8d433bfcd7ab5a366b5fa03d05abac1d2b47d2f13ee14df181460afde596
  • alt-php56-imap-5.6.40-142.el9.x86_64.rpm
    sha:dfefde8183c15962e5fb2d36f0b8141decf332e80c7630eea8151f9a337efaa0
  • alt-php56-intl-5.6.40-142.el9.x86_64.rpm
    sha:15b6e2ee1c365339ddf7fa97d427e37e7ad2c7eefc38bb18133773cf0d63b020
  • alt-php56-ldap-5.6.40-142.el9.x86_64.rpm
    sha:cab2b7792cc07740472409af6ff620a83c737c1f255ca777b8fa89514bd2391a
  • alt-php56-mbstring-5.6.40-142.el9.x86_64.rpm
    sha:2fee8f785f105a8eb775ad939ed69102e9cdc6d658793365c3edac08c3528327
  • alt-php56-mcrypt-5.6.40-142.el9.x86_64.rpm
    sha:9b370bd5b749f4393badbc4e01322787f9852d0666ca77086afb5092968006b4
  • alt-php56-mssql-5.6.40-142.el9.x86_64.rpm
    sha:2c265a03fa6b9c3f1ab1bc5ce54d8909f5ff3073e14be82c7ea6441fa5fa3e82
  • alt-php56-mysqlnd-5.6.40-142.el9.x86_64.rpm
    sha:3912ab5875ad74b84ef866482b651622b29aee79000be5d6f7d40c394cf44e18
  • alt-php56-odbc-5.6.40-142.el9.x86_64.rpm
    sha:c748a53ce0f525c5079fa4ce4e065ae9a66fba6a19828132efe743628ce99e03
  • alt-php56-opcache-5.6.40-142.el9.x86_64.rpm
    sha:1369fdaab48aeb63f6f8250be00251c3c6823bff22ad288d4e69252175662057
  • alt-php56-pdo-5.6.40-142.el9.x86_64.rpm
    sha:ce49d3f786d239b7f7c96512848c37605ecb11bdcc660bae58cbc95ba8f6819f
  • alt-php56-pgsql-5.6.40-142.el9.x86_64.rpm
    sha:14c73dfee801d06c6905e9bac136592e371dbcf8490ae8fba71964fbbd02628a
  • alt-php56-php-fpm-5.6.40-142.el9.x86_64.rpm
    sha:899f288ec22f2be8dad8cbcbefce83925afd53eb8acc1472bef9b7d2457c9737
  • alt-php56-process-5.6.40-142.el9.x86_64.rpm
    sha:b4fd7b5f0abc0f8b1d46e2619e0a6e11406ecbca41cbc42ccc334c4c76d8936f
  • alt-php56-pspell-5.6.40-142.el9.x86_64.rpm
    sha:f4ce73896a29859a9f0568db93271193a230c09ed7198f69e48535cb1dbb7d55
  • alt-php56-recode-5.6.40-142.el9.x86_64.rpm
    sha:4c8bde33665f28194d179251f4cea2c04859c4987034669f49dff7d533d4f410
  • alt-php56-snmp-5.6.40-142.el9.x86_64.rpm
    sha:e2ef3a5617906b834aac42b3d0eb7400b7d74a7558bc202760b653349ffb680e
  • alt-php56-soap-5.6.40-142.el9.x86_64.rpm
    sha:309e4686d064c78a58c0f28ddd9595b01b169db1d485977ab551fc739747b978
  • alt-php56-sybase-5.6.40-142.el9.x86_64.rpm
    sha:db328a1e83d46ddba108a596b67558b2834ab2e9badabd000d98861d969bc988
  • alt-php56-tidy-5.6.40-142.el9.x86_64.rpm
    sha:5144f56115b13c54341dd5ee5ab92d455287ae6c76c3f40583d85612d12ced4a
  • alt-php56-xml-5.6.40-142.el9.x86_64.rpm
    sha:f5e78486bf338b11649098e124e044776a27e2acc2ea27f3446d860ccb2e3665
  • alt-php56-xmlrpc-5.6.40-142.el9.x86_64.rpm
    sha:4d969dabba825489ac07b7f045d2f85a602aa7e8a42a6d9ff25d04a23756a1db
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.