[CLSA-2026:1779453105] Fix of 5 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-22 12:31:51 UTC
Description:
* SECURITY UPDATE: soap extension use-after-free via apache:Map duplicate keys - debian/patches/php-7.2-CVE-2026-6722.patch: backport upstream commit aee3b3ac9b in ext/soap/php_encoding.c — add Z_TRY_ADDREF_P on soap_add_xml_ref insertion and change SOAP_GLOBAL(ref_map) destructor to ZVAL_PTR_DTOR. - CVE-2026-6722 * SECURITY UPDATE: soap extension NULL pointer dereference via apache:Map item missing element - debian/patches/php-7.2-CVE-2026-7262.patch: backport upstream commit 79551ab8b1 in ext/soap/php_encoding.c — fix typo'd null check in to_zval_map() (was checking xmlKey, should check xmlValue). - CVE-2026-7262 * SECURITY UPDATE: php-fpm status endpoint XSS via unescaped request_uri - debian/patches/php-7.2-CVE-2026-6735.patch: backport upstream commit 99a5ad7441 in sapi/fpm/fpm/fpm_status.c — escape proc.request_uri with php_escape_html_entities_ex() and fix the broken "ENT_HTML_IGNORE_ERRORS & ENT_COMPAT" flag (bitwise-AND of two flag constants evaluates to 0). Adapted to 7.x layout (struct access "proc.X", single encode flag, older 6-arg php_escape_html_entities_ex signature). - CVE-2026-6735 * SECURITY UPDATE: soap SoapServer use-after-free after header parsing failure when SOAP_PERSISTENCE_SESSION is set - debian/patches/php-7.2-CVE-2026-7261.patch: backport upstream commit db2a7f9348 in ext/soap/soap.c — guard both zval_ptr_dtor(soap_obj) call sites in PHP_METHOD(SoapServer, handle) with "if (service->soap_class.persistence != SOAP_PERSISTENCE_SESSION)". - CVE-2026-7261 * SECURITY UPDATE: metaphone() signed integer overflow on >INT_MAX input - debian/patches/php-7.2-CVE-2026-7568.patch: backport upstream commit 47def8ce1d in ext/standard/metaphone.c — retype w_idx and Lookahead's how_far/idx from int to size_t to avoid signed overflow while walking strings larger than 2 GB on 64-bit builds. - CVE-2026-7568
Updated packages:
  • alt-php72_7.2.34-74_amd64.deb
    sha:92bdbac4cf8d622e9f6b8ebcd116105357f4f9c5
  • alt-php72-bcmath_7.2.34-74_amd64.deb
    sha:0fabce8d5c470eeea92d685a8c4ab7d7db170c30
  • alt-php72-cli_7.2.34-74_amd64.deb
    sha:45107fe433aa5c293286a5e8a44206ed59022692
  • alt-php72-common_7.2.34-74_amd64.deb
    sha:c058e5a8d58d23656027f1e7522afda107a931c8
  • alt-php72-dba_7.2.34-74_amd64.deb
    sha:a1fd774b8f09636364153773aaee933b51b96436
  • alt-php72-dev_7.2.34-74_amd64.deb
    sha:21f73aaff2d4865923f63b637dd03cacff281f72
  • alt-php72-enchant_7.2.34-74_amd64.deb
    sha:12f5e4a873043a985fd40b7a44b5b22ccf6906d4
  • alt-php72-firebird_7.2.34-74_amd64.deb
    sha:6fcdee1fce3b26975730b9c33e0c7641976c2da2
  • alt-php72-fpm_7.2.34-74_amd64.deb
    sha:8625ab09a8357f4b2ddfc95831cbb35baaf5fbde
  • alt-php72-gd_7.2.34-74_amd64.deb
    sha:24cea31dc8cf0f3917bc1730e040818e672e2267
  • alt-php72-imap_7.2.34-74_amd64.deb
    sha:1f172f230ab4028769fa1c7504b8b59104f07641
  • alt-php72-intl_7.2.34-74_amd64.deb
    sha:4ade3d07a0ba1a34e4c21c3caa140d1b7e6df156
  • alt-php72-ldap_7.2.34-74_amd64.deb
    sha:ab92ff8a2b5e22053b520d56a36e2484b49abfa7
  • alt-php72-mbstring_7.2.34-74_amd64.deb
    sha:280388bfadbac7b40594f9cddffa2d462a0d403b
  • alt-php72-mysqlnd_7.2.34-74_amd64.deb
    sha:9034d7c8a48fcd83406e8dc4f973f129d6ce47cf
  • alt-php72-odbc_7.2.34-74_amd64.deb
    sha:3d357eb87d9e70e5d1c93d262382c882bc2b24ee
  • alt-php72-opcache_7.2.34-74_amd64.deb
    sha:9b04baa8184665f06c337e0c15ef953c7a3fcb61
  • alt-php72-pdo_7.2.34-74_amd64.deb
    sha:3912f84d4140fe0816df55a637cdb87fdbca7adc
  • alt-php72-pgsql_7.2.34-74_amd64.deb
    sha:91f03666fbee62e830855defa41cd968a6806b74
  • alt-php72-process_7.2.34-74_amd64.deb
    sha:1424b5ac866d5fa3e01d06748d4ef8fe2ed5f5b1
  • alt-php72-pspell_7.2.34-74_amd64.deb
    sha:db53288e5a5f0bb7eb69e4a8f902d39b84b6ff2e
  • alt-php72-recode_7.2.34-74_amd64.deb
    sha:ea57eb5b59f2493747025d2531f234799632d72c
  • alt-php72-snmp_7.2.34-74_amd64.deb
    sha:98a6ada15a2e014f75b149d2d09f0006086af0b0
  • alt-php72-soap_7.2.34-74_amd64.deb
    sha:0b35ab25d856172d882de50abf0a7169db78e905
  • alt-php72-tidy_7.2.34-74_amd64.deb
    sha:a405cbf546a37ae01d224ff7f071923260f36dd0
  • alt-php72-xml_7.2.34-74_amd64.deb
    sha:881cc6ee28a83180bedff99441979b1998b99c8b
  • alt-php72-xmlrpc_7.2.34-74_amd64.deb
    sha:0cc75293a24e6adb0d7f78045189f2f211a670e9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.