Release date:
2026-10-05 17:06:26 UTC
Description:
* SECURITY UPDATE: out-of-bounds read when following a redirect with an
empty Location header
- debian/patches/php-7.2-CVE-2026-93682.patch: an empty Location header
makes the http:// wrapper allocate a single byte for the NUL
terminator, but the relative-redirect branch in
ext/standard/http_fopen_wrapper.c still read location[1] to decide
whether to join the target against the request path, over-reading heap
memory and potentially appending a garbage-derived path to the redirect
target instead of the host root. The scheme test now uses
header_info.location_len instead of strlen() on the same buffer, and the
relative join is guarded by location_len > 1, so the second byte is
never read. The > 1 bound is upstream's end state after the GH-23521
follow-up: the first fix used > 0, which made a single-character
Location resolve against the request path rather than the host root, and
that intermediate behaviour is not shipped here.
- CVE-2026-93682
* SECURITY UPDATE: FastCGI listen.allowed_clients compared only 96 bits of
an IPv6 address
- debian/patches/php-7.2-CVE-2026-91768.patch: fcgi_is_allowed() in
main/fastcgi.c compared an incoming IPv6 peer address against each
configured allowed client with memcmp() over a hardcoded 12 bytes, so
only the first 96 bits were checked and the low 32 bits were ignored.
Any address sharing the first 96 bits with an allowed entry was
accepted, which for an IPv4-mapped entry such as ::ffff:a.b.c.d means
the whole embedded IPv4 address went unchecked. The comparison now uses
sizeof(client_sa.sa_inet6.sin6_addr), covering all 128 bits
(GHSA-62xp-839h-2637).
- CVE-2026-91768
Updated packages:
-
alt-php72_7.2.34-97_amd64.deb
sha:a4a9945c3b9c30c4b6ee9647bca5b162e102ce52
-
alt-php72-bcmath_7.2.34-97_amd64.deb
sha:4e853578ed6e18f3a7c0fe794da359ef9ec41851
-
alt-php72-cli_7.2.34-97_amd64.deb
sha:fa9fe0f37544e892d56083075ded08d61f066bde
-
alt-php72-common_7.2.34-97_amd64.deb
sha:bc4a5d78484b0d4e140987ae013ad64b3cc0c6f5
-
alt-php72-dba_7.2.34-97_amd64.deb
sha:860c4b5910220eb3ab30f0a3a75bb47177fd8012
-
alt-php72-dev_7.2.34-97_amd64.deb
sha:cb0cc058c023c3f2d6a93d996c82cdc52b0b8a2f
-
alt-php72-enchant_7.2.34-97_amd64.deb
sha:b73ff2bad6344eceda0f72285b7aad645e2baa97
-
alt-php72-firebird_7.2.34-97_amd64.deb
sha:000873a1dd6994eaf7e25303d3fe21cc7c6e5c8a
-
alt-php72-gd_7.2.34-97_amd64.deb
sha:ac39d2a6790d358de38d4eb0210ea3f829c23f78
-
alt-php72-imap_7.2.34-97_amd64.deb
sha:6cfaf5a74e76bf921d6824f032ccf66c53456315
-
alt-php72-intl_7.2.34-97_amd64.deb
sha:0b765f428e5fd0a6916b24c61b5139da25adaef6
-
alt-php72-ldap_7.2.34-97_amd64.deb
sha:fc39a54131dc66c83a58ad49141a77bdc940d6ef
-
alt-php72-mbstring_7.2.34-97_amd64.deb
sha:a17b24dd5be615658c207995be08965d8b49ec52
-
alt-php72-mysqlnd_7.2.34-97_amd64.deb
sha:903d2f48495ef0c26002b76b28297e2d76b23f5c
-
alt-php72-odbc_7.2.34-97_amd64.deb
sha:a3779d1d3fc6530ffbf132dd09ddfda02bd28dd0
-
alt-php72-opcache_7.2.34-97_amd64.deb
sha:e72a036d850b16743d985a1151cfdac42e1298ff
-
alt-php72-pdo_7.2.34-97_amd64.deb
sha:cd1a3f6c3b703455af55cd3cdc20aac4d4bfc690
-
alt-php72-pgsql_7.2.34-97_amd64.deb
sha:a4900caf5de48be1305d1929a13996e200a48eb0
-
alt-php72-php-fpm_7.2.34-97_amd64.deb
sha:739d66fdaa7bf9f05b9aa3beb163a832815064a1
-
alt-php72-process_7.2.34-97_amd64.deb
sha:f8608730495beedc54de26ccd89e205f12c427eb
-
alt-php72-pspell_7.2.34-97_amd64.deb
sha:798c48ed1131525b04a166ca4ca1518bb86b01fb
-
alt-php72-recode_7.2.34-97_amd64.deb
sha:e5e64ad091a6bd2cc4ea3c4ac2462677b57a9a69
-
alt-php72-snmp_7.2.34-97_amd64.deb
sha:e29eb29a857aa662884fee513737fb49b5ff81be
-
alt-php72-soap_7.2.34-97_amd64.deb
sha:6b3d9c676a88b4a095d7747db92eee42fb3d6f87
-
alt-php72-sodium_7.2.34-97_amd64.deb
sha:460e5e1b756af8ece4e104e2756dec1f2b5443f2
-
alt-php72-tidy_7.2.34-97_amd64.deb
sha:e3cb6cc2071ece08b2542cc864d4a6882bbb1cd9
-
alt-php72-xml_7.2.34-97_amd64.deb
sha:97e6f896ac8422a0ae3cc30e8e0fbdcd74fa2f92
-
alt-php72-xmlrpc_7.2.34-97_amd64.deb
sha:0b6818edb9001182601ce65fc4b7c47ba6462c39
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.