Release date:
2026-10-05 14:42:57 UTC
Description:
* SECURITY UPDATE: out-of-bounds read on an empty Location header when the
http:// stream wrapper follows a redirect
- debian/patches/php-5.6-CVE-2026-93682.patch: backport the net effect of
upstream commits 8196275133ed (GH-23467) and de3436c76e46 (GH-23521) in
ext/standard/http_fopen_wrapper.c. An empty Location header allocates a
single byte for the NUL terminator, so the relative-redirect branch's
read of location[1] over-read heap memory and could append a
garbage-derived path to the redirect target instead of the host root.
The length test now uses header_info.location_len, which this branch
already carries from the CVE-2025-1861 backport, instead of strlen(),
and the relative join is skipped when the header is shorter than two
bytes so the second byte is never read.
- Note: the guard lands directly on its final "location_len > 1" form.
The intermediate "> 0" form from 8196275133ed is deliberately not
shipped: it regressed single-character relative Location headers into
resolving against the request path rather than the host root, which is
what de3436c76e46 then fixed. Both changed lines are byte-identical to
upstream; only the hunk offsets and the surrounding context differ
(5.6 keeps resource->path as a plain char *). Upstream's two regression
tests are carried as
ext/standard/tests/http/http_empty_location_redirect.phpt and
http_single_char_location_redirect.phpt, with the harness include
switched to ext/openssl/tests/ServerClientTestCase2.inc, the copy that
has phpt_notify_server_start() and the {{ ADDR }} placeholder on this
branch.
- CVE-2026-93682
* SECURITY UPDATE: php-fpm listen.allowed_clients matched only the first 96
bits of an IPv6 address
- debian/patches/php-5.6-CVE-2026-91768.patch: backport upstream commit
dcdfcf86fcf7 (GHSA-62xp-839h-2637) in sapi/fpm/fpm/fastcgi.c.
fcgi_is_allowed() compared an incoming IPv6 peer against each entry of
listen.allowed_clients with a hardcoded length of 12 bytes, so any
client sharing only the first 96 bits of an allowed address was let
through - every host in the same /96 as a permitted one, including the
whole ::ffff:0:0/96 IPv4-mapped range for a single mapped entry. The
comparison now covers sizeof(sin6_addr), all 128 bits.
- Note: the changed line is byte-identical to upstream; only its location
differs, as the FastCGI protocol code lives in sapi/fpm/fpm/fastcgi.c on
5.6 rather than main/fastcgi.c. Upstream's two regression tests are not
carried: they need the modern FPM test harness (sapi/fpm/tests/tester.inc
with the FPM\Tester class, its {{ADDR:IPv6:ANY[...]}} placeholders and
skipIfIPv6IsNotSupported()), which does not exist on this branch.
- CVE-2026-91768
Updated packages:
-
alt-php56_5.6.40-147_amd64.deb
sha:abfe569c6cfb1e8e7cad7bf1cb6a0c378650768d
-
alt-php56-bcmath_5.6.40-147_amd64.deb
sha:4f2579c9cb9a87a8afbdfb71a659ddf78b861aed
-
alt-php56-cli_5.6.40-147_amd64.deb
sha:a439bd6a801d461b89485fe4f0e33446a376d18c
-
alt-php56-common_5.6.40-147_amd64.deb
sha:c3fdcd643ebc3ccd3bb08f8f84bce6bd640f0133
-
alt-php56-dba_5.6.40-147_amd64.deb
sha:4adce600b0af5b63358a7af91aef2091926e1d2f
-
alt-php56-dbx_5.6.40-147_amd64.deb
sha:d48fd5db370dc0518b17ef42281ee80b7b075cf4
-
alt-php56-dev_5.6.40-147_amd64.deb
sha:8d81ea872f2e8fef033cd43b758d977b149f8104
-
alt-php56-enchant_5.6.40-147_amd64.deb
sha:0c3f7933ed47cb472a250ab61aa809c957a7fc08
-
alt-php56-firebird_5.6.40-147_amd64.deb
sha:88cfa958cf76780dce04d54c156e3e308eb5354b
-
alt-php56-gd_5.6.40-147_amd64.deb
sha:8ac39e4fcf8f273f027fa96ac95c9093c24d6386
-
alt-php56-imap_5.6.40-147_amd64.deb
sha:b74a94cd4484617e2eed1ef003d655aaed0ea512
-
alt-php56-intl_5.6.40-147_amd64.deb
sha:d123dcb8aa2b152eaff1c0caf4f042dc39685b07
-
alt-php56-ldap_5.6.40-147_amd64.deb
sha:a990574b6b3d5a58e5b7180bddbaa98be3f956a5
-
alt-php56-mbstring_5.6.40-147_amd64.deb
sha:fb361e3aa99415a788e7fc98fe1534aa93bc15bc
-
alt-php56-mcrypt_5.6.40-147_amd64.deb
sha:8811d1c28f6e4db65fb914feb70bebabb480b2bc
-
alt-php56-mysqlnd_5.6.40-147_amd64.deb
sha:ebf12d462ac58f4b04557be84d2565048664eb7c
-
alt-php56-odbc_5.6.40-147_amd64.deb
sha:cdc2fc0349297636fa8eb7a7935ab40f0108c0d8
-
alt-php56-opcache_5.6.40-147_amd64.deb
sha:77af6287bd1116456359aeb8a87d7df559a6bda2
-
alt-php56-pdo_5.6.40-147_amd64.deb
sha:09188edd5ec1087af10048b9b2ec11fe62119c48
-
alt-php56-pgsql_5.6.40-147_amd64.deb
sha:a7479f30bce888e3a5defbbb6002ee25b1533681
-
alt-php56-php-fpm_5.6.40-147_amd64.deb
sha:bf27619b51232495cf098ad2a5d07fb9af68099b
-
alt-php56-process_5.6.40-147_amd64.deb
sha:e6256c0fab3f5a200fc1cf72af3d97522c0e1c42
-
alt-php56-pspell_5.6.40-147_amd64.deb
sha:6aa8daab8b44c9f95818e4ba3b4d4d5c2e7008da
-
alt-php56-recode_5.6.40-147_amd64.deb
sha:deb6e52cb180634e5fa4b392df902bb3c244df4d
-
alt-php56-snmp_5.6.40-147_amd64.deb
sha:c6fe40269a357b1d6ba41b44e355c75fc04c1744
-
alt-php56-soap_5.6.40-147_amd64.deb
sha:c4d7b912be315f6f1f9ef4b6d0c792f844a4bc3d
-
alt-php56-sybase_5.6.40-147_amd64.deb
sha:091954b6df1e24b810003a5c6d8e77c4962355ed
-
alt-php56-tidy_5.6.40-147_amd64.deb
sha:b7dcb840ddea88bde6ff8894147aba1a399cf34a
-
alt-php56-xml_5.6.40-147_amd64.deb
sha:324b12b0be1698293788a813a63d2810add11777
-
alt-php56-xmlrpc_5.6.40-147_amd64.deb
sha:25559c75f8a23f9e38160f8cf77815ab1d47855f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.