[CLSA-2026:1791211359] Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-05 14:42:57 UTC
Description:
* SECURITY UPDATE: out-of-bounds read on an empty Location header when the http:// stream wrapper follows a redirect - debian/patches/php-5.6-CVE-2026-93682.patch: backport the net effect of upstream commits 8196275133ed (GH-23467) and de3436c76e46 (GH-23521) in ext/standard/http_fopen_wrapper.c. An empty Location header allocates a single byte for the NUL terminator, so the relative-redirect branch's read of location[1] over-read heap memory and could append a garbage-derived path to the redirect target instead of the host root. The length test now uses header_info.location_len, which this branch already carries from the CVE-2025-1861 backport, instead of strlen(), and the relative join is skipped when the header is shorter than two bytes so the second byte is never read. - Note: the guard lands directly on its final "location_len > 1" form. The intermediate "> 0" form from 8196275133ed is deliberately not shipped: it regressed single-character relative Location headers into resolving against the request path rather than the host root, which is what de3436c76e46 then fixed. Both changed lines are byte-identical to upstream; only the hunk offsets and the surrounding context differ (5.6 keeps resource->path as a plain char *). Upstream's two regression tests are carried as ext/standard/tests/http/http_empty_location_redirect.phpt and http_single_char_location_redirect.phpt, with the harness include switched to ext/openssl/tests/ServerClientTestCase2.inc, the copy that has phpt_notify_server_start() and the {{ ADDR }} placeholder on this branch. - CVE-2026-93682 * SECURITY UPDATE: php-fpm listen.allowed_clients matched only the first 96 bits of an IPv6 address - debian/patches/php-5.6-CVE-2026-91768.patch: backport upstream commit dcdfcf86fcf7 (GHSA-62xp-839h-2637) in sapi/fpm/fpm/fastcgi.c. fcgi_is_allowed() compared an incoming IPv6 peer against each entry of listen.allowed_clients with a hardcoded length of 12 bytes, so any client sharing only the first 96 bits of an allowed address was let through - every host in the same /96 as a permitted one, including the whole ::ffff:0:0/96 IPv4-mapped range for a single mapped entry. The comparison now covers sizeof(sin6_addr), all 128 bits. - Note: the changed line is byte-identical to upstream; only its location differs, as the FastCGI protocol code lives in sapi/fpm/fpm/fastcgi.c on 5.6 rather than main/fastcgi.c. Upstream's two regression tests are not carried: they need the modern FPM test harness (sapi/fpm/tests/tester.inc with the FPM\Tester class, its {{ADDR:IPv6:ANY[...]}} placeholders and skipIfIPv6IsNotSupported()), which does not exist on this branch. - CVE-2026-91768
Updated packages:
  • alt-php56_5.6.40-147_amd64.deb
    sha:abfe569c6cfb1e8e7cad7bf1cb6a0c378650768d
  • alt-php56-bcmath_5.6.40-147_amd64.deb
    sha:4f2579c9cb9a87a8afbdfb71a659ddf78b861aed
  • alt-php56-cli_5.6.40-147_amd64.deb
    sha:a439bd6a801d461b89485fe4f0e33446a376d18c
  • alt-php56-common_5.6.40-147_amd64.deb
    sha:c3fdcd643ebc3ccd3bb08f8f84bce6bd640f0133
  • alt-php56-dba_5.6.40-147_amd64.deb
    sha:4adce600b0af5b63358a7af91aef2091926e1d2f
  • alt-php56-dbx_5.6.40-147_amd64.deb
    sha:d48fd5db370dc0518b17ef42281ee80b7b075cf4
  • alt-php56-dev_5.6.40-147_amd64.deb
    sha:8d81ea872f2e8fef033cd43b758d977b149f8104
  • alt-php56-enchant_5.6.40-147_amd64.deb
    sha:0c3f7933ed47cb472a250ab61aa809c957a7fc08
  • alt-php56-firebird_5.6.40-147_amd64.deb
    sha:88cfa958cf76780dce04d54c156e3e308eb5354b
  • alt-php56-gd_5.6.40-147_amd64.deb
    sha:8ac39e4fcf8f273f027fa96ac95c9093c24d6386
  • alt-php56-imap_5.6.40-147_amd64.deb
    sha:b74a94cd4484617e2eed1ef003d655aaed0ea512
  • alt-php56-intl_5.6.40-147_amd64.deb
    sha:d123dcb8aa2b152eaff1c0caf4f042dc39685b07
  • alt-php56-ldap_5.6.40-147_amd64.deb
    sha:a990574b6b3d5a58e5b7180bddbaa98be3f956a5
  • alt-php56-mbstring_5.6.40-147_amd64.deb
    sha:fb361e3aa99415a788e7fc98fe1534aa93bc15bc
  • alt-php56-mcrypt_5.6.40-147_amd64.deb
    sha:8811d1c28f6e4db65fb914feb70bebabb480b2bc
  • alt-php56-mysqlnd_5.6.40-147_amd64.deb
    sha:ebf12d462ac58f4b04557be84d2565048664eb7c
  • alt-php56-odbc_5.6.40-147_amd64.deb
    sha:cdc2fc0349297636fa8eb7a7935ab40f0108c0d8
  • alt-php56-opcache_5.6.40-147_amd64.deb
    sha:77af6287bd1116456359aeb8a87d7df559a6bda2
  • alt-php56-pdo_5.6.40-147_amd64.deb
    sha:09188edd5ec1087af10048b9b2ec11fe62119c48
  • alt-php56-pgsql_5.6.40-147_amd64.deb
    sha:a7479f30bce888e3a5defbbb6002ee25b1533681
  • alt-php56-php-fpm_5.6.40-147_amd64.deb
    sha:bf27619b51232495cf098ad2a5d07fb9af68099b
  • alt-php56-process_5.6.40-147_amd64.deb
    sha:e6256c0fab3f5a200fc1cf72af3d97522c0e1c42
  • alt-php56-pspell_5.6.40-147_amd64.deb
    sha:6aa8daab8b44c9f95818e4ba3b4d4d5c2e7008da
  • alt-php56-recode_5.6.40-147_amd64.deb
    sha:deb6e52cb180634e5fa4b392df902bb3c244df4d
  • alt-php56-snmp_5.6.40-147_amd64.deb
    sha:c6fe40269a357b1d6ba41b44e355c75fc04c1744
  • alt-php56-soap_5.6.40-147_amd64.deb
    sha:c4d7b912be315f6f1f9ef4b6d0c792f844a4bc3d
  • alt-php56-sybase_5.6.40-147_amd64.deb
    sha:091954b6df1e24b810003a5c6d8e77c4962355ed
  • alt-php56-tidy_5.6.40-147_amd64.deb
    sha:b7dcb840ddea88bde6ff8894147aba1a399cf34a
  • alt-php56-xml_5.6.40-147_amd64.deb
    sha:324b12b0be1698293788a813a63d2810add11777
  • alt-php56-xmlrpc_5.6.40-147_amd64.deb
    sha:25559c75f8a23f9e38160f8cf77815ab1d47855f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.