Release date:
2026-10-05 23:31:10 UTC
Description:
* SECURITY UPDATE: out-of-bounds read when following a redirect with an
empty Location header
- debian/patches/php-7.1-CVE-2026-93682.patch: an empty Location header
allocates a single byte for the NUL terminator, but the relative-redirect
branch of the http stream wrapper tested *(header_info.location+1), so it
read past the end of that allocation and could append a path derived from
the garbage it found to the redirect target instead of resolving against
the host root. Both guards now use header_info.location_len, which our
CVE-2025-1861 backport already introduced. This is the net effect of
upstream 8196275133 and its follow-up de3436c76e: the first commit used
location_len > 0, which made a single-character relative Location resolve
against the request path rather than the host root, and the follow-up
restored the long-standing behaviour with > 1. Only the final > 1 state
is shipped.
- CVE-2026-93682
* SECURITY UPDATE: FastCGI listen.allowed_clients compared only the first
96 bits of an IPv6 address
- debian/patches/php-7.1-CVE-2026-91768.patch: fcgi_is_allowed() passed a
hard-coded length of 12 to the memcmp() that matches a connecting IPv6
client against listen.allowed_clients, so only the leading 96 of the
128 address bits were checked and any client sharing that prefix with an
allowed address — including every host in the same /96, and every
IPv4-mapped address once the allowed entry is one — was accepted. The
comparison now covers the full sizeof(sin6_addr). On 7.1 this code lives
in main/fastcgi.c rather than sapi/fpm/fpm/fastcgi.c.
- CVE-2026-91768
Updated packages:
-
alt-php71_7.1.33-113_amd64.deb
sha:599a68350174e55448e7d85538d098b26c39433f
-
alt-php71-bcmath_7.1.33-113_amd64.deb
sha:fc6140418600ecacf80b162845d260a3b799935b
-
alt-php71-cli_7.1.33-113_amd64.deb
sha:77e22e1ab8577bd4820760ad120bd7d1ab9ffdc0
-
alt-php71-common_7.1.33-113_amd64.deb
sha:9f6ef9c8f640130f49e81226e1e5c39aabb86808
-
alt-php71-dba_7.1.33-113_amd64.deb
sha:431c426f6ef3f954b2929928d4e84c1ef1e7d701
-
alt-php71-dev_7.1.33-113_amd64.deb
sha:6db66006b83c95a8b17e529393bf80c8d3b15f90
-
alt-php71-enchant_7.1.33-113_amd64.deb
sha:5af753694b529f1effca7c692ef1f164a9c86380
-
alt-php71-firebird_7.1.33-113_amd64.deb
sha:abb4f874e963509fc52f2678672c958b19a2c60e
-
alt-php71-gd_7.1.33-113_amd64.deb
sha:d9dcc24d5f47202ae3196e633e981578567849aa
-
alt-php71-imap_7.1.33-113_amd64.deb
sha:7de25a9bd46a35312e769749d04c7d7779173ce2
-
alt-php71-intl_7.1.33-113_amd64.deb
sha:25a2ca56d434cf49199bdd240dd1cb6d5a06ecc9
-
alt-php71-ldap_7.1.33-113_amd64.deb
sha:5e9a761cb20a2cc1496e6cbbfa971df7b34dc6c1
-
alt-php71-mbstring_7.1.33-113_amd64.deb
sha:10d9ad0f6b651f34c547847fa875878e61f0204c
-
alt-php71-mcrypt_7.1.33-113_amd64.deb
sha:686eeb200ffe6432d9fa3ea0376a58760634a721
-
alt-php71-mysqlnd_7.1.33-113_amd64.deb
sha:3ad073395918d6bee70f091d69c887a02651b8e4
-
alt-php71-odbc_7.1.33-113_amd64.deb
sha:204f3e308df05674165b30e7088595948496f7ad
-
alt-php71-opcache_7.1.33-113_amd64.deb
sha:dfeeb82cb5afec70d1ebc7a626638b59e9e508f5
-
alt-php71-pdo_7.1.33-113_amd64.deb
sha:b283f3b165b93aec9fbff2c0276679ec8ee8fb88
-
alt-php71-pgsql_7.1.33-113_amd64.deb
sha:318d1c55dc44011527c6853108ab5b0c8cd1f475
-
alt-php71-php-fpm_7.1.33-113_amd64.deb
sha:8d3ea8275b857f28c095a4e29249e6056e53b761
-
alt-php71-process_7.1.33-113_amd64.deb
sha:6558bb4c89f687cea9ab020c2fb41a2d1c01d88e
-
alt-php71-pspell_7.1.33-113_amd64.deb
sha:246ac33e1db58bb7110ee2acf28d00eba3696b02
-
alt-php71-recode_7.1.33-113_amd64.deb
sha:e7ce18440c3e2e63ce9981d57d8d90b28ebe17c4
-
alt-php71-snmp_7.1.33-113_amd64.deb
sha:0384bde2a4087535f40d607f4d620ca91cfc9b68
-
alt-php71-soap_7.1.33-113_amd64.deb
sha:7170ac6da5571f6a31434060f29e097b80b56414
-
alt-php71-tidy_7.1.33-113_amd64.deb
sha:a0814f8be52e70055cbe026b9244843fc2433036
-
alt-php71-xml_7.1.33-113_amd64.deb
sha:75441c2a92a4814487c75624cf2cb1c7e808abc3
-
alt-php71-xmlrpc_7.1.33-113_amd64.deb
sha:7ddf588c4d53a89f615ec860c48990216a766364
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.