[CLSA-2026:1791236570] Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-05 21:43:06 UTC
Description:
* SECURITY UPDATE: out-of-bounds read on an empty Location header when the http:// stream wrapper follows a redirect - debian/patches/php-5.6-CVE-2026-93682.patch: backport the net effect of upstream commits 8196275133ed (GH-23467) and de3436c76e46 (GH-23521) in ext/standard/http_fopen_wrapper.c. An empty Location header allocates a single byte for the NUL terminator, so the relative-redirect branch's read of location[1] over-read heap memory and could append a garbage-derived path to the redirect target instead of the host root. The length test now uses header_info.location_len, which this branch already carries from the CVE-2025-1861 backport, instead of strlen(), and the relative join is skipped when the header is shorter than two bytes so the second byte is never read. - Note: the guard lands directly on its final "location_len > 1" form. The intermediate "> 0" form from 8196275133ed is deliberately not shipped: it regressed single-character relative Location headers into resolving against the request path rather than the host root, which is what de3436c76e46 then fixed. Both changed lines are byte-identical to upstream; only the hunk offsets and the surrounding context differ (5.6 keeps resource->path as a plain char *). Upstream's two regression tests are carried as ext/standard/tests/http/http_empty_location_redirect.phpt and http_single_char_location_redirect.phpt, with the harness include switched to ext/openssl/tests/ServerClientTestCase2.inc, the copy that has phpt_notify_server_start() and the {{ ADDR }} placeholder on this branch. - CVE-2026-93682 * SECURITY UPDATE: php-fpm listen.allowed_clients matched only the first 96 bits of an IPv6 address - debian/patches/php-5.6-CVE-2026-91768.patch: backport upstream commit dcdfcf86fcf7 (GHSA-62xp-839h-2637) in sapi/fpm/fpm/fastcgi.c. fcgi_is_allowed() compared an incoming IPv6 peer against each entry of listen.allowed_clients with a hardcoded length of 12 bytes, so any client sharing only the first 96 bits of an allowed address was let through - every host in the same /96 as a permitted one, including the whole ::ffff:0:0/96 IPv4-mapped range for a single mapped entry. The comparison now covers sizeof(sin6_addr), all 128 bits. - Note: the changed line is byte-identical to upstream; only its location differs, as the FastCGI protocol code lives in sapi/fpm/fpm/fastcgi.c on 5.6 rather than main/fastcgi.c. Upstream's two regression tests are not carried: they need the modern FPM test harness (sapi/fpm/tests/tester.inc with the FPM\Tester class, its {{ADDR:IPv6:ANY[...]}} placeholders and skipIfIPv6IsNotSupported()), which does not exist on this branch. - CVE-2026-91768
Updated packages:
  • alt-php56_5.6.40-147_amd64.deb
    sha:abfe569c6cfb1e8e7cad7bf1cb6a0c378650768d
  • alt-php56-bcmath_5.6.40-147_amd64.deb
    sha:4efaedf213f49dd31d87864e464abeeaa44b447a
  • alt-php56-cli_5.6.40-147_amd64.deb
    sha:1ee2e3274b2d797086c3c9c02128bb15daaa3019
  • alt-php56-common_5.6.40-147_amd64.deb
    sha:66408a4e916dfdc485e276163be53fc6dee0588e
  • alt-php56-dba_5.6.40-147_amd64.deb
    sha:63a669af85a574c08ffa725a3282a2bbc774c4f1
  • alt-php56-dbx_5.6.40-147_amd64.deb
    sha:7a85e84e6b7ef5a3eb250d0130827b207defd18f
  • alt-php56-dev_5.6.40-147_amd64.deb
    sha:949c533dba770e0c29ef5b40e4ac0a7204abff34
  • alt-php56-enchant_5.6.40-147_amd64.deb
    sha:f9255251ff8204462ff8a63a7662196d5b2e59cc
  • alt-php56-firebird_5.6.40-147_amd64.deb
    sha:cdae22d06e2ef25973f96e5f65f15301a8f23192
  • alt-php56-gd_5.6.40-147_amd64.deb
    sha:c488cee521fd8bc92eb773b9c0b6ad94965d5cfc
  • alt-php56-imap_5.6.40-147_amd64.deb
    sha:0d99c4777aabb9710a6f14a8ca1b48e9479f5bb0
  • alt-php56-intl_5.6.40-147_amd64.deb
    sha:c032e27301b43c6902bf17439b59189edd6f06f2
  • alt-php56-ldap_5.6.40-147_amd64.deb
    sha:5bf62e68e21d5b633718a763872e5ba95076b3a8
  • alt-php56-mbstring_5.6.40-147_amd64.deb
    sha:bc4401d0ec61e052138ed0c8e34b3a8cd1427515
  • alt-php56-mcrypt_5.6.40-147_amd64.deb
    sha:89538a4611d22c02e45e3947f3ecaa7f2d5c92fb
  • alt-php56-mysqlnd_5.6.40-147_amd64.deb
    sha:f6c97f883c9264c47552156c30a7e2cd5c8c0f5b
  • alt-php56-odbc_5.6.40-147_amd64.deb
    sha:c52e3d42e8c680fd27253c26682ac8e601988140
  • alt-php56-opcache_5.6.40-147_amd64.deb
    sha:0dfeb4a3c9f0e80d7d8752f6516a2101062ac140
  • alt-php56-pdo_5.6.40-147_amd64.deb
    sha:25dc5ce3a537fc0141941990a55e152b957c25a9
  • alt-php56-pgsql_5.6.40-147_amd64.deb
    sha:b4d7429d989cb8fc9ddde069e178795e333546e1
  • alt-php56-php-fpm_5.6.40-147_amd64.deb
    sha:1b1dcebccfc4a4b0b0845d7fb656a538e03debde
  • alt-php56-process_5.6.40-147_amd64.deb
    sha:8bf8a5d46c5cdb0e0ef81992a8c4ee76a1a9ab43
  • alt-php56-pspell_5.6.40-147_amd64.deb
    sha:095a0eb132e2b23b18450f5f8e9e0cb30aac11f6
  • alt-php56-recode_5.6.40-147_amd64.deb
    sha:096464c165c4510cfd4093bc979886671d7b1e4d
  • alt-php56-snmp_5.6.40-147_amd64.deb
    sha:9e1ea6f1d8c1cc2bbd35e7ada432813c1d160232
  • alt-php56-soap_5.6.40-147_amd64.deb
    sha:b3482785d79b3dc527a689bfbfaa366e48707e67
  • alt-php56-sybase_5.6.40-147_amd64.deb
    sha:9b547f8ad0d7e9d402e3b1c45d33c240ce9f95ca
  • alt-php56-tidy_5.6.40-147_amd64.deb
    sha:88e0140a612edeeebc2f60889c24cb70b3a13d6c
  • alt-php56-xml_5.6.40-147_amd64.deb
    sha:d8e46a0da65ed52d0c263d03981ee356514ab656
  • alt-php56-xmlrpc_5.6.40-147_amd64.deb
    sha:77cfb38486f72496401411fbf9b526f7104d056d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.