Release date:
2026-10-06 02:37:26 UTC
Description:
* SECURITY UPDATE: out-of-bounds read when following a redirect with an
empty Location header
- debian/patches/php-7.1-CVE-2026-93682.patch: an empty Location header
allocates a single byte for the NUL terminator, but the relative-redirect
branch of the http stream wrapper tested *(header_info.location+1), so it
read past the end of that allocation and could append a path derived from
the garbage it found to the redirect target instead of resolving against
the host root. Both guards now use header_info.location_len, which our
CVE-2025-1861 backport already introduced. This is the net effect of
upstream 8196275133 and its follow-up de3436c76e: the first commit used
location_len > 0, which made a single-character relative Location resolve
against the request path rather than the host root, and the follow-up
restored the long-standing behaviour with > 1. Only the final > 1 state
is shipped.
- CVE-2026-93682
* SECURITY UPDATE: FastCGI listen.allowed_clients compared only the first
96 bits of an IPv6 address
- debian/patches/php-7.1-CVE-2026-91768.patch: fcgi_is_allowed() passed a
hard-coded length of 12 to the memcmp() that matches a connecting IPv6
client against listen.allowed_clients, so only the leading 96 of the
128 address bits were checked and any client sharing that prefix with an
allowed address — including every host in the same /96, and every
IPv4-mapped address once the allowed entry is one — was accepted. The
comparison now covers the full sizeof(sin6_addr). On 7.1 this code lives
in main/fastcgi.c rather than sapi/fpm/fpm/fastcgi.c.
- CVE-2026-91768
Updated packages:
-
alt-php71_7.1.33-113_amd64.deb
sha:599a68350174e55448e7d85538d098b26c39433f
-
alt-php71-bcmath_7.1.33-113_amd64.deb
sha:c66fa91814e094d250e067be01860c43bef472dd
-
alt-php71-cli_7.1.33-113_amd64.deb
sha:aee700ae4c68b2d6ef8b104021a891b8cbccebd3
-
alt-php71-common_7.1.33-113_amd64.deb
sha:7915d9f6b321589d0a4ab7283ce4643e09cd7652
-
alt-php71-dba_7.1.33-113_amd64.deb
sha:c328cc12a7b168aa8905a263ef53372eb61fe3c1
-
alt-php71-dev_7.1.33-113_amd64.deb
sha:cca7757eab46f1117580c35b200fe5390c758c23
-
alt-php71-enchant_7.1.33-113_amd64.deb
sha:02e5fce6b38023724384491b0e8a5688e520ff33
-
alt-php71-firebird_7.1.33-113_amd64.deb
sha:89c921624746c5143bddfad90c2560738b83e78f
-
alt-php71-gd_7.1.33-113_amd64.deb
sha:dffcb23e1b1f8e3c0ad68536151fc0428c9d1059
-
alt-php71-imap_7.1.33-113_amd64.deb
sha:4876e0255889725e2d7083fdfb2e536d08df4343
-
alt-php71-intl_7.1.33-113_amd64.deb
sha:e16548f3db7745f60a31c4d60bcc2a62c03f4320
-
alt-php71-ldap_7.1.33-113_amd64.deb
sha:3eefb9ec8d860e52d2fea2dba055356c98e78e06
-
alt-php71-mbstring_7.1.33-113_amd64.deb
sha:04e2fe3e3f999429a96872cdc504ab84dfecd52a
-
alt-php71-mcrypt_7.1.33-113_amd64.deb
sha:64012143396bfe8cf35dc9a5783ab8c692adfb2c
-
alt-php71-mysqlnd_7.1.33-113_amd64.deb
sha:e2f30f2830cdca79d80ed33492851dfd00e2d1eb
-
alt-php71-odbc_7.1.33-113_amd64.deb
sha:e02e6bf956c4869a12e3aa034191b9e83c03ae27
-
alt-php71-opcache_7.1.33-113_amd64.deb
sha:6d9e43d5d8b351038a7994453a9eb40788e1b170
-
alt-php71-pdo_7.1.33-113_amd64.deb
sha:ca0cff2b795a4642a10436ec42c2573adbfa1da3
-
alt-php71-pgsql_7.1.33-113_amd64.deb
sha:b228248b85a0472c42010d87a387f112c64cab68
-
alt-php71-php-fpm_7.1.33-113_amd64.deb
sha:fdf9d88795f86ba7827214cf8f5694cb4e16ee2f
-
alt-php71-process_7.1.33-113_amd64.deb
sha:af2059c72c5584eea0f23fcc022218dac1b5932c
-
alt-php71-pspell_7.1.33-113_amd64.deb
sha:8c1ffa6ae65be592cbf980eda53906ca4d7a40fe
-
alt-php71-recode_7.1.33-113_amd64.deb
sha:e6d7047ab319f3840cbbd268ba50be1a3b49ee84
-
alt-php71-snmp_7.1.33-113_amd64.deb
sha:9320b4ab7333464bc42c77a8badb9942022e63fb
-
alt-php71-soap_7.1.33-113_amd64.deb
sha:0b2bbfb925b723733909417415212efdd9d26ae7
-
alt-php71-tidy_7.1.33-113_amd64.deb
sha:14e681dd1a62590ad3db651744355e17671be55c
-
alt-php71-xml_7.1.33-113_amd64.deb
sha:cf74df936b043010a77fa1686419a31cb90c097c
-
alt-php71-xmlrpc_7.1.33-113_amd64.deb
sha:2fe863fdedbf28fb75a64cc710cf3fd5b280cf09
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.