[CLSA-2026:1791210449] alt-php56: Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-05 14:27:46 UTC
Description:
- CVE-2026-93682: out-of-bounds read on an empty Location header when the http:// stream wrapper follows a redirect (ext/standard/http_fopen_wrapper.c, GH-23467). An empty Location header allocates a single byte for the NUL terminator, so the relative-redirect branch's read of location[1] over-read heap memory and could append a garbage-derived path to the redirect target instead of the host root. Net effect of upstream commits 8196275133ed and de3436c76e46: the length test uses header_info.location_len - already present on this branch from the CVE-2025-1861 backport - instead of strlen(), and the relative join is skipped unless the header is at least two bytes long. The guard is shipped directly in its final "location_len > 1" form; the intermediate "> 0" form of 8196275133ed is skipped, as it regressed single-character relative Location headers into resolving against the request path instead of the host root. Both changed lines are byte-identical to upstream. Upstream's two regression tests are carried as ext/standard/tests/http/http_empty_location_redirect.phpt and http_single_char_location_redirect.phpt, with the harness include switched to ext/openssl/tests/ServerClientTestCase2.inc, which is the copy on this branch that provides phpt_notify_server_start() and the {{ ADDR }} placeholder. - CVE-2026-91768: php-fpm listen.allowed_clients matched only the first 96 bits of an IPv6 address (sapi/fpm/fpm/fastcgi.c, GHSA-62xp-839h-2637). fcgi_is_allowed() memcmp()'d an incoming IPv6 peer against each allowed entry with a hardcoded length of 12, so any client sharing only the leading 96 bits of an allowed address was accepted - every host in the same /96, including the whole ::ffff:0:0/96 IPv4-mapped range for one mapped entry. Backport of upstream commit dcdfcf86fcf7; the comparison now uses sizeof(sin6_addr), all 128 bits. Byte-identical to upstream, only the file differs: 5.6 keeps the FastCGI protocol code in sapi/fpm/fpm/fastcgi.c, not main/fastcgi.c. Upstream's regression tests are not carried - they require the modern FPM test harness (sapi/fpm/tests/tester.inc, FPM\Tester, its {{ADDR:IPv6:ANY[...]}} placeholders and skipIfIPv6IsNotSupported()), which does not exist on this branch.
Updated packages:
  • alt-php56-5.6.40-144.el7.x86_64.rpm
    sha:ed1f70988eb17635dacd2edfab8c0e3be12adf60471cdc5f41818eaff87e77a5
  • alt-php56-bcmath-5.6.40-144.el7.x86_64.rpm
    sha:d0fdaa2dc97abf42d78ddd61f67c6fa47250e47a738ba9c3b1148301aaf599f1
  • alt-php56-cli-5.6.40-144.el7.x86_64.rpm
    sha:89294be8b09b2ffe51178868e8c4876595cf04f8df470e385aa28d0c93cad0a2
  • alt-php56-common-5.6.40-144.el7.x86_64.rpm
    sha:489587722e7c248c24f744b23612dbcb86aad08a8a21c96d1befb8c547e1a2c1
  • alt-php56-dba-5.6.40-144.el7.x86_64.rpm
    sha:904d1402af610e07d350fdccd765ee528ab1ed6e5032ca76edc4a5db146d76a0
  • alt-php56-dbx-5.6.40-144.el7.x86_64.rpm
    sha:2f3bf12e8701683718ff5e3d6a6e06a2a9309ca8631423310435010d5bab2e14
  • alt-php56-devel-5.6.40-144.el7.x86_64.rpm
    sha:9156c93907b38ed1e2c572a99bb7ea22eb2ef8537cdb426520531d73e6bc523b
  • alt-php56-enchant-5.6.40-144.el7.x86_64.rpm
    sha:3106de0be91b29f6cb07056b30112b6dd825535eab5a585b068530e1895d1ca6
  • alt-php56-firebird-5.6.40-144.el7.x86_64.rpm
    sha:2dc8f891b2b7cea3d1d00afa4f9bc706cd8c1ec8335b7b0624fdfca939b64aa1
  • alt-php56-gd-5.6.40-144.el7.x86_64.rpm
    sha:cf8c9ed84b0596be34565e02453c209dd282200993ca89696056cfe2ce24b84a
  • alt-php56-imap-5.6.40-144.el7.x86_64.rpm
    sha:c34f1738134bc5f56bf00a1e0cb31ecc578f60ee84eaf4bfebe9f44bfa98634a
  • alt-php56-intl-5.6.40-144.el7.x86_64.rpm
    sha:452b5d12a61357b67664d9a572a59a2f271866641816d1208d90ddef954ee11a
  • alt-php56-ldap-5.6.40-144.el7.x86_64.rpm
    sha:ef72f7aa79834e6c86edd54c91d7275bef3f06c9c1a732419ba8d460104cf51d
  • alt-php56-mbstring-5.6.40-144.el7.x86_64.rpm
    sha:9ddcf7028a563167a822e9cad1f32cbb2aae17f8a3c9cfe05d77430629df7cb0
  • alt-php56-mcrypt-5.6.40-144.el7.x86_64.rpm
    sha:448124d96dfeaa398bf2fcd6344d5219ca0dc1e24b169abe38641fd74fb4484a
  • alt-php56-mssql-5.6.40-144.el7.x86_64.rpm
    sha:713c3dce54432cbef87455fa2a4750d0ec5dc01b22bb383a23be4d8cd3b2f613
  • alt-php56-mysqlnd-5.6.40-144.el7.x86_64.rpm
    sha:f65fe52d9d53a56da7d4c42b4f04641df966c385c7bb61a79a3931f97d51a067
  • alt-php56-odbc-5.6.40-144.el7.x86_64.rpm
    sha:1cec1324d9a02a8b4bf2a24d25809e0c111d346753fe7f960004346f6fccca03
  • alt-php56-opcache-5.6.40-144.el7.x86_64.rpm
    sha:1b4edaa4481e33484969f3b7d3d2e55eb132d1d91509e2f63462889fd356e961
  • alt-php56-pdo-5.6.40-144.el7.x86_64.rpm
    sha:41b1028eaa5729337083f7d66ada8d9c77a2cc54818258ba2ee07502b7de99e6
  • alt-php56-pgsql-5.6.40-144.el7.x86_64.rpm
    sha:fa9269dc7e42f8cb56fa1ee5bc312fcfe7e1a61a0c93b2943958969a2ffa6005
  • alt-php56-php-fpm-5.6.40-144.el7.x86_64.rpm
    sha:a1c4f3d08a9240f4254eea095f9ddc8d3bb81910d399b52da083ce4ecea19a49
  • alt-php56-process-5.6.40-144.el7.x86_64.rpm
    sha:caa3c7610852c4f2e50fe86510291c0b5b03611455c6f2c94e8a18c36583cca5
  • alt-php56-pspell-5.6.40-144.el7.x86_64.rpm
    sha:f3a92d69b8a99c45a575a7a1cf0157e573b796512a14280226b7761be2c22e82
  • alt-php56-recode-5.6.40-144.el7.x86_64.rpm
    sha:a54b67ac984d68abf9930ad0801019a8f5592704b3c446ea496f42bd7dbf5246
  • alt-php56-snmp-5.6.40-144.el7.x86_64.rpm
    sha:2f439c7b26d4c0b36fb20019de5573eee6d8219458063ddca00e21bcf39bbbac
  • alt-php56-soap-5.6.40-144.el7.x86_64.rpm
    sha:01229f75d2ad94dd5c4276a671a48536ad96d0f1a81376878c402a3839a7f657
  • alt-php56-sybase-5.6.40-144.el7.x86_64.rpm
    sha:bf007b9d29e882cd65c2e7e75d4afe37aa6319e0043e2c92948b724423a56af0
  • alt-php56-tidy-5.6.40-144.el7.x86_64.rpm
    sha:6ea035963478b8f62911c2933220d52a8b60a257b5b9f365a7eded581331e33d
  • alt-php56-xml-5.6.40-144.el7.x86_64.rpm
    sha:15157c3eb865e25d3a21756049e70d6e0ee79ac634b52a34f9178edc0b050df1
  • alt-php56-xmlrpc-5.6.40-144.el7.x86_64.rpm
    sha:0166895e1c10c119e0387842e6dd8fdc405bd4840829d7b59732ffe0d3a678f9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.