[CLSA-2026:1784547428] alt-php72: Fix of CVE-2026-14355
Type:
security
Severity:
Important
Release date:
2026-07-20 11:37:36 UTC
Description:
- CVE-2026-14355: openssl_encrypt() heap buffer overflow with AES key-wrap-with-padding (aes-*-wrap-pad) ciphers; the output buffer was sized as data_len + one block, which under-sizes the RFC 5649 padded-wrap output (roundup(len,8)+8) and corrupts the zend heap when built against OpenSSL 3.x. Reserve an extra block for EVP_CIPH_WRAP_MODE.
CVEs fixed:
Updated packages:
  • alt-php72-7.2.34-84.el8.x86_64.rpm
    sha:0300d6e0746456e7c3140cfb45f93ea64ad497539f483536d22a6176d5281bce
  • alt-php72-bcmath-7.2.34-84.el8.x86_64.rpm
    sha:b5e2995866953fa37e9545ac096064a43e8515545742ef7bbba8550b949b40a6
  • alt-php72-cli-7.2.34-84.el8.x86_64.rpm
    sha:3b90c132c81c1518eb9ebeb7a7d9f5b543ca48e2298ce10eb13fd12354fe4dfd
  • alt-php72-common-7.2.34-84.el8.x86_64.rpm
    sha:0e137e9660464b66162af34d6ecbf59b105c3b3705fda562b6cf29660c8ef237
  • alt-php72-dba-7.2.34-84.el8.x86_64.rpm
    sha:a83fef454702704d1cfe5040b2e840f04491fc20c39fff55571f8e2c3e6bae15
  • alt-php72-devel-7.2.34-84.el8.x86_64.rpm
    sha:7f4918599e146ebb7f0d47b952ceeb7f8b7c6d43ca54448592255272d1ebc94c
  • alt-php72-enchant-7.2.34-84.el8.x86_64.rpm
    sha:18918be6d08e1e6569a47585657cfabbe058da348efd9ad14846f2eba89bb145
  • alt-php72-firebird-7.2.34-84.el8.x86_64.rpm
    sha:3556f83915802fecafcbde3305440cb0e79b98e950059945edecb7748d433f97
  • alt-php72-gd-7.2.34-84.el8.x86_64.rpm
    sha:1f68abbdc971f4324634af6c38c98756dd24efceb92f9f94277e883c36f38be6
  • alt-php72-imap-7.2.34-84.el8.x86_64.rpm
    sha:6977ef892e453df953a8bb0432709d12555bbb447784216ca651f28f15dcc6f9
  • alt-php72-intl-7.2.34-84.el8.x86_64.rpm
    sha:d857c3858ea6287f5f1d21ce72756591e93ab401b59542a4dbfb40a1721eefb6
  • alt-php72-ldap-7.2.34-84.el8.x86_64.rpm
    sha:5386e48ffcf9c093790057d2872703c257173577e033ebf27f05d6033da51565
  • alt-php72-mbstring-7.2.34-84.el8.x86_64.rpm
    sha:26a868a5b11925904c0f1507fa4f83bd3bdcc55405a7ad62a3fbf0a60fa73f67
  • alt-php72-mysqlnd-7.2.34-84.el8.x86_64.rpm
    sha:9bf9cc8a30056af5c2431e88d601c35bc8dd4ef94c5e0d1f394c6d5b3468eb43
  • alt-php72-odbc-7.2.34-84.el8.x86_64.rpm
    sha:bf42fc44fa21d007c6aa842de88328950679c90e9b6936e69cc8a1eb68b831af
  • alt-php72-opcache-7.2.34-84.el8.x86_64.rpm
    sha:567c208b9262ddf01f1e1b44615e2b56858be2ed10e7d51324c1eacb5f2639c3
  • alt-php72-pdo-7.2.34-84.el8.x86_64.rpm
    sha:7b83d9484ee1b513b461c409ad8f97bc5f60522cc294fae8ae0e6b218c6474a5
  • alt-php72-pgsql-7.2.34-84.el8.x86_64.rpm
    sha:1c0e5f1a4cf8b90e4607d9e344fa7979ff3a2b8c47591175e2f8086adfd86501
  • alt-php72-php-fpm-7.2.34-84.el8.x86_64.rpm
    sha:b0b248c73650233a842c949ac7e378741f89920f8c9068a218eef13f62316a64
  • alt-php72-process-7.2.34-84.el8.x86_64.rpm
    sha:50608ff5eae9a6d23ed2d3b3a9260057df99cce8651ab2bed94a1523c6b0eb58
  • alt-php72-pspell-7.2.34-84.el8.x86_64.rpm
    sha:66adc5a60325816ccb79b8295dd81bb86f076166fc48b9b390c900e599d99913
  • alt-php72-recode-7.2.34-84.el8.x86_64.rpm
    sha:809239d651f5271d43dcd00525e278afcb054058e2ed4079258df6f815757e1a
  • alt-php72-snmp-7.2.34-84.el8.x86_64.rpm
    sha:2730d93d3b0c5f2c371b7ea265e56ab7daa5cfc6ed00cd63ec8e1d63aef9de56
  • alt-php72-soap-7.2.34-84.el8.x86_64.rpm
    sha:76dd867941b14a87940809b1f8a57e3cf6ca7d47848ca4b12e67e946cb104716
  • alt-php72-sodium-7.2.34-84.el8.x86_64.rpm
    sha:25d2295d69f381ea7cf490b0080747001df8b766923d2b9b79edbb803929c037
  • alt-php72-tidy-7.2.34-84.el8.x86_64.rpm
    sha:5854493645f4731fd98480022fc1156540a12539f12df3b0cdb77b99a1557053
  • alt-php72-xml-7.2.34-84.el8.x86_64.rpm
    sha:0798684116af4066fc852640c27289a2c7a038a7adb8df32fe87f8ac36c68294
  • alt-php72-xmlrpc-7.2.34-84.el8.x86_64.rpm
    sha:e4708510b7d91c986e8d5064200217472196b8d75156ba0bc1eade5cec665599
  • alt-php72-zts-7.2.34-84.el8.x86_64.rpm
    sha:f8d263c5313e5a26082a0b06656789afa91530e9d077cb0c875e60c99cbba7d6
  • alt-php72-zts-devel-7.2.34-84.el8.x86_64.rpm
    sha:4737dc2e0e68a730554f210e7b961d67dbb64f6248b0bb5319c6c0b528a96d3a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.