ALAS2-2026-3316


Amazon Linux 2 Security Advisory: ALAS2-2026-3316
Advisory Released Date: 2026-05-26
Advisory Updated Date: 2026-05-26
Severity: Important

Issue Overview:

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution. (CVE-2026-6722)


Affected Packages:

php


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update php or yum update --advisory ALAS2-2026-3316 to update your system.

New Packages:
aarch64:
    php-5.4.16-46.amzn2.0.7.aarch64
    php-cli-5.4.16-46.amzn2.0.7.aarch64
    php-fpm-5.4.16-46.amzn2.0.7.aarch64
    php-common-5.4.16-46.amzn2.0.7.aarch64
    php-devel-5.4.16-46.amzn2.0.7.aarch64
    php-ldap-5.4.16-46.amzn2.0.7.aarch64
    php-pdo-5.4.16-46.amzn2.0.7.aarch64
    php-mysqlnd-5.4.16-46.amzn2.0.7.aarch64
    php-pgsql-5.4.16-46.amzn2.0.7.aarch64
    php-process-5.4.16-46.amzn2.0.7.aarch64
    php-odbc-5.4.16-46.amzn2.0.7.aarch64
    php-soap-5.4.16-46.amzn2.0.7.aarch64
    php-snmp-5.4.16-46.amzn2.0.7.aarch64
    php-xml-5.4.16-46.amzn2.0.7.aarch64
    php-xmlrpc-5.4.16-46.amzn2.0.7.aarch64
    php-mbstring-5.4.16-46.amzn2.0.7.aarch64
    php-gd-5.4.16-46.amzn2.0.7.aarch64
    php-bcmath-5.4.16-46.amzn2.0.7.aarch64
    php-dba-5.4.16-46.amzn2.0.7.aarch64
    php-embedded-5.4.16-46.amzn2.0.7.aarch64
    php-pspell-5.4.16-46.amzn2.0.7.aarch64
    php-recode-5.4.16-46.amzn2.0.7.aarch64
    php-intl-5.4.16-46.amzn2.0.7.aarch64
    php-enchant-5.4.16-46.amzn2.0.7.aarch64
    php-debuginfo-5.4.16-46.amzn2.0.7.aarch64

i686:
    php-5.4.16-46.amzn2.0.7.i686
    php-cli-5.4.16-46.amzn2.0.7.i686
    php-fpm-5.4.16-46.amzn2.0.7.i686
    php-common-5.4.16-46.amzn2.0.7.i686
    php-devel-5.4.16-46.amzn2.0.7.i686
    php-ldap-5.4.16-46.amzn2.0.7.i686
    php-pdo-5.4.16-46.amzn2.0.7.i686
    php-mysqlnd-5.4.16-46.amzn2.0.7.i686
    php-pgsql-5.4.16-46.amzn2.0.7.i686
    php-process-5.4.16-46.amzn2.0.7.i686
    php-odbc-5.4.16-46.amzn2.0.7.i686
    php-soap-5.4.16-46.amzn2.0.7.i686
    php-snmp-5.4.16-46.amzn2.0.7.i686
    php-xml-5.4.16-46.amzn2.0.7.i686
    php-xmlrpc-5.4.16-46.amzn2.0.7.i686
    php-mbstring-5.4.16-46.amzn2.0.7.i686
    php-gd-5.4.16-46.amzn2.0.7.i686
    php-bcmath-5.4.16-46.amzn2.0.7.i686
    php-dba-5.4.16-46.amzn2.0.7.i686
    php-embedded-5.4.16-46.amzn2.0.7.i686
    php-pspell-5.4.16-46.amzn2.0.7.i686
    php-recode-5.4.16-46.amzn2.0.7.i686
    php-intl-5.4.16-46.amzn2.0.7.i686
    php-enchant-5.4.16-46.amzn2.0.7.i686
    php-debuginfo-5.4.16-46.amzn2.0.7.i686

src:
    php-5.4.16-46.amzn2.0.7.src

x86_64:
    php-5.4.16-46.amzn2.0.7.x86_64
    php-cli-5.4.16-46.amzn2.0.7.x86_64
    php-fpm-5.4.16-46.amzn2.0.7.x86_64
    php-common-5.4.16-46.amzn2.0.7.x86_64
    php-devel-5.4.16-46.amzn2.0.7.x86_64
    php-ldap-5.4.16-46.amzn2.0.7.x86_64
    php-pdo-5.4.16-46.amzn2.0.7.x86_64
    php-mysqlnd-5.4.16-46.amzn2.0.7.x86_64
    php-pgsql-5.4.16-46.amzn2.0.7.x86_64
    php-process-5.4.16-46.amzn2.0.7.x86_64
    php-odbc-5.4.16-46.amzn2.0.7.x86_64
    php-soap-5.4.16-46.amzn2.0.7.x86_64
    php-snmp-5.4.16-46.amzn2.0.7.x86_64
    php-xml-5.4.16-46.amzn2.0.7.x86_64
    php-xmlrpc-5.4.16-46.amzn2.0.7.x86_64
    php-mbstring-5.4.16-46.amzn2.0.7.x86_64
    php-gd-5.4.16-46.amzn2.0.7.x86_64
    php-bcmath-5.4.16-46.amzn2.0.7.x86_64
    php-dba-5.4.16-46.amzn2.0.7.x86_64
    php-embedded-5.4.16-46.amzn2.0.7.x86_64
    php-pspell-5.4.16-46.amzn2.0.7.x86_64
    php-recode-5.4.16-46.amzn2.0.7.x86_64
    php-intl-5.4.16-46.amzn2.0.7.x86_64
    php-enchant-5.4.16-46.amzn2.0.7.x86_64
    php-debuginfo-5.4.16-46.amzn2.0.7.x86_64