Amazon Linux 2 Security Advisory: ALAS2-2026-3316
Advisory Released Date: 2026-05-26
Advisory Updated Date: 2026-05-26
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution. (CVE-2026-6722)
Affected Packages:
php
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update php or yum update --advisory ALAS2-2026-3316 to update your system.
aarch64:
php-5.4.16-46.amzn2.0.7.aarch64
php-cli-5.4.16-46.amzn2.0.7.aarch64
php-fpm-5.4.16-46.amzn2.0.7.aarch64
php-common-5.4.16-46.amzn2.0.7.aarch64
php-devel-5.4.16-46.amzn2.0.7.aarch64
php-ldap-5.4.16-46.amzn2.0.7.aarch64
php-pdo-5.4.16-46.amzn2.0.7.aarch64
php-mysqlnd-5.4.16-46.amzn2.0.7.aarch64
php-pgsql-5.4.16-46.amzn2.0.7.aarch64
php-process-5.4.16-46.amzn2.0.7.aarch64
php-odbc-5.4.16-46.amzn2.0.7.aarch64
php-soap-5.4.16-46.amzn2.0.7.aarch64
php-snmp-5.4.16-46.amzn2.0.7.aarch64
php-xml-5.4.16-46.amzn2.0.7.aarch64
php-xmlrpc-5.4.16-46.amzn2.0.7.aarch64
php-mbstring-5.4.16-46.amzn2.0.7.aarch64
php-gd-5.4.16-46.amzn2.0.7.aarch64
php-bcmath-5.4.16-46.amzn2.0.7.aarch64
php-dba-5.4.16-46.amzn2.0.7.aarch64
php-embedded-5.4.16-46.amzn2.0.7.aarch64
php-pspell-5.4.16-46.amzn2.0.7.aarch64
php-recode-5.4.16-46.amzn2.0.7.aarch64
php-intl-5.4.16-46.amzn2.0.7.aarch64
php-enchant-5.4.16-46.amzn2.0.7.aarch64
php-debuginfo-5.4.16-46.amzn2.0.7.aarch64
i686:
php-5.4.16-46.amzn2.0.7.i686
php-cli-5.4.16-46.amzn2.0.7.i686
php-fpm-5.4.16-46.amzn2.0.7.i686
php-common-5.4.16-46.amzn2.0.7.i686
php-devel-5.4.16-46.amzn2.0.7.i686
php-ldap-5.4.16-46.amzn2.0.7.i686
php-pdo-5.4.16-46.amzn2.0.7.i686
php-mysqlnd-5.4.16-46.amzn2.0.7.i686
php-pgsql-5.4.16-46.amzn2.0.7.i686
php-process-5.4.16-46.amzn2.0.7.i686
php-odbc-5.4.16-46.amzn2.0.7.i686
php-soap-5.4.16-46.amzn2.0.7.i686
php-snmp-5.4.16-46.amzn2.0.7.i686
php-xml-5.4.16-46.amzn2.0.7.i686
php-xmlrpc-5.4.16-46.amzn2.0.7.i686
php-mbstring-5.4.16-46.amzn2.0.7.i686
php-gd-5.4.16-46.amzn2.0.7.i686
php-bcmath-5.4.16-46.amzn2.0.7.i686
php-dba-5.4.16-46.amzn2.0.7.i686
php-embedded-5.4.16-46.amzn2.0.7.i686
php-pspell-5.4.16-46.amzn2.0.7.i686
php-recode-5.4.16-46.amzn2.0.7.i686
php-intl-5.4.16-46.amzn2.0.7.i686
php-enchant-5.4.16-46.amzn2.0.7.i686
php-debuginfo-5.4.16-46.amzn2.0.7.i686
src:
php-5.4.16-46.amzn2.0.7.src
x86_64:
php-5.4.16-46.amzn2.0.7.x86_64
php-cli-5.4.16-46.amzn2.0.7.x86_64
php-fpm-5.4.16-46.amzn2.0.7.x86_64
php-common-5.4.16-46.amzn2.0.7.x86_64
php-devel-5.4.16-46.amzn2.0.7.x86_64
php-ldap-5.4.16-46.amzn2.0.7.x86_64
php-pdo-5.4.16-46.amzn2.0.7.x86_64
php-mysqlnd-5.4.16-46.amzn2.0.7.x86_64
php-pgsql-5.4.16-46.amzn2.0.7.x86_64
php-process-5.4.16-46.amzn2.0.7.x86_64
php-odbc-5.4.16-46.amzn2.0.7.x86_64
php-soap-5.4.16-46.amzn2.0.7.x86_64
php-snmp-5.4.16-46.amzn2.0.7.x86_64
php-xml-5.4.16-46.amzn2.0.7.x86_64
php-xmlrpc-5.4.16-46.amzn2.0.7.x86_64
php-mbstring-5.4.16-46.amzn2.0.7.x86_64
php-gd-5.4.16-46.amzn2.0.7.x86_64
php-bcmath-5.4.16-46.amzn2.0.7.x86_64
php-dba-5.4.16-46.amzn2.0.7.x86_64
php-embedded-5.4.16-46.amzn2.0.7.x86_64
php-pspell-5.4.16-46.amzn2.0.7.x86_64
php-recode-5.4.16-46.amzn2.0.7.x86_64
php-intl-5.4.16-46.amzn2.0.7.x86_64
php-enchant-5.4.16-46.amzn2.0.7.x86_64
php-debuginfo-5.4.16-46.amzn2.0.7.x86_64