ALAS2PHP8.2-2026-011


Amazon Linux 2 Security Advisory: ALAS2PHP8.2-2026-011
Advisory Released Date: 2026-05-26
Advisory Updated Date: 2026-05-26
Severity: Important

Issue Overview:

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution. (CVE-2026-6722)

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page. (CVE-2026-6735)

Out-of-bounds read in urldecode() (CVE-2026-7258)

Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() (CVE-2026-7259)

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system. (CVE-2026-7261)

NULL pointer dereference in SOAP apache:Map decoder with missing <value> (CVE-2026-7262)

Signed integer overflow in metaphone() (CVE-2026-7568)


Affected Packages:

php


Note:

This advisory is applicable to Amazon Linux 2 - Php8.2 Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update php or yum update --advisory ALAS2PHP8.2-2026-011 to update your system.

New Packages:
aarch64:
    php-8.2.31-1.amzn2.0.1.aarch64
    php-cli-8.2.31-1.amzn2.0.1.aarch64
    php-dbg-8.2.31-1.amzn2.0.1.aarch64
    php-fpm-8.2.31-1.amzn2.0.1.aarch64
    php-common-8.2.31-1.amzn2.0.1.aarch64
    php-devel-8.2.31-1.amzn2.0.1.aarch64
    php-opcache-8.2.31-1.amzn2.0.1.aarch64
    php-ldap-8.2.31-1.amzn2.0.1.aarch64
    php-pdo-8.2.31-1.amzn2.0.1.aarch64
    php-mysqlnd-8.2.31-1.amzn2.0.1.aarch64
    php-pgsql-8.2.31-1.amzn2.0.1.aarch64
    php-process-8.2.31-1.amzn2.0.1.aarch64
    php-odbc-8.2.31-1.amzn2.0.1.aarch64
    php-soap-8.2.31-1.amzn2.0.1.aarch64
    php-snmp-8.2.31-1.amzn2.0.1.aarch64
    php-xml-8.2.31-1.amzn2.0.1.aarch64
    php-mbstring-8.2.31-1.amzn2.0.1.aarch64
    php-gd-8.2.31-1.amzn2.0.1.aarch64
    php-bcmath-8.2.31-1.amzn2.0.1.aarch64
    php-gmp-8.2.31-1.amzn2.0.1.aarch64
    php-dba-8.2.31-1.amzn2.0.1.aarch64
    php-embedded-8.2.31-1.amzn2.0.1.aarch64
    php-pspell-8.2.31-1.amzn2.0.1.aarch64
    php-intl-8.2.31-1.amzn2.0.1.aarch64
    php-enchant-8.2.31-1.amzn2.0.1.aarch64
    php-sodium-8.2.31-1.amzn2.0.1.aarch64
    php-debuginfo-8.2.31-1.amzn2.0.1.aarch64

src:
    php-8.2.31-1.amzn2.0.1.src

x86_64:
    php-8.2.31-1.amzn2.0.1.x86_64
    php-cli-8.2.31-1.amzn2.0.1.x86_64
    php-dbg-8.2.31-1.amzn2.0.1.x86_64
    php-fpm-8.2.31-1.amzn2.0.1.x86_64
    php-common-8.2.31-1.amzn2.0.1.x86_64
    php-devel-8.2.31-1.amzn2.0.1.x86_64
    php-opcache-8.2.31-1.amzn2.0.1.x86_64
    php-ldap-8.2.31-1.amzn2.0.1.x86_64
    php-pdo-8.2.31-1.amzn2.0.1.x86_64
    php-mysqlnd-8.2.31-1.amzn2.0.1.x86_64
    php-pgsql-8.2.31-1.amzn2.0.1.x86_64
    php-process-8.2.31-1.amzn2.0.1.x86_64
    php-odbc-8.2.31-1.amzn2.0.1.x86_64
    php-soap-8.2.31-1.amzn2.0.1.x86_64
    php-snmp-8.2.31-1.amzn2.0.1.x86_64
    php-xml-8.2.31-1.amzn2.0.1.x86_64
    php-mbstring-8.2.31-1.amzn2.0.1.x86_64
    php-gd-8.2.31-1.amzn2.0.1.x86_64
    php-bcmath-8.2.31-1.amzn2.0.1.x86_64
    php-gmp-8.2.31-1.amzn2.0.1.x86_64
    php-dba-8.2.31-1.amzn2.0.1.x86_64
    php-embedded-8.2.31-1.amzn2.0.1.x86_64
    php-pspell-8.2.31-1.amzn2.0.1.x86_64
    php-intl-8.2.31-1.amzn2.0.1.x86_64
    php-enchant-8.2.31-1.amzn2.0.1.x86_64
    php-sodium-8.2.31-1.amzn2.0.1.x86_64
    php-debuginfo-8.2.31-1.amzn2.0.1.x86_64