Amazon Linux 2023 : php8.2, php8.2-bcmath, php8.2-cli (ALAS2023-2026-1727)

critical Nessus Plugin ID 316831

Synopsis

The remote Amazon Linux 2023 host is missing a security update.

Description

It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2023-2026-1727 advisory.

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.
(CVE-2026-6722)

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page. (CVE-2026-6735)

Out-of-bounds read in urldecode() (CVE-2026-7258)

Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() (CVE-2026-7259)

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use- after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system. (CVE-2026-7261)

NULL pointer dereference in SOAP apache:Map decoder with missing <value> (CVE-2026-7262)

Signed integer overflow in metaphone() (CVE-2026-7568)

Tenable has extracted the preceding description block directly from the tested product security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

See Also

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-1727.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-6722.html

https://explore.alas.aws.amazon.com/CVE-2026-6735.html

https://explore.alas.aws.amazon.com/CVE-2026-7258.html

https://explore.alas.aws.amazon.com/CVE-2026-7259.html

https://explore.alas.aws.amazon.com/CVE-2026-7261.html

https://explore.alas.aws.amazon.com/CVE-2026-7262.html

https://explore.alas.aws.amazon.com/CVE-2026-7568.html

Plugin Details

Severity: Critical

ID: 316831

File Name: al2023_ALAS2023-2026-1727.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 5/26/2026

Updated: 5/26/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-7261

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.5

Threat Score: 9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CVSS Score Source: CVE-2026-6722

Vulnerability Information

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:php8.2, p-cpe:/a:amazon:linux:php8.2-bcmath, p-cpe:/a:amazon:linux:php8.2-bcmath-debuginfo, p-cpe:/a:amazon:linux:php8.2-cli, p-cpe:/a:amazon:linux:php8.2-cli-debuginfo, p-cpe:/a:amazon:linux:php8.2-common, p-cpe:/a:amazon:linux:php8.2-common-debuginfo, p-cpe:/a:amazon:linux:php8.2-dba, p-cpe:/a:amazon:linux:php8.2-dba-debuginfo, p-cpe:/a:amazon:linux:php8.2-dbg, p-cpe:/a:amazon:linux:php8.2-dbg-debuginfo, p-cpe:/a:amazon:linux:php8.2-debuginfo, p-cpe:/a:amazon:linux:php8.2-debugsource, p-cpe:/a:amazon:linux:php8.2-devel, p-cpe:/a:amazon:linux:php8.2-embedded, p-cpe:/a:amazon:linux:php8.2-embedded-debuginfo, p-cpe:/a:amazon:linux:php8.2-enchant, p-cpe:/a:amazon:linux:php8.2-enchant-debuginfo, p-cpe:/a:amazon:linux:php8.2-ffi, p-cpe:/a:amazon:linux:php8.2-ffi-debuginfo, p-cpe:/a:amazon:linux:php8.2-fpm, p-cpe:/a:amazon:linux:php8.2-fpm-debuginfo, p-cpe:/a:amazon:linux:php8.2-gd, p-cpe:/a:amazon:linux:php8.2-gd-debuginfo, p-cpe:/a:amazon:linux:php8.2-gmp, p-cpe:/a:amazon:linux:php8.2-gmp-debuginfo, p-cpe:/a:amazon:linux:php8.2-intl, p-cpe:/a:amazon:linux:php8.2-intl-debuginfo, p-cpe:/a:amazon:linux:php8.2-ldap, p-cpe:/a:amazon:linux:php8.2-ldap-debuginfo, p-cpe:/a:amazon:linux:php8.2-mbstring, p-cpe:/a:amazon:linux:php8.2-mbstring-debuginfo, p-cpe:/a:amazon:linux:php8.2-mysqlnd, p-cpe:/a:amazon:linux:php8.2-mysqlnd-debuginfo, p-cpe:/a:amazon:linux:php8.2-odbc, p-cpe:/a:amazon:linux:php8.2-odbc-debuginfo, p-cpe:/a:amazon:linux:php8.2-opcache, p-cpe:/a:amazon:linux:php8.2-opcache-debuginfo, p-cpe:/a:amazon:linux:php8.2-pdo, p-cpe:/a:amazon:linux:php8.2-pdo-debuginfo, p-cpe:/a:amazon:linux:php8.2-pgsql, p-cpe:/a:amazon:linux:php8.2-pgsql-debuginfo, p-cpe:/a:amazon:linux:php8.2-process, p-cpe:/a:amazon:linux:php8.2-process-debuginfo, p-cpe:/a:amazon:linux:php8.2-pspell, p-cpe:/a:amazon:linux:php8.2-pspell-debuginfo, p-cpe:/a:amazon:linux:php8.2-snmp, p-cpe:/a:amazon:linux:php8.2-snmp-debuginfo, p-cpe:/a:amazon:linux:php8.2-soap, p-cpe:/a:amazon:linux:php8.2-soap-debuginfo, p-cpe:/a:amazon:linux:php8.2-tidy, p-cpe:/a:amazon:linux:php8.2-tidy-debuginfo, p-cpe:/a:amazon:linux:php8.2-xml, p-cpe:/a:amazon:linux:php8.2-xml-debuginfo, p-cpe:/a:amazon:linux:php8.2-sodium, p-cpe:/a:amazon:linux:php8.2-sodium-debuginfo, p-cpe:/a:amazon:linux:php8.2-zip, p-cpe:/a:amazon:linux:php8.2-zip-debuginfo

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/25/2026

Vulnerability Publication Date: 5/6/2026

Reference Information

CVE: CVE-2026-6722, CVE-2026-6735, CVE-2026-7258, CVE-2026-7259, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568