USN-8513-1: PHP vulnerabilities | Ubuntu security notices
It was discovered that PHP incorrectly handled SOAP object deduplicationwhen processing apache:Map nodes with duplicate keys. An attacker couldpossibly use this to cause a use-after-free, resulting in remote codeexecution. (CVE-2026-6722) It was discovered that PHP incorrectly handled SOAP request persistence whenconfigured with SOAP_PERSISTENCE_SESSION. An attacker could possibly use thisto cause a use-after-free, resulting in memory…