[CLSA-2026:1785887332] expat: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-04 23:49:03 UTC
Description:
- CVE-2026-56407: cap entity textLen against signed integer overflow in doProlog - CVE-2026-56408: waterproof copyString against SIZE_MAX overflow in xmlparse.c
Updated packages:
  • expat-2.5.0-1.el9_2.tuxcare.els15.i686.rpm
    sha:72df115b6138c255a6e93d4200861079a169dc50a144b2c7c0b9d21b9f4728cb
  • expat-2.5.0-1.el9_2.tuxcare.els15.x86_64.rpm
    sha:8021705bd8f21bc5f39325ab651504f71dd176a6ab313717b564bfc7f9972db2
  • expat-devel-2.5.0-1.el9_2.tuxcare.els15.i686.rpm
    sha:5ed504071a77251cd61c5158d1da6563084ad6b106dca24602a15dbacf794af9
  • expat-devel-2.5.0-1.el9_2.tuxcare.els15.x86_64.rpm
    sha:986f80c1718721459e31d217edc2b30163d51adfc9ead195a0264a9dbc8bbfc1
  • expat-static-2.5.0-1.el9_2.tuxcare.els15.x86_64.rpm
    sha:a4211310dc1446f83c728ae57e49d277b9163be8042e65a23f71a2b69550397d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.