[CLSA-2026:1785317328] libxml2: Fix of CVE-2026-6653
Type:
security
Severity:
Critical
Release date:
2026-07-29 09:28:59 UTC
Description:
- CVE-2026-6653: fix use-after-free in xmlParseInternalSubset by not reporting a push failure in xmlPushInput after the input was already installed
CVEs fixed:
Updated packages:
  • libxml2-2.9.7-9.el8_4.2.tuxcare.els16.i686.rpm
    sha:ef6f3ca8630fd58cbc84656d40087adb7666791b1060f58705caa2f5774e0163
  • libxml2-2.9.7-9.el8_4.2.tuxcare.els16.x86_64.rpm
    sha:6b0986c11bdb6cb666dc6a8ff146a5907acfc517eaf95458151cbcc7c4d7ea69
  • libxml2-devel-2.9.7-9.el8_4.2.tuxcare.els16.i686.rpm
    sha:e38b25a265c18f181476190c38d1a181ead899088f06b53ac495a4008e8f7c5b
  • libxml2-devel-2.9.7-9.el8_4.2.tuxcare.els16.x86_64.rpm
    sha:f68484e26619f3a54f0675aa938fd93df564d003ab881f7826e5d5696d7c06dc
  • libxml2-static-2.9.7-9.el8_4.2.tuxcare.els16.x86_64.rpm
    sha:0be6632dd8ddbbd78236b7b4dee7f1c08b8ab8364bcf715099f10396022d9313
  • python3-libxml2-2.9.7-9.el8_4.2.tuxcare.els16.x86_64.rpm
    sha:adbaa7b14598e7f0c099e946ca864e0d9d9e1e31d6c334fcbc93a7faac094bae
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.