[CLSA-2026:1785317036] libxml2: Fix of CVE-2026-6653
Type:
security
Severity:
Critical
Release date:
2026-07-29 09:24:06 UTC
Description:
- CVE-2026-6653: fix use-after-free in xmlParseInternalSubset by not reporting a push failure in xmlPushInput after the input was already installed
CVEs fixed:
Updated packages:
  • libxml2-2.9.7-9.el8_4.2.tuxcare.els16.i686.rpm
    sha:ad32fb63f6d0a8f610744e8978eabd352a02b9fe6792d8d29e94a55ee8908c4c
  • libxml2-2.9.7-9.el8_4.2.tuxcare.els16.x86_64.rpm
    sha:cede8bc429a77858ef121fc312bb6e7cb20ebc973a4bae8fa9718abd976b6b2e
  • libxml2-devel-2.9.7-9.el8_4.2.tuxcare.els16.i686.rpm
    sha:406b3f8dd749dc5702201637b246ba1a30eb85b800c2743ed1c9d159d9b8932d
  • libxml2-devel-2.9.7-9.el8_4.2.tuxcare.els16.x86_64.rpm
    sha:36af0cb4863a1eb8ebf874fde751ad1749f9acf19aa0937af40a985de11af6d6
  • libxml2-static-2.9.7-9.el8_4.2.tuxcare.els16.x86_64.rpm
    sha:505c225816e528eeb4ed189bcc06a3b87e939bebe50890dbd8a19a1572983ee4
  • python3-libxml2-2.9.7-9.el8_4.2.tuxcare.els16.x86_64.rpm
    sha:d55971d3a1d7b3cdbcbd4116b82e7635c8fecbe68d024f74a42c3f9ae471c9ae
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.