[CLSA-2026:1790241797] libxml2: Fix of CVE-2025-9714
Type:
security
Severity:
None
Release date:
2026-09-24 10:56:43 UTC
Description:
- rebase to 2.9.1-6.0.13.el7_9.6 - replace the TuxCare CVE-2025-9714 backport (Patch229) with the vendor's Patch1007, which guards six evaluation paths where ours guarded three - CVE-2025-9714: initialise the XPath maxDepth the vendor's patch adds to upstream's XPATH_MAX_RECURSION_DEPTH instead of INT_MAX, which left every recursion guard it adds unreachable - all other TuxCare CVE patches are unchanged: Patch200-232 remain declared and applied
Updated packages:
  • libxml2-2.9.1-6.0.13.el7_9.6.tuxcare.els1.i686.rpm
    sha:ead0626634341506ad88eb81613b8d5773bff03c33a8486f24f62d11c78445b7
  • libxml2-2.9.1-6.0.13.el7_9.6.tuxcare.els1.x86_64.rpm
    sha:d9d544410060c3c1cdc5aa6698e317eb921f1be24a180c34665163029227eae0
  • libxml2-devel-2.9.1-6.0.13.el7_9.6.tuxcare.els1.i686.rpm
    sha:7749d2cbb605b342153e6469a104cb5d7b3816b727898cd5260c2f520c59b1bb
  • libxml2-devel-2.9.1-6.0.13.el7_9.6.tuxcare.els1.x86_64.rpm
    sha:26b438cdaf4d689a54daf825c9afbe98405318b96bf6c6c5cb56d75a6e9c82cc
  • libxml2-python-2.9.1-6.0.13.el7_9.6.tuxcare.els1.x86_64.rpm
    sha:c5365c40d56795d2d5538cd15273da1de64ec5248c1829764fc704858148da5e
  • libxml2-static-2.9.1-6.0.13.el7_9.6.tuxcare.els1.i686.rpm
    sha:5b1e79ad076f7bab89b3e004397fbfa349cd7880de0a3ee4e7cb1053d753caa8
  • libxml2-static-2.9.1-6.0.13.el7_9.6.tuxcare.els1.x86_64.rpm
    sha:aa2d48d109392b01b945b1e0ec244a8003338a28aef0c38e8db63ab15cbd2803
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.