[CLSA-2026:1790241783] libxml2: Fix of CVE-2025-9714
Type:
security
Severity:
None
Release date:
2026-09-24 09:23:12 UTC
Description:
- rebase to 2.9.1-6.0.13.el7_9.6 - replace the TuxCare CVE-2025-9714 backport (Patch229) with the vendor's Patch1007, which guards six evaluation paths where ours guarded three - CVE-2025-9714: initialise the XPath maxDepth the vendor's patch adds to upstream's XPATH_MAX_RECURSION_DEPTH instead of INT_MAX, which left every recursion guard it adds unreachable - all other TuxCare CVE patches are unchanged: Patch200-232 remain declared and applied
Updated packages:
  • libxml2-2.9.1-6.0.13.el7_9.6.tuxcare.els1.i686.rpm
    sha:a1a51b99fc212efed2e5c1d46630a9ef41542683e4126b32e2ca412ce527a4f0
  • libxml2-2.9.1-6.0.13.el7_9.6.tuxcare.els1.x86_64.rpm
    sha:c0f2b94b03046aef913cde1577c933b599f5a265ced15530165a08951b614d61
  • libxml2-devel-2.9.1-6.0.13.el7_9.6.tuxcare.els1.i686.rpm
    sha:ccd09b6c9993cf0eaf3945fc732a8e91aab38db64f10065dcec73144236eb041
  • libxml2-devel-2.9.1-6.0.13.el7_9.6.tuxcare.els1.x86_64.rpm
    sha:a4235ba93bb8ce182f18078edc6347e4c8ae024b115541a6d33e392387435e4f
  • libxml2-python-2.9.1-6.0.13.el7_9.6.tuxcare.els1.x86_64.rpm
    sha:1c2f46bf8cecc0b8317eb1a70d5d8897c433789795dfe1d432edaba82033005e
  • libxml2-static-2.9.1-6.0.13.el7_9.6.tuxcare.els1.i686.rpm
    sha:46bd6e56125eae27cbe23b63a97d653ebbb178d9d847959f3d0efd6e9eb9cba0
  • libxml2-static-2.9.1-6.0.13.el7_9.6.tuxcare.els1.x86_64.rpm
    sha:3dd2a9287d01422a37730c5e108e5c8ca4a1dcf300a1a5f31b8629faf7dc3909
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.