[CLSA-2026:1786027135] expat: Fix of CVE-2026-56407
Type:
security
Severity:
Important
Release date:
2026-08-06 14:39:28 UTC
Description:
- CVE-2026-56407: prevent signed integer overflow of the entity textLen field by capping the entityValuePool length at INT_MAX in doProlog
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els4.i686.rpm
    sha:d819fe61f79d9753cad4089fdd06a34bc6bfc8a6eecfb653d3dd6c5be82a51ac
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els4.x86_64.rpm
    sha:927bc4ab08ddbbd317388250869cda26918df57cfaa76938f69c209154490d31
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els4.i686.rpm
    sha:e93c5a82aa780dd7d6445e260f6df6e4eef7e8cc80cc25670220c4d5047fe718
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els4.x86_64.rpm
    sha:e507303161690eeac2407037938fa82bf077154de00184369fcb8087272afbf4
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els4.i686.rpm
    sha:5a6c14b2c3682ece7d2a661a7b377b6f1fb079e443ff8d2f373f549bb34d3484
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els4.x86_64.rpm
    sha:b011a445820bef04fddd9c817992647bbd6cf91117bb884f5017d9c7c765277c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.