[CLSA-2026:1790242021] libxml2: Fix of CVE-2025-9714
Type:
security
Severity:
None
Release date:
2026-09-24 09:27:11 UTC
Description:
- rebase to 2.9.1-6.0.13.el7_9.6 - replace the TuxCare CVE-2025-9714 backport (Patch229) with the vendor's Patch1007, which guards six evaluation paths where ours guarded three - CVE-2025-9714: initialise the XPath maxDepth the vendor's patch adds to upstream's XPATH_MAX_RECURSION_DEPTH instead of INT_MAX, which left every recursion guard it adds unreachable - all other TuxCare CVE patches are unchanged: Patch200-232 remain declared and applied
Updated packages:
  • libxml2-2.9.1-6.0.13.el7_9.6.tuxcare.els1.i686.rpm
    sha:98f02b5c91748eccfa7bca029d095930e1ec40a957ff623ed99fb8a081facaea
  • libxml2-2.9.1-6.0.13.el7_9.6.tuxcare.els1.x86_64.rpm
    sha:0f84bb897a6eef5ce34ebc159bf665f17b1aa2b0975ec50ff24381993fdeb17e
  • libxml2-devel-2.9.1-6.0.13.el7_9.6.tuxcare.els1.i686.rpm
    sha:12390e8a36555e1d96f3a33f0e2bd3ff2b5908e2a3f53b88539fc3679a03344c
  • libxml2-devel-2.9.1-6.0.13.el7_9.6.tuxcare.els1.x86_64.rpm
    sha:7c5be0f5fac8d405a9bb89be0eaa521ca419903639d7ca903d965127a359f9f7
  • libxml2-python-2.9.1-6.0.13.el7_9.6.tuxcare.els1.x86_64.rpm
    sha:7def09c60ffbe19fb38e409baa5fc77e4d68167732bba0cb320ae8913dee050b
  • libxml2-static-2.9.1-6.0.13.el7_9.6.tuxcare.els1.i686.rpm
    sha:44a12a2e3403faca8d97c866a517213148fde0ee7fc93a8735810d0bfbf127f9
  • libxml2-static-2.9.1-6.0.13.el7_9.6.tuxcare.els1.x86_64.rpm
    sha:2dcf35b2f7d183bb982623e1071f4a4091a0053903b6fe9e32b500b1e8769b2e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.