Release date:
2026-08-07 13:24:04 UTC
Description:
* SECURITY UPDATE: use-after-free through handler re-entrancy
- debian/patches/CVE-2026-56131.patch: track the handler call depth at
every handler call site, including the ones reached through a CDATA
section, and reject XML_ResumeParser, XML_Parse, XML_ParseBuffer,
XML_GetBuffer, XML_ParserFree and XML_ParserReset while a handler is
on the stack (libexpat PR #1246, PR #1267 and PR #1278).
- CVE-2026-56131
Updated packages:
-
expat_2.1.0-7ubuntu0.16.04.5+tuxcare.els12_amd64.deb
sha:8832518bb3b51b12c285f07ec2bbbad089467d66
-
libexpat1_2.1.0-7ubuntu0.16.04.5+tuxcare.els12_amd64.deb
sha:dfd1a4bdac9c8169df2913596647c860fc135221
-
libexpat1-dev_2.1.0-7ubuntu0.16.04.5+tuxcare.els12_amd64.deb
sha:2129b784cac49c3cd6e99e3ffcabf0c019f5ef1e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.