[CLSA-2026:1786109033] Fix CVE(s): CVE-2026-56131
Type:
security
Severity:
Critical
Release date:
2026-08-07 13:24:04 UTC
Description:
* SECURITY UPDATE: use-after-free through handler re-entrancy - debian/patches/CVE-2026-56131.patch: track the handler call depth at every handler call site, including the ones reached through a CDATA section, and reject XML_ResumeParser, XML_Parse, XML_ParseBuffer, XML_GetBuffer, XML_ParserFree and XML_ParserReset while a handler is on the stack (libexpat PR #1246, PR #1267 and PR #1278). - CVE-2026-56131
CVEs fixed:
Updated packages:
  • expat_2.1.0-7ubuntu0.16.04.5+tuxcare.els12_amd64.deb
    sha:8832518bb3b51b12c285f07ec2bbbad089467d66
  • libexpat1_2.1.0-7ubuntu0.16.04.5+tuxcare.els12_amd64.deb
    sha:dfd1a4bdac9c8169df2913596647c860fc135221
  • libexpat1-dev_2.1.0-7ubuntu0.16.04.5+tuxcare.els12_amd64.deb
    sha:2129b784cac49c3cd6e99e3ffcabf0c019f5ef1e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.