[CLSA-2026:1786358863] Fix CVE(s): CVE-2026-56407
Type:
security
Severity:
Important
Release date:
2026-08-10 10:49:08 UTC
Description:
* SECURITY UPDATE: signed integer overflow in XML entity value length - debian/patches/CVE-2026-56407.patch: cap entity textLen against signed integer overflow in doProlog() (backport of libexpat commit 30c2fc1, PR #1262). - CVE-2026-56407
CVEs fixed:
Updated packages:
  • expat_2.2.5-3ubuntu0.9+tuxcare.els10_amd64.deb
    sha:a5f8ff3e2c1cb60b0b09a77969f7ce3ba6a31b8b
  • libexpat1_2.2.5-3ubuntu0.9+tuxcare.els10_amd64.deb
    sha:0d85755ef664cc0862939d454fd8ce0d43e194a3
  • libexpat1-dev_2.2.5-3ubuntu0.9+tuxcare.els10_amd64.deb
    sha:24af96eaf3261eaaae78e385ded257f52d151019
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.