Release date:
2026-08-10 10:49:08 UTC
Description:
* SECURITY UPDATE: signed integer overflow in XML entity value length
- debian/patches/CVE-2026-56407.patch: cap entity textLen against signed
integer overflow in doProlog() (backport of libexpat commit 30c2fc1,
PR #1262).
- CVE-2026-56407
Updated packages:
-
expat_2.2.5-3ubuntu0.9+tuxcare.els10_amd64.deb
sha:a5f8ff3e2c1cb60b0b09a77969f7ce3ba6a31b8b
-
libexpat1_2.2.5-3ubuntu0.9+tuxcare.els10_amd64.deb
sha:0d85755ef664cc0862939d454fd8ce0d43e194a3
-
libexpat1-dev_2.2.5-3ubuntu0.9+tuxcare.els10_amd64.deb
sha:24af96eaf3261eaaae78e385ded257f52d151019
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.