[CLSA-2026:1786034306] expat: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-06 16:38:38 UTC
Description:
- CVE-2026-56407: cap entity textLen against signed integer overflow in doProlog - CVE-2026-56408: protect copyString from integer overflow - CVE-2026-56409: protect xmlwf output path join from integer overflow
Updated packages:
  • expat-2.5.0-5.el9_6.tuxcare.els11.i686.rpm
    sha:bd4af6796e466a7c5e2d6cc98ddacfb712e8f17fdc23579d4a6c7bb641a974f9
  • expat-2.5.0-5.el9_6.tuxcare.els11.x86_64.rpm
    sha:57c2c6a2e4f5ff6201d9ab164921f2c7a833a6b417f9034c230482767171395b
  • expat-devel-2.5.0-5.el9_6.tuxcare.els11.i686.rpm
    sha:63374daf682e9c6b751342da197c012f58d5d97993378a217cda6e89afa07c6a
  • expat-devel-2.5.0-5.el9_6.tuxcare.els11.x86_64.rpm
    sha:0058a63d3fbeb023fb182c9956a220d02e27060a62c586430883e1805b3aed01
  • expat-static-2.5.0-5.el9_6.tuxcare.els11.x86_64.rpm
    sha:c49a7419d155c705161d8b2e7728ac35cb5d5802cf01734af1c7631cf98e5326
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.