[CLSA-2026:1786112657] expat: Fix of CVE-2026-56131
Type:
security
Severity:
Critical
Release date:
2026-08-07 14:24:40 UTC
Description:
- CVE-2026-56131: fix use-after-free caused by XML_ResumeParser() being callable from inside a handler, which re-enters the parser while the outer frame still owns bufferPtr/eventPtr
CVEs fixed:
Updated packages:
  • expat-2.0.1-13.el6_8.tuxcare.els12.i686.rpm
    sha:b2fd1906ab0ea312c024d39bee9b80168ef4c41a1454804e659a3601fe6d95dd
  • expat-2.0.1-13.el6_8.tuxcare.els12.x86_64.rpm
    sha:b1af501d206109bc19272167388776bbe4fe0ae1927e332ce6a114a03c27a132
  • expat-devel-2.0.1-13.el6_8.tuxcare.els12.i686.rpm
    sha:2058205b0b8bba6c67a12bbab7df92964adfbdf5540f3b3bee4fe24a6038c137
  • expat-devel-2.0.1-13.el6_8.tuxcare.els12.x86_64.rpm
    sha:cbc735181ae53da736122acbab571a2b5f03036c6b666fae5222ed68f64c94b3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.