[CLSA-2026:1785945124] Fix CVE(s): CVE-2026-56407
Type:
security
Severity:
Important
Release date:
2026-08-05 15:52:24 UTC
Description:
* SECURITY UPDATE: signed integer overflow in XML entity value length - debian/patches/CVE-2026-56407.patch: cap entity textLen against signed integer overflow in doProlog() (backport of libexpat commit 30c2fc1, PR #1262). - CVE-2026-56407
CVEs fixed:
Updated packages:
  • expat_2.1.0-7ubuntu0.16.04.5+tuxcare.els11_amd64.deb
    sha:7e4137e2774a58c3b49b632315af7c17372e0024
  • libexpat1_2.1.0-7ubuntu0.16.04.5+tuxcare.els11_amd64.deb
    sha:b7ce5e5849d57a824de4067147b7f5cc928ed88e
  • libexpat1-dev_2.1.0-7ubuntu0.16.04.5+tuxcare.els11_amd64.deb
    sha:4731c0c44d1b9671047add874aee3e95e1a01277
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.