[CLSA-2026:1785886642] Fix CVE(s): CVE-2026-56408
Type:
security
Severity:
Important
Release date:
2026-08-04 23:37:32 UTC
Description:
* SECURITY UPDATE: integer overflow in copyString() allocation size - debian/patches/CVE-2026-56408.patch: guard the copyString() allocation length against integer overflow (backport of libexpat commit 16e2efd, issue #565). - CVE-2026-56408
CVEs fixed:
Updated packages:
  • expat_2.2.5-3ubuntu0.9+tuxcare.els8_amd64.deb
    sha:16f3e0ae11ff9f5ac7562fecead55ea02b497c5f
  • libexpat1_2.2.5-3ubuntu0.9+tuxcare.els8_amd64.deb
    sha:a1c5bd2136db431c1468c2db7568739227dd6280
  • libexpat1-dev_2.2.5-3ubuntu0.9+tuxcare.els8_amd64.deb
    sha:dc3877d63eb8968c2ba92ba9cc49f8f92ff59217
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.