[CLSA-2026:1786033457] Fix CVE(s): CVE-2026-56131
Type:
security
Severity:
Critical
Release date:
2026-08-06 16:24:27 UTC
Description:
* SECURITY UPDATE: use-after-free via re-entrant parser API calls made from inside handler callbacks - debian/patches/CVE-2026-56131.patch: track handler call depth and refuse XML_ResumeParser, XML_Parse, XML_ParseBuffer, XML_GetBuffer, XML_ParserFree and XML_ParserReset while a handler is on the stack (backport of libexpat PRs #1246, #1267 and #1278). - CVE-2026-56131
CVEs fixed:
Updated packages:
  • expat_2.2.5-3ubuntu0.9+tuxcare.els9_amd64.deb
    sha:26cdd7c92e36232684fb1d6a5d44da3c9b9b6396
  • libexpat1_2.2.5-3ubuntu0.9+tuxcare.els9_amd64.deb
    sha:107f93ccd7b7b06cf9e0dc4e91e13699ec16cbd1
  • libexpat1-dev_2.2.5-3ubuntu0.9+tuxcare.els9_amd64.deb
    sha:83e0814ab615818722733c679102a3a6478f867c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.