[CLSA-2026:1785836657] Fix CVE(s): CVE-2026-56131, CVE-2026-56407, CVE-2026-56408
Type:
security
Severity:
Critical
Release date:
2026-08-04 09:44:30 UTC
Description:
* SECURITY UPDATE: - debian/patches/CVE-2026-56131.patch: block unsafe parser APIs from handler callbacks using handler call-depth tracking in expat/lib/xmlparse.c - debian/patches/CVE-2026-56407.patch: prevent signed integer overflow when assigning entity values in expat/lib/xmlparse.c - debian/patches/CVE-2026-56408.patch: prevent integer overflow in copyString() allocation size calculations in expat/lib/xmlparse.c - CVE-2026-56131 - CVE-2026-56407 - CVE-2026-56408
Updated packages:
  • expat_2.2.9-1ubuntu0.8+tuxcare.els6_amd64.deb
    sha:52e4713d493715c4ffa89911d615c987c33fc68f
  • libexpat1_2.2.9-1ubuntu0.8+tuxcare.els6_amd64.deb
    sha:7c0b0002571ee630a11d712697d8ce0ad0ade277
  • libexpat1-dev_2.2.9-1ubuntu0.8+tuxcare.els6_amd64.deb
    sha:d8097ded27605f881784570e1c6b6f2093ce5094
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.