Release date:
2026-08-04 09:44:30 UTC
Description:
* SECURITY UPDATE:
- debian/patches/CVE-2026-56131.patch: block unsafe parser APIs from
handler callbacks using handler call-depth tracking in expat/lib/xmlparse.c
- debian/patches/CVE-2026-56407.patch: prevent signed integer overflow
when assigning entity values in expat/lib/xmlparse.c
- debian/patches/CVE-2026-56408.patch: prevent integer overflow in
copyString() allocation size calculations in expat/lib/xmlparse.c
- CVE-2026-56131
- CVE-2026-56407
- CVE-2026-56408
Updated packages:
-
expat_2.2.9-1ubuntu0.8+tuxcare.els6_amd64.deb
sha:52e4713d493715c4ffa89911d615c987c33fc68f
-
libexpat1_2.2.9-1ubuntu0.8+tuxcare.els6_amd64.deb
sha:7c0b0002571ee630a11d712697d8ce0ad0ade277
-
libexpat1-dev_2.2.9-1ubuntu0.8+tuxcare.els6_amd64.deb
sha:d8097ded27605f881784570e1c6b6f2093ce5094
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.