[CLSA-2026:1789641652] alt-libxml2: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-09-17 10:41:03 UTC
Description:
- CVE-2024-56171: use-after-free after xmlSchemaItemListAdd in the XML Schema identity-constraint code (xmlSchemaIDCFillNodeTables, xmlSchemaBubbleIDCNodeTables) - CVE-2026-6653: use-after-free in xmlParseInternalSubset; xmlPushInput() returned -1 for a parameter entity input it had already pushed, so the caller freed an input stream that ctxt->input still pointed at. Reachable through the entity amplification check carried by 2.10.2 for CVE-2021-3541, which this keeps in place. Also guards the xmlSkipBlankChars() loop on XML_PARSER_EOF (upstream e129c1d1), without which the same document spins at 100% CPU once the input is no longer freed
Updated packages:
  • alt-libxml2-2.10.2-7.el6.x86_64.rpm
    sha:f3a5958ffc2c59d2f52b616a625967afd114725b3e7522a843d12ec28426a665
  • alt-libxml2-devel-2.10.2-7.el6.x86_64.rpm
    sha:22f48b428a8d801717a5af50cc1412bfda4e13514fa60081150dc7c8e9715d6b
  • alt-libxml2-static-2.10.2-7.el6.x86_64.rpm
    sha:4cb1c0baf62c70d2c77b5dbe3bf6a27810374c3c3627672446a6e29deb5ef918
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.