[CLSA-2026:1789632227] libxml2: Fix of 5 CVEs
Type:
security
Severity:
Critical
Release date:
2026-09-17 08:32:37 UTC
Description:
- CVE-2026-86138: add overflow checks to xmlDictAddQString to prevent an integer overflow and heap buffer overflow - CVE-2026-86140: bound the writes in xmlSnprintfElements to prevent a stack buffer overflow - CVE-2026-86142: make xmlStrlen saturate above INT_MAX and reject the saturated length in xmlXPtrEvalXPtrPart to prevent a heap buffer overflow - CVE-2026-86143: reject buffer lengths at or above INT_MAX before calling the output write callback to prevent an integer overflow - CVE-2026-86144: propagate parseFlags in xmlXIncludeProcess and xmlXIncludeProcessTree so parser flags such as XML_PARSE_NONET are honoured
Updated packages:
  • libxml2-2.7.6-21.0.1.el6_8.1.tuxcare.ol.els18.i686.rpm
    sha:3fa7858db4db2e9b90b75ad754bfd455cf031f586c6a6c5e8b49b6ab3e6baf96
  • libxml2-2.7.6-21.0.1.el6_8.1.tuxcare.ol.els18.x86_64.rpm
    sha:329d6499bf7ab9fff77aa07fec1f562801ec217796902adb3eecb31a822fe45e
  • libxml2-devel-2.7.6-21.0.1.el6_8.1.tuxcare.ol.els18.i686.rpm
    sha:5691fca6c137b7e7f327a89547469a230c65b4c2a6f9d94ccfac244713dc02ba
  • libxml2-devel-2.7.6-21.0.1.el6_8.1.tuxcare.ol.els18.x86_64.rpm
    sha:d9917c89b4fc8f15e346607d7254dbe1aa4d92254deecc487face212eb01c7f2
  • libxml2-python-2.7.6-21.0.1.el6_8.1.tuxcare.ol.els18.x86_64.rpm
    sha:628b77d5dc59c7a6bc971a9abd8a6bffac0cbc90cead3061b2fd2f7cba379cda
  • libxml2-static-2.7.6-21.0.1.el6_8.1.tuxcare.ol.els18.x86_64.rpm
    sha:eb168fdb2729770c05b7ec4c44514438568d5418c517db09f88723b7a89b16f0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.