[CLSA-2026:1789658299] libxml2: Fix of CVE-2026-86138
Type:
security
Severity:
Critical
Release date:
2026-09-17 15:18:30 UTC
Description:
- CVE-2026-86138: add overflow checks to xmlDictAddQString pool size calculation and reject over-long QNames in xmlDictQLookup to prevent heap buffer overflow when interning long QNames
CVEs fixed:
Updated packages:
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els11.i686.rpm
    sha:a550fb14cd7ddb732bb614b2ae9a6dab5b0040d58c7b58ea03d874ad6a1b7e97
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els11.x86_64.rpm
    sha:375daa2491d3b84f214933d4b7b4e80f8d0fefd0824b1e0a4522f332e3364bc9
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els11.i686.rpm
    sha:73db8420cfb9f50eeb6c1a4e87dc2dc4a4f0db05be268f31272a6f77a297b271
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els11.x86_64.rpm
    sha:426de669d3aa987479935e34e55b54a53af3a44b52a31575615b73c8492b039d
  • libxml2-python-2.9.1-6.0.11.el7_9.6.tuxcare.els11.x86_64.rpm
    sha:69a3937cbd492d3fcd26786c2ca746be408cd334d798034f13e2fc5f8a823ea9
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els11.i686.rpm
    sha:53feeb94fade98491ca8190268fdaf8417d344af906b465e8d87e42e7ad90b08
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els11.x86_64.rpm
    sha:f3dcff5c46d680680f78e716f8cff46980c5d8fe75bf06f6974ed1ade3d37548
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.