[CLSA-2026:1789396170] expat: Fix of CVE-2026-76957
Type:
security
Severity:
Critical
Release date:
2026-09-14 14:29:44 UTC
Description:
- CVE-2026-76957: fix a use-after-free by covering the custom XML_Encoding convert/release callbacks with the handler call-depth tracking, so a same-parser call made from inside them is rejected
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els7.i686.rpm
    sha:7bda802cf9450b58b26483853468fcfda53d86bd62e9ac05b2c448b5c74176eb
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els7.x86_64.rpm
    sha:a0bc52d4021d8e782ccfd978f8741b3def4a40f7af4a29dbc73d7af85cac20d0
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els7.i686.rpm
    sha:fc0c84183b8289dbad8bff8daf6120ce52c6e6e00bd99985333305dd7151ce84
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els7.x86_64.rpm
    sha:18990a55a1db8a1d760dd10b691937b5574064afd861fa5bebfdffb4a2ee6f37
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els7.i686.rpm
    sha:0692b1b4468601eeaeaaa24021ba667af6b787eb8338463177659133bac963af
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els7.x86_64.rpm
    sha:a2e3f7b04d31e1b7f46a1b2fc9b29acd85c2215ada60ff886c5a32d93360cac8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.