[CLSA-2026:1789745145] libxml2: Fix of CVE-2026-86140
Type:
security
Severity:
Critical
Release date:
2026-09-18 15:25:56 UTC
Description:
- CVE-2026-86140: add bounds checks around the englobing parenthesis strcat() calls in xmlSnprintfElements to prevent stack buffer overflow when dumping long element lists
CVEs fixed:
Updated packages:
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els12.i686.rpm
    sha:cd9fc4081674ebe6eacc5a084986b239dd18a2f6dfc26f0ede45c4047b1bac48
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els12.x86_64.rpm
    sha:ebab9024baa713cb5f4d28a391aa24231da382226c7350477f5d79717baafed0
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els12.i686.rpm
    sha:49ad33150b0c4624689a30ac0bba7a327e93724971a27fd58b48c1dda2491114
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els12.x86_64.rpm
    sha:a154b034409b95fc09b061d0a7ecdd1c3e9d80efb2e1b32c33a302e22ddad168
  • libxml2-python-2.9.1-6.0.11.el7_9.6.tuxcare.els12.x86_64.rpm
    sha:215906e96bfac0039e7729df375647cc85dd975b61c2a5921e1794daf5a766c4
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els12.i686.rpm
    sha:75624dd0b008b620adba3883ebaeaa4ba7ffe69fd25d340ad1923cb59cab6ccf
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els12.x86_64.rpm
    sha:3aef2c3fbbc4a4e27b1081b47eb82dae117efc195b7a221295c91347cde49796
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.