Release date:
2026-09-14 14:26:01 UTC
Description:
- CVE-2026-76957: fix a use-after-free by covering the custom XML_Encoding
convert/release callbacks with the handler call-depth tracking, so a
same-parser call made from inside them is rejected
Updated packages:
-
expat-2.1.0-15.0.7.amzn2.tuxcare.els7.i686.rpm
sha:5dbec751cca8d7bfba54278ae9489dfb9f00224892f1d2d8fbf2b2e616c83a56
-
expat-2.1.0-15.0.7.amzn2.tuxcare.els7.x86_64.rpm
sha:2cc5bf6cdd7ceb5f27a7141f054c3686dee3050e3868e4fe2cfc215e8cc741a8
-
expat-devel-2.1.0-15.0.7.amzn2.tuxcare.els7.x86_64.rpm
sha:d2ecb1d3dad534ca3f9e4dd10d7a699a047ea4bca3b5a9975ca693bef3de6ff3
-
expat-static-2.1.0-15.0.7.amzn2.tuxcare.els7.x86_64.rpm
sha:23961ea42820f5e928ad9117d99f38bdad885d167509d7b3f6e359202dc5a004
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.