[CLSA-2026:1789780589] libxml2: Fix of 5 CVEs
Type:
security
Severity:
Critical
Release date:
2026-09-19 01:16:44 UTC
Description:
- CVE-2026-86140: add bounds checks around the parenthesis writes in xmlSnprintfElements - CVE-2026-86141: check the xmlStrdup result in xmlRegNewParserCtxt so a failed allocation cannot leave a NULL parser cursor - CVE-2026-86142: make xmlStrlen saturate above INT_MAX and reject the saturated length in xmlXPtrEvalXPtrPart before sizing the buffer - CVE-2026-86143: check for integer overflow before passing a buffer length to the output write callback - CVE-2026-86144: propagate the document parse flags in xmlXIncludeProcess and xmlXIncludeProcessTree
Updated packages:
  • libxml2-2.9.7-18.el8.tuxcare.els13.i686.rpm
    sha:5cb22832569f2ecbe8cb560f71cc9180306cc900df34766f55aeabd823026949
  • libxml2-2.9.7-18.el8.tuxcare.els13.x86_64.rpm
    sha:bb13a5c02de3b5843a2b709c1511794bb9e4cfd30ea653d9a9556ab07b68286f
  • libxml2-devel-2.9.7-18.el8.tuxcare.els13.i686.rpm
    sha:655a3fb254481f242de2288a8f5bf1ee6a00279ace3bf608527162d5b285c1df
  • libxml2-devel-2.9.7-18.el8.tuxcare.els13.x86_64.rpm
    sha:776916cf0509dcb2fcb2c0049798e2c852c101c1aa1873a8fae17d8f314684c3
  • libxml2-static-2.9.7-18.el8.tuxcare.els13.x86_64.rpm
    sha:2d366bf8e2a076ad5ec294d975e558e61246156341e33e4de8c30224c2ae462d
  • python3-libxml2-2.9.7-18.el8.tuxcare.els13.x86_64.rpm
    sha:71cbbed3df734752422fd162d603813ced6e05f475c393bb4b6a738380515afb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.