[CLSA-2026:1789202279] Fix CVE(s): CVE-2026-6653
Type:
security
Severity:
Critical
Release date:
2026-09-12 09:30:09 UTC
Description:
* SECURITY UPDATE: use-after-free in the DTD parser reachable through parameter-entity references - debian/patches/CVE-2026-6653.patch: drop the post-inputPush XML_PARSER_EOF early return from xmlPushInput() in parser.c. It reported an already-halted parser as a push failure after ownership of the input had been transferred, so xmlParsePEReference() freed the input still installed as ctxt->input and xmlParseInternalSubset() read through the dangling pointer. The flaw is introduced by the CVE-2021-3541 backport, not by the shipped version. - CVE-2026-6653
CVEs fixed:
Updated packages:
  • libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_amd64.deb
    sha:d5b195a1c40d8e617d72c7213403728e70cae5ec
  • libxml2-dev_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_amd64.deb
    sha:6b21b504f328d6f0d904533a67fa70b5596bf687
  • libxml2-doc_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_all.deb
    sha:28b5216b05f0aa7dd6611a3133bafd69d4d195d2
  • libxml2-utils_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_amd64.deb
    sha:745e7221f158e166b3d2a248627628655320c4ef
  • python-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_amd64.deb
    sha:727fb29b8089894d2568fb006af4005a01213ee0
  • python3-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_amd64.deb
    sha:7d216676bfc0453f95baed7f7f8915ced410f64a
  • libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_arm64.deb
    sha:684f9b9b320cc1e00662fc8ad5f7ba07a2436971
  • libxml2-dev_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_arm64.deb
    sha:87e796ec124c52da014f1030edea1b0d3130f773
  • libxml2-utils_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_arm64.deb
    sha:09b96d1ea536e434b3943126cd55f58ff97fdfc8
  • python-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_arm64.deb
    sha:9336dcf1ea061f195a69c5ab6561bced7b705b74
  • python3-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_arm64.deb
    sha:7ca55f28b486cafcae3c25582e622acc73ed7ba2
  • libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_armel.deb
    sha:53c76f928462504476fd8864bbd31169b0fa7b9b
  • libxml2-dev_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_armel.deb
    sha:2f0956df5bd96e7361bd9e2d2d4cfb65b8cdc909
  • libxml2-utils_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_armel.deb
    sha:5aa4a601bca4382c49ab4f7674a6c95924e50caa
  • python-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_armel.deb
    sha:20c67e763eae57cd31cb50cef08fc342d05a32d5
  • python3-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els12_armel.deb
    sha:afa8c19c6cb883f9839bfd54ebe61e3aef5ac979
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.