[CLSA-2026:1789382179] libxml2: Fix of CVE-2026-86142
Type:
security
Severity:
Critical
Release date:
2026-09-14 10:36:35 UTC
Description:
- CVE-2026-86142: fix heap buffer overflow in xmlXPtrEvalXPtrPart by rejecting XPointer parts whose length is not representable as an int
CVEs fixed:
Updated packages:
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els9.i686.rpm
    sha:80f0338315c9de066cd9afeea1bcea0aa34cbcb40dcb97a082967d7d8c60dd3a
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els9.x86_64.rpm
    sha:fcf2bb0ded6adeafa43bfbc596337df2c58d89e0ffd39bb852c0d476d746a659
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els9.i686.rpm
    sha:4f594125db3c48c24d800d4e20d6f4c8771ba59675db59733dd140a24bee8068
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els9.x86_64.rpm
    sha:d98198843c82db98da56e5b4cb5092e2439f0c39bfea8c003e1a5a6d9119b817
  • libxml2-python-2.9.1-6.0.11.el7_9.6.tuxcare.els9.x86_64.rpm
    sha:3bf6b234a675d76c405f5adac188c8c0a51da3e0bd7f9a4acea23db804ec0dd4
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els9.i686.rpm
    sha:0a711ab88169f63a0439ac28bd35fe5befce71301b66d7db7f02a79a500e857c
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els9.x86_64.rpm
    sha:2ed546bdb70f6ae97b5be0718a7ad427a18b1785bb39774e6f84daf755906e03
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.