[CLSA-2026:1789395947] expat: Fix of CVE-2026-76957
Type:
security
Severity:
Critical
Release date:
2026-09-14 14:26:01 UTC
Description:
- CVE-2026-76957: fix a use-after-free by covering the custom XML_Encoding convert/release callbacks with the handler call-depth tracking, so a same-parser call made from inside them is rejected
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.amzn2.tuxcare.els7.i686.rpm
    sha:5dbec751cca8d7bfba54278ae9489dfb9f00224892f1d2d8fbf2b2e616c83a56
  • expat-2.1.0-15.0.7.amzn2.tuxcare.els7.x86_64.rpm
    sha:2cc5bf6cdd7ceb5f27a7141f054c3686dee3050e3868e4fe2cfc215e8cc741a8
  • expat-devel-2.1.0-15.0.7.amzn2.tuxcare.els7.x86_64.rpm
    sha:d2ecb1d3dad534ca3f9e4dd10d7a699a047ea4bca3b5a9975ca693bef3de6ff3
  • expat-static-2.1.0-15.0.7.amzn2.tuxcare.els7.x86_64.rpm
    sha:23961ea42820f5e928ad9117d99f38bdad885d167509d7b3f6e359202dc5a004
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.