[CLSA-2026:1789576008] libxml2: Fix of CVE-2026-86138
Type:
security
Severity:
Critical
Release date:
2026-09-16 16:26:57 UTC
Description:
- CVE-2026-86138: add integer-overflow guards to the pool size calculations in xmlDictAddString and xmlDictAddQString, and cap the name and prefix lengths in xmlDictQLookup at INT_MAX/2, preventing an undersized allocation and heap buffer overflow
CVEs fixed:
Updated packages:
  • libxml2-2.9.7-18.el8.tuxcare.els12.i686.rpm
    sha:66abea492cd91d47a2ac9dd694416ae26ef4dc78915e4075c4e29d9abf5aee25
  • libxml2-2.9.7-18.el8.tuxcare.els12.x86_64.rpm
    sha:9719069415af1c280635dcf29189a0c5af92c1a4f7f28654957243caf3df93f2
  • libxml2-devel-2.9.7-18.el8.tuxcare.els12.i686.rpm
    sha:52dff193cd23ee957c72be1f8ad15240eaa634a0cdcc4e12fefff7dd08704932
  • libxml2-devel-2.9.7-18.el8.tuxcare.els12.x86_64.rpm
    sha:659b8e47df36b95ecb73769cfd495565cf84f39fc5b2bb7699accaed508efc73
  • libxml2-static-2.9.7-18.el8.tuxcare.els12.x86_64.rpm
    sha:fa22a2b99036f13e83c828dbbe47f2c3a9b2cf12d45b3ddf4c562c7c6d303e7c
  • python3-libxml2-2.9.7-18.el8.tuxcare.els12.x86_64.rpm
    sha:877a924d874c72aaa4c3881c3341965ff06701164a4c7b3ce9ef1181931600ae
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.