Release date:
2026-09-19 00:43:22 UTC
Description:
- CVE-2026-86143: guard the size_t buffer length against INT_MAX before it is
narrowed to the int passed to writecallback in xmlOutputBufferWrite(),
xmlOutputBufferWriteEscape() and xmlOutputBufferFlush() (xmlIO.c), so a
negative length can no longer reach an output callback
- CVE-2026-86144: propagate the document's parseFlags in xmlXIncludeProcess()
and xmlXIncludeProcessTree() and apply them to the parse="text" sub-context
in xmlXIncludeLoadTxt() (xinclude.c), so XML_PARSE_NONET is honoured during
XInclude resolution
Updated packages:
-
libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
sha:7eb94fac13f263d5b0d5c90471099f5a0e9616e7a255fd9ac8dca35a24f656f4
-
libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:d4040fb5b5b4f715b6f0762bbb93bd9d597855cb04d49e1a1d86cb52a03de65d
-
libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
sha:51d038cb68c44728d3c69d3218e6e43022c50caae6f28d484b5777db97132305
-
libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:b1e1fe38fc7098db38a828caa1312664a55b4a5eb403cc253120214e2ec9a419
-
libxml2-python-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:a7368cc8925cfcb5dd7e98391e8910eee1f6ff6eb1785df625c24b057b0be3fa
-
libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
sha:1411d75f8d40d54ca2329dfc63d35bf6a2a1a1d4c40c665655c74788ff0cb1f9
-
libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:4b7acb1fcabc6a7841e88b324ea151317bbcf7a41bc8b07aadff18aead405ae9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.