[CLSA-2026:1789554096] libxml2: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-17 00:33:23 UTC
Description:
- CVE-2026-86143: guard the size_t buffer length against INT_MAX before it is narrowed to the int passed to writecallback in xmlOutputBufferWrite(), xmlOutputBufferWriteEscape() and xmlOutputBufferFlush() (xmlIO.c), so a negative length can no longer reach an output callback - CVE-2026-86144: propagate the document's parseFlags in xmlXIncludeProcess() and xmlXIncludeProcessTree() and apply them to the parse="text" sub-context in xmlXIncludeLoadTxt() (xinclude.c), so XML_PARSE_NONET is honoured during XInclude resolution
Updated packages:
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
    sha:53e6d4167afb994608e6e7ba9647746781350612fd93d006da9f97bd5a502b8a
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
    sha:73138fb62890de4656b1935f3ec3909d70bac622cfdcd843a134c77df4da5e99
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
    sha:c7e48b0b9361c951d6a6c2770eb4727c7090dcdea7ed81c963b32ee30a11b1b2
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
    sha:da89260de80e27b894acda117bfa64c679c44f26d22c290d453764e4b37d3b1d
  • libxml2-python-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
    sha:908f3d64354a4babaf9ffb3b03245f5cc1925e54f35b2fb377e80cc1d6990f71
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
    sha:37e36670607bbde63274c166ddeaa7ded53a0ece64978668e981c0b0aa97c113
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
    sha:9cfa2855f4056edf64532773be157690aaf40fc72cc538b2db94322e9855fa1c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.