[CLSA-2026:1789744935] libxml2: Fix of CVE-2026-86140
Type:
security
Severity:
Critical
Release date:
2026-09-18 15:22:32 UTC
Description:
- CVE-2026-86140: add bounds checks around the englobing parenthesis strcat() calls in xmlSnprintfElements to prevent stack buffer overflow when dumping long element lists
CVEs fixed:
Updated packages:
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els12.i686.rpm
    sha:b8d0bae4dcd058e18215d9d5ca94d169b6d7c7609d7271eaf47e138e35a52b71
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els12.x86_64.rpm
    sha:20bd8950922f763bae7bff8e123f17abe414f8c4c94a1879ee6a917f4cf893e8
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els12.i686.rpm
    sha:a6d90b3c66bac698238142d07c2a9ce8b9cc2c92f8deae3e967833daf5280c52
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els12.x86_64.rpm
    sha:9fd627fb2f3ae0bf51bdf4c673738cf1d0c52e46a8f30684dde69d37cff38671
  • libxml2-python-2.9.1-6.0.11.el7_9.6.tuxcare.els12.x86_64.rpm
    sha:3508232ea50768b5996ad47c954b767d779900510a74680735e3382c245f8d0d
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els12.i686.rpm
    sha:c7ee354ffa6e98b0a14538a76c60aac3ac094689a1b049ffabf96f245ab9f86d
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els12.x86_64.rpm
    sha:b22d076e93f90d555f03c6acc93aab60e7eed3ba3543553dede3adea63d91b1f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.