[CLSA-2026:1789395902] expat: Fix of CVE-2026-76957
Type:
security
Severity:
Critical
Release date:
2026-09-14 14:25:16 UTC
Description:
- CVE-2026-76957: fix a use-after-free by covering the custom XML_Encoding convert/release callbacks with the handler call-depth tracking, so a same-parser call made from inside them is rejected
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els7.i686.rpm
    sha:6d9389ff4f9af91bf3edfbbcd18e8ff756819b2c7455372040be622894bdf38b
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els7.x86_64.rpm
    sha:82d812922be319ad6de9afe28e692497ce3b2ca1f90d4142accfef671ef41343
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els7.i686.rpm
    sha:c11b4c10c61c9688260a44bda8e2e64c1d4812ae9dbe688c40ee97a38d467ab4
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els7.x86_64.rpm
    sha:2bc9302723a1516399220909e2073196d8225740fe0c1af4d8a88899af25f18e
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els7.i686.rpm
    sha:6f0fd6e536d9bae46001687c88a5a5ccc74dddfb1a502edba8274b10ce776971
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els7.x86_64.rpm
    sha:98eabec2d152345af1480b8b7270b20ab1cd19fff30c7bc48d1378e70a4d9ae9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.