[CLSA-2026:1789554317] libxml2: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-16 10:25:27 UTC
Description:
- CVE-2026-86143: guard the size_t buffer length against INT_MAX before it is narrowed to the int passed to writecallback in xmlOutputBufferWrite(), xmlOutputBufferWriteEscape() and xmlOutputBufferFlush() (xmlIO.c), so a negative length can no longer reach an output callback - CVE-2026-86144: propagate the document's parseFlags in xmlXIncludeProcess() and xmlXIncludeProcessTree() and apply them to the parse="text" sub-context in xmlXIncludeLoadTxt() (xinclude.c), so XML_PARSE_NONET is honoured during XInclude resolution
Updated packages:
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
    sha:4e84888d250e0cb81c628d569aed65dccbff3737441a6429b54c8357e8796f26
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
    sha:97573fb81f7d52f8942f5ff35510bbd32f74db692d6e2ed2455ffb337d51693a
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
    sha:37a295a9f71dda9b717bb023c0d73c601997e0ceb26be95089fc3764ba9bbcb1
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
    sha:5cb5daaadcdc9636f0ffe22bbf449014a2bf257916dbdd224b3854b8fe060097
  • libxml2-python-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
    sha:43b854aa24becb1b1237407aa1816709122e48ccb32ee28cc48ffeaa8d615583
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
    sha:e5a124bdc10f74c30c3fc1b05e9c4d263b9f152069e29bdc9c4aff616942cf66
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
    sha:252b0bb89c0f1639ecebc898ef5e19eee984e8148bc04d7babf679eba164bc92
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.