Release date:
2026-09-15 15:12:17 UTC
Description:
- CVE-2026-86137: out-of-bounds read in the NXT macro in xmlFAParsePosCharGroup
- CVE-2026-86138: integer overflow and heap buffer overflow in xmlDictAddQString
- CVE-2025-24928: stale-length bounds check inside the xmlSnprintfElements loop
(upstream 8c8753ad); this is the stack overflow reachable on 2.10.2
- CVE-2026-86140: unchecked strcat at the entry and exit of xmlSnprintfElements
(upstream d1686f91); hardening only on 2.10.2, callers pass an emptied buffer
- CVE-2026-86141: NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure
- CVE-2026-86142: heap buffer overflow in xmlXPtrEvalXPtrPart from xpointer length saturation
- CVE-2026-86143: negative lengths reaching write callbacks in xmlIO
- CVE-2026-86144: xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate
parseFlags; the include context now inherits every document parse flag
(NOENT, RECOVER and HUGE included), not only NONET
Updated packages:
-
alt-libxml2-2.10.2-6.el7.x86_64.rpm
sha:82143561e06c0d5bc16d7f5e19a2871f8cf5b7c507f056f536060a881498cfe6
-
alt-libxml2-devel-2.10.2-6.el7.x86_64.rpm
sha:399f990cc499ad80133bfacead8f11c4038e5ee142dd37449b6dc56528fcc1b3
-
alt-libxml2-static-2.10.2-6.el7.x86_64.rpm
sha:a316a4fa30e9025f80686b6cd8761abd3ab7cbbc0187a1b6a4ff40a4789a7078
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.