Release date:
2026-09-16 23:20:22 UTC
Description:
- CVE-2026-86140: add bounds checks around the parenthesis writes in xmlSnprintfElements
- CVE-2026-86141: check the xmlStrdup result in xmlRegNewParserCtxt so a failed allocation cannot leave a NULL parser cursor
- CVE-2026-86142: make xmlStrlen saturate above INT_MAX and reject the saturated
length in xmlXPtrEvalXPtrPart before sizing the buffer
- CVE-2026-86143: check for integer overflow before passing a buffer length to the output write callback
- CVE-2026-86144: propagate the document parse flags in xmlXIncludeProcess and xmlXIncludeProcessTree
Updated packages:
-
libxml2-2.9.1-6.amzn2.5.26.tuxcare.els3.i686.rpm
sha:aa8bbaf706a0640c78dabb229f314df1c01d0c8938e0093d40d43701d5e6f9bd
-
libxml2-2.9.1-6.amzn2.5.26.tuxcare.els3.x86_64.rpm
sha:b806b5152984ac7cf97f2a55c71f7a80e0cc951655aa7077bfaab9a5bc274cd0
-
libxml2-devel-2.9.1-6.amzn2.5.26.tuxcare.els3.x86_64.rpm
sha:39c3ecbad573d7c84821c6f3932cbf674849d13a9b122baf3e7d37f956b00fb0
-
libxml2-python-2.9.1-6.amzn2.5.26.tuxcare.els3.x86_64.rpm
sha:1df5c4bae0d3e2c7d9b52c91407b08619a7719e8ba4a43f9af4351d41b636a59
-
libxml2-static-2.9.1-6.amzn2.5.26.tuxcare.els3.x86_64.rpm
sha:63eeb63ef9bbf64299f68ed3df4201947edc3d06dbc5b6a890215e8309cae16f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.